nerdexam
Isaca

CISM · Question #532

Which of the following should be done FIRST after a ransomware incident has been successfully contained?

The correct answer is B. Conduct forensic analysis. Once containment is achieved, the priority is to conduct forensic analysis to preserve evidence, determine the scope and root cause of the attack, and inform subsequent recovery efforts before restoring systems or drawing broader lessons.

Submitted by renata2k· Apr 18, 2026Information Security Incident Management

Question

Which of the following should be done FIRST after a ransomware incident has been successfully contained?

Options

  • ANotify relevant stakeholders.
  • BConduct forensic analysis.
  • CPerform lessons learned.
  • DRestore impacted systems.

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    79% (19)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Once containment is achieved, the priority is to conduct forensic analysis to preserve evidence, determine the scope and root cause of the attack, and inform subsequent recovery efforts before restoring systems or drawing broader lessons.

Topics

#Incident Response Process#Forensic Analysis#Ransomware#Containment Phase

Community Discussion

No community discussion yet for this question.

Full CISM Practice