Isaca
CISM · Question #565
Which of the following is the BEST course of action when SIEM monitoring indicates that a network attack is in progress?
The correct answer is A. Isolate the affected segments. Isolating the affected network segments is the best immediate response to contain the attack while minimizing impact on other parts of the network. It allows for investigation and remediation without disrupting the entire environment.
Submitted by yuriko_h· Apr 18, 2026Information Security Incident Management
Question
Which of the following is the BEST course of action when SIEM monitoring indicates that a network attack is in progress?
Options
- AIsolate the affected segments.
- BValidate the event logs.
- CRestart the affected devices.
- DShut down affected devices.
How the community answered
(39 responses)- A79% (31)
- B3% (1)
- C13% (5)
- D5% (2)
Explanation
Isolating the affected network segments is the best immediate response to contain the attack while minimizing impact on other parts of the network. It allows for investigation and remediation without disrupting the entire environment.
Topics
#Incident Response#Containment Strategy#Network Attack#SIEM
Community Discussion
No community discussion yet for this question.