nerdexam
Isaca

CISM · Question #617

Which of the following is the PRIMARY goal of the eradication phase of an information security incident response process?

The correct answer is D. To remove malicious artifacts left from the incident. The primary goal of the eradication phase is to eliminate all malicious components, such as malware or compromised accounts, to ensure the threat is fully removed before recovery begins.

Submitted by andres_qro· Apr 18, 2026Information Security Incident Management

Question

Which of the following is the PRIMARY goal of the eradication phase of an information security incident response process?

Options

  • ATo restore systems to normal operation
  • BTo improve organizational incident response capability
  • CTo prevent further damage from occurring
  • DTo remove malicious artifacts left from the incident

How the community answered

(20 responses)
  • A
    5% (1)
  • C
    5% (1)
  • D
    90% (18)

Explanation

The primary goal of the eradication phase is to eliminate all malicious components, such as malware or compromised accounts, to ensure the threat is fully removed before recovery begins.

Topics

#Incident Response#Eradication Phase#Incident Management Process

Community Discussion

No community discussion yet for this question.

Full CISM Practice