nerdexam
Isaca

CISM · Question #71

Which of the following eradication methods is MOST appropriate when responding to an incident resulting in malware on an application server?

The correct answer is C. Restore the system from a known good backup.. When responding to malware on an application server, the most appropriate eradication method is to restore the system from a known good backup.

Submitted by hans_de· Apr 18, 2026Information Security Incident Management

Question

Which of the following eradication methods is MOST appropriate when responding to an incident resulting in malware on an application server?

Options

  • ADisconnect the system from the network.
  • BChange passwords on the compromised system.
  • CRestore the system from a known good backup.
  • DPerform operation system hardening.

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    16% (6)
  • C
    74% (28)
  • D
    5% (2)

Why each option

When responding to malware on an application server, the most appropriate eradication method is to restore the system from a known good backup.

ADisconnect the system from the network.

Disconnecting the system from the network is a containment action, not an eradication method; it stops the malware's spread but does not remove it from the system.

BChange passwords on the compromised system.

Changing passwords on a compromised system is part of post-eradication steps (recovery), and it might not be effective if the system is still infected or if the malware has captured new credentials.

CRestore the system from a known good backup.Correct

Restoring the system from a known good backup is the most appropriate eradication method for malware on an application server because it reliably removes all traces of the malicious software and returns the system to a pre-infection, trusted state. This approach ensures thorough eradication, minimizes the risk of residual malware, and often simplifies the recovery process compared to attempting to manually clean a potentially deeply compromised system.

DPerform operation system hardening.

Performing operating system hardening is a preventative measure to reduce attack surfaces, not an eradication method for an already infected system.

Concept tested: Incident response - Eradication

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#Incident Response#Malware Eradication#System Restoration#Recovery

Community Discussion

No community discussion yet for this question.

Full CISM Practice