nerdexam
Isaca

CISM · Question #781

Which of the following is the MOST appropriate action during the containment phase of a cyber incident response?

The correct answer is D. Isolate affected systems to prevent the spread of damage. Isolating affected systems (D) is the hallmark action of the containment phase - the goal at this stage is to stop the bleeding by limiting how far the incident can spread, not to fix or fully understand it yet. A is wrong because root cause analysis belongs to the…

Submitted by lucia.co· Apr 18, 2026Information Security Incident Management

Question

Which of the following is the MOST appropriate action during the containment phase of a cyber incident response?

Options

  • ADetermine the final root cause of the incident.
  • BRemove all instances of the incident from the network.
  • CMitigate exploited vulnerabilities to prevent future incidents.
  • DIsolate affected systems to prevent the spread of damage.

How the community answered

(40 responses)
  • B
    3% (1)
  • C
    3% (1)
  • D
    95% (38)

Explanation

Isolating affected systems (D) is the hallmark action of the containment phase - the goal at this stage is to stop the bleeding by limiting how far the incident can spread, not to fix or fully understand it yet.

  • A is wrong because root cause analysis belongs to the post-incident/lessons learned phase, after the threat has been neutralized.
  • B is wrong because fully removing all instances of malware or attacker presence is the eradication phase, which comes after containment.
  • C is wrong because patching and mitigating vulnerabilities to prevent recurrence is part of the recovery/remediation phase, not containment.

Memory tip: Think of incident response phases as PICERL (Preparation → Identification → Containment → Eradication → Recovery → Lessons Learned). Containment = contain the blast radius first, everything else comes later. If you see "isolate," "segment," or "disconnect," that's containment.

Topics

#Incident Response#Containment Phase#Cyber Incident Management#Incident Lifecycle

Community Discussion

No community discussion yet for this question.

Full CISM Practice