nerdexam
Isaca

CISM · Question #8

Which of the following should be done FIRST once a cybersecurity attack has been confirmed?

The correct answer is A. Isolate the affected system. Once a cybersecurity attack is confirmed, the very first step should be to isolate the affected system to prevent further compromise and contain the incident.

Submitted by katya_ua· Apr 18, 2026Information Security Incident Management

Question

Which of the following should be done FIRST once a cybersecurity attack has been confirmed?

Options

  • AIsolate the affected system
  • BPower down the system
  • CNotify senior management
  • DContact legal authorities

How the community answered

(26 responses)
  • A
    92% (24)
  • C
    4% (1)
  • D
    4% (1)

Why each option

Once a cybersecurity attack is confirmed, the very first step should be to isolate the affected system to prevent further compromise and contain the incident.

AIsolate the affected systemCorrect

Isolating the affected system is crucial to prevent the attack from spreading to other systems or networks, thus limiting the scope and potential damage of the incident. This containment step helps preserve evidence and allows for more controlled analysis and remediation.

BPower down the system

Powering down the system might destroy volatile data crucial for forensic analysis and could also disrupt critical business services, so isolation is generally preferred over immediate shutdown.

CNotify senior management

Notifying senior management is important, but containment (isolation) should precede notification to prevent further damage while management is being informed and plans are being made.

DContact legal authorities

Contacting legal authorities is a later step in the incident response process, typically after initial containment, assessment, and potentially some investigation, when enough information is gathered to make such a report.

Concept tested: Incident response containment (first step)

Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-61r2.pdf

Topics

#Incident Response#Containment#Cybersecurity Attack#First Steps

Community Discussion

No community discussion yet for this question.

Full CISM Practice