nerdexam
Isaca

CISM · Question #83

To prepare for a third-party forensics investigation following an incident involving malware, the incident response team should:

The correct answer is D. preserve the evidence.. To prepare for a third-party forensics investigation, the incident response team's most crucial step is to preserve all relevant evidence from the incident.

Submitted by carter_n· Apr 18, 2026Information Security Incident Management

Question

To prepare for a third-party forensics investigation following an incident involving malware, the incident response team should:

Options

  • Aclean the malware.
  • Bisolate the infected systems.
  • Cimage the infected systems.
  • Dpreserve the evidence.

How the community answered

(56 responses)
  • A
    5% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    91% (51)

Why each option

To prepare for a third-party forensics investigation, the incident response team's most crucial step is to preserve all relevant evidence from the incident.

Aclean the malware.

Cleaning the malware before a forensic investigation could destroy critical evidence needed to understand the attack's scope, method, and origin.

Bisolate the infected systems.

While isolating infected systems is a critical containment step in an incident response, the primary preparation for *forensics* is evidence preservation, which often includes imaging the isolated systems.

Cimage the infected systems.

Imaging the infected systems is a *method* of preserving evidence, but 'preserve the evidence' is the overarching objective that encompasses imaging and other actions.

Dpreserve the evidence.Correct

Forensic investigations critically rely on the integrity and completeness of evidence. Before any other actions that might alter the state of infected systems, it is paramount to preserve all potential evidence, such as logs, memory dumps, and disk images, to ensure the third-party investigators have an accurate and untainted record of the incident for analysis.

Concept tested: Incident response - evidence preservation

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-86.pdf

Topics

#Incident Response#Digital Forensics#Evidence Preservation#Malware Incidents

Community Discussion

No community discussion yet for this question.

Full CISM Practice