nerdexam
Isaca

CISM · Question #898

Which of the following should an information security manager do FIRST when an employee reports having clicked on a potentially suspicious link sent via email?

The correct answer is C. Investigate and confirm the incident. The first step in any reported incident is to investigate and confirm whether an actual security event occurred. Acting prematurely - such as locking an account (B) or quarantining the computer (D) - disrupts business operations and may be unnecessary if the link was benign…

Submitted by skyler.x· Apr 18, 2026Information Security Incident Management

Question

Which of the following should an information security manager do FIRST when an employee reports having clicked on a potentially suspicious link sent via email?

Options

  • ASchedule mandatory security awareness training.
  • BLock the user's account.
  • CInvestigate and confirm the incident.
  • DDisable and quarantine the user's computer.

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    80% (16)
  • D
    10% (2)

Explanation

The first step in any reported incident is to investigate and confirm whether an actual security event occurred. Acting prematurely - such as locking an account (B) or quarantining the computer (D) - disrupts business operations and may be unnecessary if the link was benign. Investigation determines the scope and severity, which then informs the appropriate response. Security awareness training (A) is a long-term corrective measure, not an immediate incident response action.

Topics

#Incident Response#Phishing#Initial Response#Incident Investigation

Community Discussion

No community discussion yet for this question.

Full CISM Practice