nerdexam
Isaca

CISM · Question #926

Which phase of the incident management process includes removing the threat and restoring affected systems to their previous state?

The correct answer is D. Eradication. Eradication is the phase where security teams actively remove the threat (malware, unauthorized accounts, vulnerabilities) and restore affected systems to a clean, known-good state - it's the "clean up and fix" step after you've stopped the spread. A (Lessons learned) is wrong…

Submitted by saadiq_pk· Apr 18, 2026Information Security Incident Management

Question

Which phase of the incident management process includes removing the threat and restoring affected systems to their previous state?

Options

  • ALessons learned
  • BDetection and analysis
  • CContainment
  • DEradication

How the community answered

(30 responses)
  • B
    3% (1)
  • C
    7% (2)
  • D
    90% (27)

Explanation

Eradication is the phase where security teams actively remove the threat (malware, unauthorized accounts, vulnerabilities) and restore affected systems to a clean, known-good state - it's the "clean up and fix" step after you've stopped the spread.

  • A (Lessons learned) is wrong - this is a post-incident review phase focused on what went well or poorly, not active remediation.
  • B (Detection and analysis) is wrong - this phase is about identifying and understanding the incident, not fixing it.
  • C (Containment) is wrong - containment limits the damage (isolating infected systems, blocking traffic) but does not remove the threat or restore systems.

Memory tip: Think of the phases in order - Detect → Contain → Eradicate → Recover → Learn. "Eradicate" literally means to pull out by the roots, which maps perfectly to removing the threat root cause and rebuilding clean systems.

Topics

#Incident Management Process#Eradication Phase#Threat Removal#System Restoration

Community Discussion

No community discussion yet for this question.

Full CISM Practice