nerdexam
Isaca

CRISC · Question #581

A user has contacted the risk practitioner regarding malware spreading laterally across the organization's corporate network. Which of the following is the risk practitioner's BEST course of action?

The correct answer is C. Notify the cybersecurity incident response team. When malware is actively spreading laterally across a corporate network, the risk practitioner's immediate and best course of action is to escalate the issue to the cybersecurity incident response team.

Submitted by saadiq_pk· Apr 18, 2026Risk Response and Reporting

Question

A user has contacted the risk practitioner regarding malware spreading laterally across the organization's corporate network. Which of the following is the risk practitioner's BEST course of action?

Options

  • AReview all log files generated during the period of malicious activity.
  • BPerform a root cause analysis.
  • CNotify the cybersecurity incident response team.
  • DUpdate the risk register.

How the community answered

(15 responses)
  • A
    7% (1)
  • B
    13% (2)
  • C
    73% (11)
  • D
    7% (1)

Why each option

When malware is actively spreading laterally across a corporate network, the risk practitioner's immediate and best course of action is to escalate the issue to the cybersecurity incident response team.

AReview all log files generated during the period of malicious activity.

Reviewing log files is part of the investigation phase but not the immediate first action when active lateral movement is confirmed, as containment is paramount.

BPerform a root cause analysis.

Performing a root cause analysis is a post-incident activity, done after the threat has been contained and eradicated, to prevent future occurrences.

CNotify the cybersecurity incident response team.Correct

Notifying the cybersecurity incident response team is the most critical immediate step when an active incident like malware spreading laterally is identified. This action initiates the formal incident response process, which includes containment, eradication, recovery, and post-incident analysis to mitigate the ongoing threat.

DUpdate the risk register.

Updating the risk register is a risk management activity that follows an incident, incorporating lessons learned, but it doesn't address the immediate active threat.

Concept tested: Incident response initiation

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender/incident-response-overview

Topics

#Incident Response#Risk Response#Malware#Communication

Community Discussion

No community discussion yet for this question.

Full CRISC Practice