exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 567 discussion

Actual exam question from Isaca's CISM
Question #: 567
Topic #: 1
[All CISM Questions]

After an information security incident has been detected and its priority established, which of the following should be the NEXT course of action?

  • A. Gathering evidence
  • B. Eradicating the incident
  • C. Performing a risk assessment
  • D. Containing the incident
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
richck102
12 months ago
D. Containing the incident
upvoted 2 times
...
karanvp
1 year ago
Selected Answer: D
Correct Answer D Gathering Evidence not required until any investigation requirement confirmed; Eradication is not initial steps; Risk Assessment not required as it is Incident. Hence D
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...