exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 726 discussion

Actual exam question from Isaca's CISM
Question #: 726
Topic #: 1
[All CISM Questions]

An information security manager has been notified about a compromised endpoint device. Which of the following is the BEST course of action to prevent further damage?

  • A. Run a virus scan on the endpoint device
  • B. Wipe and reset the endpoint device
  • C. Power off the endpoint device
  • D. Isolate the endpoint device
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 11 months ago
Selected Answer: D
The BEST course of action to prevent further damage in this scenario is "D. Isolate the endpoint device." When a compromised endpoint device is detected, it is essential to isolate the device as soon as possible to prevent further damage and to minimize the risk of data loss or theft. This can involve disconnecting the device from the network, disabling any active connections, and removing the device from the production environment.
upvoted 6 times
...
yottabyte
Most Recent 10 months, 1 week ago
Selected Answer: D
D is the only correct choice, whoever answered B may not be ready for the exam just yet :-P
upvoted 1 times
...
xcjxcj
10 months, 2 weeks ago
Selected Answer: B
Question is best prevent A. Device active, damage can go on C. Immediate. When you power on again, damage continues D. remaining code is still active, when you connect back, damage goes on B > C > D, IMO
upvoted 1 times
xcjxcj
10 months, 2 weeks ago
Though practically i would do D
upvoted 1 times
...
...
richck102
1 year, 6 months ago
D. Isolate the endpoint device
upvoted 1 times
...
CarlLimps
1 year, 10 months ago
Selected Answer: D
You want to isolate, that way you can still conduct some type of investigation and get some IOC's and see if there are more in your environment. Eventually you'll want to wipe it but not the first step, if you have the capabilities.
upvoted 2 times
...
aokisan
2 years, 1 month ago
Selected Answer: B
wipe and reset are important.
upvoted 2 times
CarlLimps
1 year, 10 months ago
Wrong. You want to isolate, that way you can still conduct some type of investigation and get some IOC's and see if there are more in your environment. Eventually you'll want to wipe it but not the first step, if you have the capabilities.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...