Exam CISM All QuestionsBrowse all questions from this exam
Question 1079

Following a breach where the risk has been isolated and forensic processes have been performed, which of the following should be done NEXT?

    Correct Answer: D

    Following a breach where the risk has been isolated and forensic processes have been performed, it is crucial to ensure the server is rebuilt securely. Rebuilding the server with relevant patches from the original media helps in addressing any potential vulnerabilities that may have been exploited during the breach. Simply restoring from a backup could reintroduce vulnerabilities if the backup does not have the latest security patches.

Discussion
shootnotOption: D

ISACA has the same question#37 in their Q&A.

helg420Option: D

Backups could be contaminated