CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 727


During which of the following phases should an incident response team document actions required to remove the threat that caused the incident?

Show Answer
Correct Answer: A

During the Eradication phase, the incident response team focuses on removing the threat and restoring affected systems. This phase requires documentation of actions taken to eliminate the cause of the incident, such as applying patches, removing malware, closing vulnerabilities, or blocking access points. Proper documentation is crucial for ensuring the steps are recorded for future reference and for updating incident response procedures.

Discussion

7 comments
Sign in to comment
BroesweeliesOption: A
Feb 10, 2023

you make the document during eradication because it is most needed then, it is reviewed during incident review to improve the incident response plan

mad68Option: A
May 15, 2023

A. Eradication. During the Eradication phase of the incident response process, the focus is on removing the threat, eliminating any traces of the attacker, and restoring affected systems to their normal state. This phase involves taking specific actions to remediate the cause of the incident, such as applying patches, removing malware, closing vulnerabilities, or blocking access points used by the attacker. Documentation of the actions taken during the Eradication phase is crucial for several reasons. It helps ensure that the steps taken are properly recorded for future reference and can be used to update incident response procedures.

aokisanOption: D
Dec 26, 2022

document is need for review.

BoomersOption: A
Feb 5, 2023

Eradication - Eradication is the phase of effective incident response that entails removing the threat and restoring affected systems to their previous state, ideally while minimizing data loss.

Gr3yGh0sTOption: A
May 9, 2023

The eradication phase is when the incident response team takes steps to remove the threat that caused the incident. This may include removing malware, patching vulnerabilities, or changing passwords. The team should document all actions taken during this phase so that they can be reviewed and improved upon in the future.

richck102Option: A
Jul 7, 2023

A. Eradication

03allenOption: D
Jun 29, 2024

I'm not too fond of the question, it says document actions, not the actions to remove the threat. It is to document. I feel like D more than A.