CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 264


An organization's operations have been significantly impacted by a cyberattack resulting in data loss. Once the attack has been contained, what should the security team do NEXT?

Show Answer
Correct Answer: B

Once a cyberattack has been contained, the next step for the security team is to perform a root cause analysis. This analysis is crucial to understand how the attack occurred in the first place, identify any vulnerabilities that allowed the attack, and prevent similar incidents from happening in the future. Without understanding the root cause, subsequent steps such as implementing compensating controls or updating incident response plans would not be effectively targeted to address the actual weaknesses exploited by the attack.

Discussion

9 comments
Sign in to comment
Ej24356Option: D
Oct 19, 2023

Why not D, isn't root cause analysis done in conjunction with lessons learned?

richck102Option: B
Jun 5, 2023

B. Perform a root cause analysis.

oluchecpointOption: B
Sep 5, 2023

B. Perform a root cause analysis: It's crucial to understand how the cyberattack occurred in the first place. A root cause analysis helps identify the vulnerabilities or weaknesses in the organization's security posture that allowed the attack to happen. This analysis informs future security improvements and helps prevent similar incidents in the future.

Uncle_LuciferOption: D
Dec 8, 2023

After incidence should be lessoned leaned. You would have performed root cause analysis to know how to solve and mitigate the issue. Answer id D

Uncle_Lucifer
Dec 12, 2023

I was wrong. Answer is B. Containment is when you isolate a system to stop it from affecting or connecting to network. In this stage, the incidence hasn;t been mitigated, therefore leason learned is not valid. You need Root Cause analysis to determin what the issue is then fix/mitigate it. Answer is B. Sorry for selecting C. Admin please delete my selection.

Uncle_LuciferOption: B
Dec 12, 2023

I was wrong. Answer is B. Containment is when you isolate a system to stop it from affecting or connecting to network. In this stage, the incidence hasn;t been mitigated, therefore leason learned is not valid. You need Root Cause analysis to determin what the issue is then fix/mitigate it. Answer is B. Sorry for selecting C. Admin please delete my selection.

Uncle_Lucifer
Dec 12, 2023

ooops i selected D not C

Uncle_LuciferOption: B
Dec 12, 2023

Actually Answer could be C. Your next step should be eradicate. Root cause analysis is performed post incidence fix same with lesson learned. In exam i will select C

e891cd1
Apr 8, 2024

The root cause analysis is done as part of the Eradication process cuz u need to know the root cause to understand how it can be eradicated.

POWNEDOption: B
Dec 20, 2023

You need to find the root cause before lessons learned. Answer is B

oluchecpointOption: B
Jan 28, 2024

B. Perform a root cause analysis: It's crucial to understand how the cyberattack occurred in the first place. A root cause analysis helps identify the vulnerabilities or weaknesses in the organization's security posture that allowed the attack to happen. This analysis informs future security improvements and helps prevent similar incidents in the future.

bcffcfbOption: B
Jul 10, 2024

B While implementing compensating controls (option C) is important, it typically comes after understanding the root cause of the incident. How can we implement a control unless we find out the root cause/vulnerabilities etc.