Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 1234 discussion

Actual exam question from Isaca's CISM
Question #: 1234
Topic #: 1
[All CISM Questions]

When multiple Internet intrusions on a server are detected, the PRIMARY concern of the information security manager should be to ensure:

  • A. the incident is reported to senior management.
  • B. the integrity of evidence is preserved.
  • C. the server is unplugged from power.
  • D. forensic investigation software is loaded on the server.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Raj91188
Highly Voted 1 month, 3 weeks ago
Selected Answer: B
B. Preserving the integrity of evidence is crucial when dealing with an intrusion because it ensures that any subsequent investigation, whether internal or legal, is based on accurate and untampered data. Maintaining evidence integrity allows the organization to analyze the attack, understand the scope, and potentially use the findings in court if necessary.
upvoted 5 times
...
pgonza
Most Recent 2 months, 2 weeks ago
Selected Answer: A
A. Report the incident to senior management. The rational is that if the server is critical to the business, senior management will decide weather the risk associated is acceptable compared to the cost of the isolating or shutting it down for investigation is investigation.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...