Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 108 discussion

Actual exam question from Isaca's CISM
Question #: 108
Topic #: 1
[All CISM Questions]

An employee clicked on a link in a phishing email, triggering a ransomware attack. Which of the following should be the information security manager's FIRST step?

  • A. Notify internal legal counsel.
  • B. Isolate the impacted endpoints.
  • C. Wipe the affected system.
  • D. Notify senior management.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
kokh94
3 months, 2 weeks ago
Selected Answer: B
Containment is the first act upon any confirmed incidents.
upvoted 1 times
...
Eltooth
4 months, 1 week ago
Selected Answer: D
D is correct answer - notify senior mgmt. Remember this is a CISManager exam so you would manage the situation both up (to senior mgmt) and down (secops engineers).
upvoted 1 times
...
helg420
6 months, 2 weeks ago
Selected Answer: B
B. Isolate the impacted endpoints. Isolating the impacted endpoints should be the information security manager's FIRST step upon discovering that a ransomware attack has been triggered by an employee clicking on a link in a phishing email. This action is essential to prevent the ransomware from spreading further across the organization's network, thereby containing the attack and minimizing potential damage. Isolating affected systems helps in protecting unaffected resources and is a critical step in managing and mitigating the incident effectively. While senior management's involvement and guidance are essential, especially in handling communications, legal considerations, and overarching organizational responses, the urgency of containing the ransomware attack to minimize its impact dictates that notifying senior management should follow after initial containment efforts have been initiated. This approach aligns with incident response best practices that prioritize immediate actions to secure the organization’s IT environment.
upvoted 2 times
...
nuel_12
7 months, 2 weeks ago
Selected Answer: D
D is the best choice, you have to come in terms to define the function of an information security manger, this is managerial position not operation position, if it was CASP+, GIAC, B will be the answer
upvoted 1 times
...
Thavee
7 months, 3 weeks ago
Selected Answer: D
Report to management first is the correct step even if it does look not a smartest way. In real life, just inform the management first, and another second later, give a call to the IT supervisor to quarantine the PC/whole VLAN/whole network segment. Cut the connections between operations and backup storage links (normally, should always have an airgap)
upvoted 1 times
...
cidigi
8 months, 1 week ago
Manager Himself doesnt do operational work(eg isolate endpoints etc). Also, if the ransomware happened, is too late to deal with endpoints. Now is time to deal with the request hence D, notify the big guys
upvoted 1 times
...
xcjxcj
8 months, 3 weeks ago
Selected Answer: B
Containment first. While B and D are essential, do you do B first or D first
upvoted 1 times
...
CCIEBYDEC
9 months, 1 week ago
Selected Answer: D
Knowing the meaning of the Ransome attack might help. The Ransome attack has already gone beyond containment it already involves payment, and a decision needs to be made
upvoted 1 times
xcjxcj
8 months, 3 weeks ago
Ransomware is a type of malware that locks and encrypts a victim's data, files, devices or systems, rendering them inaccessible and unusable until the attacker receives a ransom payment 1 pc is locked, i need to FIRST isolate it from the network.
upvoted 1 times
...
...
AlexJacobson
10 months ago
Selected Answer: D
While it's tempting to pick B (isolate), you have to remember that this is management level exam (similar to CISSP). This means you don't touch anything, only consult, advise, steer... While it is absolutely correct that the next thing you do upon confirming the incident is to contain it (in this case, isolate the affected endpoints), as a infosec manager you don't do that, you go ahead and inform management. So D, in my opinion.
upvoted 1 times
...
wello
1 year, 5 months ago
Selected Answer: D
ISACA emphasizes the importance of promptly notifying senior management about security incidents to ensure appropriate decision-making, resource allocation, and coordination of response efforts. Senior management needs to be informed early on to understand the potential impact of the incident, assess the organization's risk exposure, and authorize necessary actions.
upvoted 1 times
[Removed]
1 year, 4 months ago
after confirming an incident, the second step is always containment.
upvoted 3 times
...
CISSPST
1 year, 2 months ago
Yes, they do that in the Review Manual, yet in their Sample questions, they first want you to contain, inform the data owners, and then senior management. Refer Qs 96 & 103 (10th Ed). They even go ahead and say that senior management should only be informed if the impact is critical. It sucks what they do to our gullible minds, but well.... the answer is A (??) :).
upvoted 1 times
CISSPST
1 year, 1 month ago
sorry, I meant, the answer is B. Isolate impacted endpoints.
upvoted 3 times
...
...
...
richck102
1 year, 5 months ago
B. Isolate the impacted endpoints.
upvoted 2 times
...
Naijaboy
1 year, 6 months ago
Selected Answer: B
In such attacks, quick response makes a difference, hence if device is isolated, mgt can be notified. B then D
upvoted 2 times
...
Dravidian
1 year, 7 months ago
Selected Answer: D
The ISM is not going to be isolating anything aka not implementing actions. His role instead would be assess the situation and inform management.
upvoted 3 times
dark_3k03r
1 year, 6 months ago
he will not be doing the isolation himself, but instead instructing his direct reports to do it. From there he will reach out to management. But simply not telling their analyst to stop it will allow the problem to go unabated.
upvoted 3 times
...
...
Antonivs
1 year, 9 months ago
Selected Answer: B
B, then D
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...