CISM - Incident Management - Section 4.11

Execute incident eradication and recovery activities to restore systems and services to normal operation.

Execute eradication activities to remove the root cause of an incident - such as eliminating malware, closing exploited vulnerabilities, and revoking compromised credentials - before initiating system recovery and restoration to normal operation. Verify that eradication is complete and that restored systems are clean prior to returning them to production.

EradicationSystem recoveryRoot cause removalRestoration

Practice question for this objective

Free sampleIncident Managementhard

Following containment of an intrusion that used a stolen service account to move between several systems, the information security manager is planning eradication. A senior engineer proposes resetting the compromised account and reimaging the entry-point server so recovery can begin. The manager judges this insufficient. Which consideration best explains why eradication should go further before recovery starts?

  • AThe root cause and full scope of the compromise, including any other accounts or hosts the attacker reached, must be removed or eradication treats only the symptoms. Correct
  • BReimaging a single server will not satisfy the recovery time objective agreed for the affected business service in the business impact analysis.
  • CReimaging should be deferred until forensic imaging is complete so that evidence of the intrusion is preserved for any later legal action.
  • DResetting one account and one server keeps remediation cheaper than rebuilding every host the attacker may have touched during the intrusion.
Eradication must remove the root cause and the full scope of compromise, not just the visible entry point, before recovery can safely begin. Lateral movement using a stolen account means the attacker's reach extends beyond the entry-point server. Eradicating only the obvious symptoms leaves residual access, so the full scope and root cause must be removed first.

Why A is correct: An account that moved laterally implies wider footholds; eradicating only the obvious entry point leaves the root cause and undiscovered access in place, so recovery would restore systems while the threat persists.

Why B is wrong: Linking the action to the recovery time objective sounds business-aligned, but the objective concerns how fast service returns, not whether the threat is fully removed, so it misses the real eradication gap.

Why C is wrong: Evidence preservation is a valid concern earlier in the response, but the manager's worry here is incomplete threat removal, not admissibility, so this addresses a different phase of the lifecycle.

Why D is wrong: Cost restraint can look like sound managerial judgement, but choosing the cheaper fix while the attacker's full reach is unknown is precisely the symptom-level remediation the manager rejects.

See more CISM practice questions, answers explained.

More in this domain

Back to all Incident Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.