CISM - Incident Management - Section 4.9

Apply incident containment methods to limit the scope and impact of a security incident.

Apply incident containment methods - including isolation, network segmentation, and quarantine - to limit the spread and impact of a security incident without prematurely destroying forensic evidence. Choose the containment approach that balances the urgency of stopping damage against the business impact of taking systems or network segments offline.

ContainmentIsolationNetwork segmentationQuarantine

Practice question for this objective

Free sampleIncident Managementhard

During a confirmed ransomware outbreak, malware is spreading laterally across a flat manufacturing network that also runs safety-critical industrial control systems. The incident response team can isolate the affected segment immediately, but doing so will halt a production line mid-cycle in a way that could damage equipment. What should most influence the information security manager's containment decision?

  • AThe estimated cost of replacing the encrypted servers, since this quantifies the financial loss the containment action is meant to prevent.
  • BWhether the forensic team has finished capturing volatile memory from every affected host, because evidence preservation always precedes any containment step.
  • CThe wording of the cyber-insurance policy, which determines whether the insurer will reimburse losses from the production stoppage.
  • DThe relative business and safety impact of continued lateral spread versus an abrupt production halt, so containment limits overall harm rather than shifting it. Correct
Containment decisions must weigh the impact of continued incident spread against the impact of the containment action itself. Effective containment limits the total harm of an incident. When the isolation action carries its own safety or operational risk, the manager must compare that risk against the damage of unchecked lateral movement, choosing the option that minimises net impact rather than reflexively isolating or reflexively preserving evidence.

Why A is wrong: Replacement cost is an after-the-fact recovery figure; containment timing must weigh the live spread and the safety impact of stopping the line, not the price of hardware already affected.

Why B is wrong: Evidence preservation matters, but treating it as an absolute precondition that delays containment lets the malware keep spreading; preservation is balanced against, not placed ahead of, limiting impact.

Why C is wrong: Insurance terms inform later cost recovery and are tempting because executives ask about them, but they do not govern the operational judgement of how to contain an actively spreading incident safely.

Why D is correct: Correct: containment is about limiting net scope and impact, and in an environment with safety-critical systems the manager must compare the harm of continued spread against the harm of the isolation action itself before acting.

See more CISM practice questions, answers explained.

More in this domain

Back to all Incident Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.