CISM - Incident Management (30% of the exam) - Section 4.9

Apply incident containment methods to limit the scope and impact of a security incident.

Apply incident containment methods - including isolation, network segmentation, and quarantine - to limit the spread and impact of a security incident without prematurely destroying forensic evidence. Choose the containment approach that balances the urgency of stopping damage against the business impact of taking systems or network segments offline.

ContainmentIsolationNetwork segmentationQuarantine

Practice question for this objective

Free sampleIncident Managementhard

During a confirmed ransomware outbreak, malware is spreading laterally across a flat manufacturing network that also runs safety-critical industrial control systems. The incident response team can isolate the affected segment immediately, but doing so will halt a production line mid-cycle in a way that could damage equipment. What should most influence the information security manager's containment decision?

  • AThe estimated cost of replacing the encrypted servers, since this quantifies the financial loss the containment action is meant to prevent.
  • BWhether the forensic team has finished capturing volatile memory from every affected host, because evidence preservation always precedes any containment step.
  • CThe wording of the cyber-insurance policy, which determines whether the insurer will reimburse losses from the production stoppage.
  • DThe relative business and safety impact of continued lateral spread versus an abrupt production halt, so containment limits overall harm rather than shifting it. Correct
Containment decisions must weigh the impact of continued incident spread against the impact of the containment action itself. Effective containment limits the total harm of an incident. When the isolation action carries its own safety or operational risk, the manager must compare that risk against the damage of unchecked lateral movement, choosing the option that minimises net impact rather than reflexively isolating or reflexively preserving evidence.

Why A is wrong: Replacement cost is an after-the-fact recovery figure; containment timing must weigh the live spread and the safety impact of stopping the line, not the price of hardware already affected.

Why B is wrong: Evidence preservation matters, but treating it as an absolute precondition that delays containment lets the malware keep spreading; preservation is balanced against, not placed ahead of, limiting impact.

Why C is wrong: Insurance terms inform later cost recovery and are tempting because executives ask about them, but they do not govern the operational judgement of how to contain an actively spreading incident safely.

Why D is correct: Correct: containment is about limiting net scope and impact, and in an environment with safety-critical systems the manager must compare the harm of continued spread against the harm of the isolation action itself before acting.

See more CISM practice questions, answers explained.

Exam traps in Incident Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • Power down every server on the affected network at once so the malware loses all hosts it could use to propagate further across the estate

    Why it is wrong: Tempting because a full shutdown definitively halts propagation, but it also stops the revenue-critical platform, inflicting the business harm the manager is mandated to avoid where a lesser measure exists.

  • To permanently remove the attacker's tools, accounts and persistence so the same intrusion cannot recur on the affected systems

    Why it is wrong: Tempting because it sounds like the ultimate goal of response, but removing tools and persistence is eradication, a later phase; containment aims only to limit spread and impact while analysis continues.

  • The technical effectiveness of the action at fully stopping the attacker, since the most thorough containment measure should always be selected

    Why it is wrong: Tempting because thoroughness feels safest, but treating maximum technical effect as the sole driver ignores the business cost of halting payments and can cause more harm than the incident itself.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.