What Is the First Step in Malware Incident Triage?

Incident Response Management
Answer Correct answer: B — Immediately isolate the compromised endpoint to halt lateral movement and prevent further network infection before initiating forensic collection.

Which of the following should be the FIRST step when performing triage of a malware incident?

  1. Preserving the forensic image
  2. Containing the affected system Correct Answer
  3. Comparing backup against production
  4. Removing the malware

Community Votes

B
67%
C
33%

67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests your understanding of incident response prioritization, where candidates often mistakenly choose forensic preservation or malware removal before stopping the active threat from spreading.

Effective malware incident triage prioritizes immediate system isolation to halt lateral movement, with experts and candidates consistently agreeing that containment must precede forensic imaging or removal.

Option C (Comparing backup against production) is selected by some who confuse recovery procedures with initial triage, overlooking that restoration happens only after the threat is fully contained and eradicated.

Community Discussion (3 comments)

ATT5832 👍 2 Selected: B
Containment.
ServerBrain 👍 1 Selected: C
B. Containing the affected system
shootnot 👍 1
B- Malware spreads rapidly therefore containment should be the first step by isolating the system.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Containment directly addresses the immediate risk of lateral movement and data exfiltration during a malware outbreak. By isolating the affected system, security teams stop the threat from propagating across the network while preserving the environment for subsequent investigation. This aligns with standard incident response lifecycles that mandate threat neutralization before evidence collection or system restoration.

Why the Other Options Are Wrong

Preserving a forensic image (A) is critical but typically occurs concurrently with or immediately after containment to avoid disrupting active malicious processes. Comparing backups against production (C) belongs to the recovery phase, which cannot safely begin until the malware is verified as eradicated. Removing the malware (D) is an eradication step that follows containment, as premature deletion may destroy valuable indicators of compromise needed for root cause analysis.

Community Comment Notes

Candidates frequently debate whether to capture disk images first, but the consensus emphasizes speed over perfect evidence collection during active outbreaks. As noted in top-voted discussions, “Malware spreads rapidly therefore containment should be the first step by isolating the system.” Multiple users confirmed that operational stability and risk mitigation take precedence in certification scenarios, reinforcing B as the definitive choice.

Official Reference

Exam Strategy

Always prioritize actions that stop active data loss or lateral movement first. When an option involves halting spread versus gathering evidence or restoring systems, containment almost always takes precedence in CISM scenario questions.

Frequently Asked Questions

Why not preserve forensic image first during malware triage?

While evidence integrity matters, uncontained malware actively spreads; isolating the host stops data exfiltration and lateral movement immediately.

Does containment mean shutting down the infected system?

Not necessarily; effective containment uses network segmentation, firewall rules, or account suspension to limit access without destroying volatile data needed for later forensics.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide