What Is the First Step in Malware Incident Triage?
Which of the following should be the FIRST step when performing triage of a malware incident?
Community Votes
67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests your understanding of incident response prioritization, where candidates often mistakenly choose forensic preservation or malware removal before stopping the active threat from spreading.
Effective malware incident triage prioritizes immediate system isolation to halt lateral movement, with experts and candidates consistently agreeing that containment must precede forensic imaging or removal.
Option C (Comparing backup against production) is selected by some who confuse recovery procedures with initial triage, overlooking that restoration happens only after the threat is fully contained and eradicated.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Containment directly addresses the immediate risk of lateral movement and data exfiltration during a malware outbreak. By isolating the affected system, security teams stop the threat from propagating across the network while preserving the environment for subsequent investigation. This aligns with standard incident response lifecycles that mandate threat neutralization before evidence collection or system restoration.Why the Other Options Are Wrong
Preserving a forensic image (A) is critical but typically occurs concurrently with or immediately after containment to avoid disrupting active malicious processes. Comparing backups against production (C) belongs to the recovery phase, which cannot safely begin until the malware is verified as eradicated. Removing the malware (D) is an eradication step that follows containment, as premature deletion may destroy valuable indicators of compromise needed for root cause analysis.Community Comment Notes
Candidates frequently debate whether to capture disk images first, but the consensus emphasizes speed over perfect evidence collection during active outbreaks. As noted in top-voted discussions, “Malware spreads rapidly therefore containment should be the first step by isolating the system.” Multiple users confirmed that operational stability and risk mitigation take precedence in certification scenarios, reinforcing B as the definitive choice.Official Reference
Exam Strategy
Always prioritize actions that stop active data loss or lateral movement first. When an option involves halting spread versus gathering evidence or restoring systems, containment almost always takes precedence in CISM scenario questions.
Frequently Asked Questions
Why not preserve forensic image first during malware triage?
While evidence integrity matters, uncontained malware actively spreads; isolating the host stops data exfiltration and lateral movement immediately.
Does containment mean shutting down the infected system?
Not necessarily; effective containment uses network segmentation, firewall rules, or account suspension to limit access without destroying volatile data needed for later forensics.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →