What Is Most Important When Planning Cyberattack Eradication?
Which of the following is MOST important to consider when planning the eradication of a cyberattack?
Community Votes
80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between eradication and recovery, where candidates often mistakenly prioritize restoring systems via backups instead of identifying the threat first.
Understanding the exact nature and origin of a threat is critical for effective cyberattack eradication, a fact consistently reinforced by CISM candidates and exam experts.
Option C (obtaining a clean backup) is frequently chosen because candidates confuse the eradication phase with the recovery phase, overlooking that restoration cannot safely occur without first neutralizing the active threat.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The eradication phase requires precise identification of malicious artifacts, attack vectors, and persistence mechanisms before any cleanup occurs. Knowing the exact type and source of the threat ensures that responders remove all traces of the compromise rather than just addressing surface symptoms. This aligns with NIST SP 800-61 and SANS incident handling frameworks, which mandate threat intelligence gathering prior to eradication efforts.Why the Other Options Are Wrong
While team competency and tool costs matter, they are operational constraints that cannot substitute for technical threat knowledge during this specific phase. Selecting a clean backup belongs to the recovery stage, not eradication, and attempting to restore infected systems prematurely risks reinfection. CISM exams consistently prioritize process accuracy over resource allocation questions unless explicitly asked about budget or staffing.Community Comment Notes
Multiple high-voted comments clarify that “eradication” fundamentally means deep cleaning, which demands full awareness of the attacker’s methods. Several users initially selected the backup option but revised their answers after recognizing the strict phase definitions. As one contributor noted, “Question asks about eradication, not recovery,” highlighting how terminology traps drive incorrect choices.Official Reference
Exam Strategy
Always map CISM incident response questions to NIST or ISO 27035 phase definitions first; confusing eradication with containment or recovery is a classic distractor pattern that wastes time if not caught early.
Frequently Asked Questions
Why isn't obtaining a clean backup the priority during eradication?
Backups belong to the recovery phase. Restoring systems before full threat eradication risks immediate reinfection from lingering malware or backdoors.
Does team skill level matter less than threat knowledge in this phase?
Highly skilled teams still cannot effectively clean an unknown threat. Precise IOCs and attack vectors must be identified before execution begins.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →