What Is Most Important When Planning Cyberattack Eradication?

Incident Management / Cyberattack Response
Answer Correct answer: D — Identify the exact type and origin of the threat before removing malicious artifacts to ensure complete system neutralization.

Which of the following is MOST important to consider when planning the eradication of a cyberattack?

  1. The skills and competencies of the eradication team
  2. The cost of tools and efforts required for the process
  3. Obtain a clean backup of the operating system
  4. Knowledge about the type and source of the threat Correct Answer

Community Votes

D
80%
C
20%

80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between eradication and recovery, where candidates often mistakenly prioritize restoring systems via backups instead of identifying the threat first.

Understanding the exact nature and origin of a threat is critical for effective cyberattack eradication, a fact consistently reinforced by CISM candidates and exam experts.

Option C (obtaining a clean backup) is frequently chosen because candidates confuse the eradication phase with the recovery phase, overlooking that restoration cannot safely occur without first neutralizing the active threat.

Community Discussion (5 comments)

Josef4CISM 👍 2 Selected: D
Question asks about eradication, not recovery. Hence, D.
bronay 👍 2 Selected: D
D knowledge
shootnot 👍 4
D- Eradication is the key word which in essence is deep cleaning. Knowing what to clean and where to clean to eradicate fully is the most important knowledge.
yottabyte 👍 1
Apologies, I think it is D to be honest. My previous answer choice was incorrect.
yottabyte 👍 1 Selected: C
I am leaning towards C, all options are required but having a clean backup is important to bring the systems back online.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The eradication phase requires precise identification of malicious artifacts, attack vectors, and persistence mechanisms before any cleanup occurs. Knowing the exact type and source of the threat ensures that responders remove all traces of the compromise rather than just addressing surface symptoms. This aligns with NIST SP 800-61 and SANS incident handling frameworks, which mandate threat intelligence gathering prior to eradication efforts.

Why the Other Options Are Wrong

While team competency and tool costs matter, they are operational constraints that cannot substitute for technical threat knowledge during this specific phase. Selecting a clean backup belongs to the recovery stage, not eradication, and attempting to restore infected systems prematurely risks reinfection. CISM exams consistently prioritize process accuracy over resource allocation questions unless explicitly asked about budget or staffing.

Community Comment Notes

Multiple high-voted comments clarify that “eradication” fundamentally means deep cleaning, which demands full awareness of the attacker’s methods. Several users initially selected the backup option but revised their answers after recognizing the strict phase definitions. As one contributor noted, “Question asks about eradication, not recovery,” highlighting how terminology traps drive incorrect choices.

Official Reference

Exam Strategy

Always map CISM incident response questions to NIST or ISO 27035 phase definitions first; confusing eradication with containment or recovery is a classic distractor pattern that wastes time if not caught early.

Frequently Asked Questions

Why isn't obtaining a clean backup the priority during eradication?

Backups belong to the recovery phase. Restoring systems before full threat eradication risks immediate reinfection from lingering malware or backdoors.

Does team skill level matter less than threat knowledge in this phase?

Highly skilled teams still cannot effectively clean an unknown threat. Precise IOCs and attack vectors must be identified before execution begins.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide