First Step for Actively Exploited Application Vulnerability
An information security team has confirmed that threat actors are taking advantage of a newly announced critical vulnerability within an application. Which of the following should be done FIRST?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the prioritization of incident management steps, where the trap is jumping directly to technical containment actions before establishing the organizational response framework.
When a critical vulnerability is confirmed to be actively exploited, the consensus is to immediately invoke the incident response plan to ensure a coordinated and structured defense.
Choosing to prevent access (B) is a common mistake because containment is a specific step within the plan, not the initial administrative action required to organize the response.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Invoking the incident response plan (C) is the correct first step because it activates the pre-defined chain of command, communication protocols, and resource allocation necessary to manage the crisis effectively. Without this framework, containment and remediation efforts may be disjointed or legally risky.Why the Other Options Are Wrong
Preventing access (B) is a containment action that should be executed according to the plan, not before it. Notifying senior management (A) is a communication step included within the plan's procedures. Installing additional controls (D) is a remediation or recovery activity that occurs later in the lifecycle.Community Comment Notes
Comment 1 emphasizes the need for a structured process to ensure timely action, while Comment 2 correctly identifies that options A, B, and D are actually sub-components of option C. Comment 3 suggests immediate containment, which reflects a common instinct to fix the technical issue first, ignoring the governance requirements of the CISM framework.Official Reference
Exam Strategy
For "FIRST" questions involving incidents, always prioritize the establishment of the process or plan over specific technical actions. Activating the plan authorizes and guides subsequent containment and eradication steps.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →