First Step for Actively Exploited Application Vulnerability

Incident Response
Answer Correct answer: C — Invoke the incident response plan.

An information security team has confirmed that threat actors are taking advantage of a newly announced critical vulnerability within an application. Which of the following should be done FIRST?

  1. Notify senior management.
  2. Prevent access to the application.
  3. Invoke the incident response plan. Correct Answer
  4. Install additional application controls.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the prioritization of incident management steps, where the trap is jumping directly to technical containment actions before establishing the organizational response framework.

When a critical vulnerability is confirmed to be actively exploited, the consensus is to immediately invoke the incident response plan to ensure a coordinated and structured defense.

Choosing to prevent access (B) is a common mistake because containment is a specific step within the plan, not the initial administrative action required to organize the response.

Community Discussion (3 comments)

koala_lay 👍 1 Selected: C
When a critical vulnerability is discovered that is being actively exploited by threat actors, the first and most important step is to invoke the organization's incident response plan. This plan provides a structured and well-defined process for responding to security incidents, ensuring that the appropriate actions are taken in a timely and coordinated manner.
sausageman 👍 1 Selected: C
C. Invoke the incident response plan. All others can be part of the incident response plan
1899f17 👍 1
PREVENT ACESS TO THE APPLICATION

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Invoking the incident response plan (C) is the correct first step because it activates the pre-defined chain of command, communication protocols, and resource allocation necessary to manage the crisis effectively. Without this framework, containment and remediation efforts may be disjointed or legally risky.

Why the Other Options Are Wrong

Preventing access (B) is a containment action that should be executed according to the plan, not before it. Notifying senior management (A) is a communication step included within the plan's procedures. Installing additional controls (D) is a remediation or recovery activity that occurs later in the lifecycle.

Community Comment Notes

Comment 1 emphasizes the need for a structured process to ensure timely action, while Comment 2 correctly identifies that options A, B, and D are actually sub-components of option C. Comment 3 suggests immediate containment, which reflects a common instinct to fix the technical issue first, ignoring the governance requirements of the CISM framework.

Official Reference

ISACA CISM Review Manual

Exam Strategy

For "FIRST" questions involving incidents, always prioritize the establishment of the process or plan over specific technical actions. Activating the plan authorizes and guides subsequent containment and eradication steps.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide