Preserving Evidence Integrity During Server Intrusion Response

Incident Management / Forensics
Answer Correct answer: B — Preserve the integrity of digital evidence to maintain chain of custody and prevent destruction of volatile system data during intrusion response.

When multiple Internet intrusions on a server are detected, the PRIMARY concern of the information security manager should be to ensure:

  1. the incident is reported to senior management.
  2. the integrity of evidence is preserved. Correct Answer
  3. the server is unplugged from power.
  4. forensic investigation software is loaded on the server.

Community Votes

B
70%
A
30%

70% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests incident response prioritization, with the common trap being immediate hardware isolation that destroys volatile forensic data.

Preserving digital evidence integrity is the primary priority when detecting multiple server intrusions, as confirmed by CISM exam candidates and ISACA guidelines. Proper handling prevents data loss and ensures valid legal or investigative outcomes.

Option A is frequently chosen due to the assumption that executive escalation takes precedence, overlooking the immediate need to secure actionable forensic data before it degrades.

Community Discussion (3 comments)

Raj91188 👍 7 Selected: B
B. Preserving the integrity of evidence is crucial when dealing with an intrusion because it ensures that any subsequent investigation, whether internal or legal, is based on accurate and untampered data. Maintaining evidence integrity allows the organization to analyze the attack, understand the scope, and potentially use the findings in court if necessary.
ATT5832 👍 1 Selected: C
Step 1 should be isolation. Answer C is the only option for isolation.
pgonza 👍 3 Selected: A
A. Report the incident to senior management. The rational is that if the server is critical to the business, senior management will decide weather the risk associated is acceptable compared to the cost of the isolating or shutting it down for investigation is investigation.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Preserving evidence integrity is the primary concern because it maintains the chain of custody and ensures subsequent investigations rely on untampered data. ISACA’s incident response framework prioritizes securing volatile system states before any remediation or reporting occurs. Without intact forensic artifacts, determining the attack vector and scope becomes legally and technically impossible.

Why the Other Options Are Wrong

Reporting to senior management (A) is necessary but secondary, as executives require accurate post-preservation findings to make informed risk decisions. Unplugging the server (C) causes immediate power loss, erasing RAM contents and active network sessions critical for malware analysis. Loading forensic software (D) modifies the system environment, potentially overwriting logs and contaminating the original intrusion footprint.

Community Comment Notes

Candidates heavily favor option B, recognizing that legal defensibility hinges on data authenticity. One top-voted comment explains that preserving evidence allows organizations to analyze attacks and support potential court proceedings. While some argue for immediate management escalation or physical isolation, these approaches overlook the irreversible loss of volatile forensic data emphasized in official CISM study materials.

Official Reference

Exam Strategy

Always evaluate options through the lens of business impact and legal defensibility rather than purely technical fixes. In CISM scenarios, avoid actions that permanently alter system state unless explicitly authorized for immediate threat neutralization.

Frequently Asked Questions

Why shouldn't I unplug the server immediately upon detecting intrusions?

Unplugging cuts power instantly, wiping volatile RAM contents like running processes and network connections essential for forensic analysis.

When should senior management be notified about server intrusions?

Management notification follows initial containment and evidence preservation, ensuring leaders receive accurate findings rather than premature alerts.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide