Preserving Evidence Integrity During Server Intrusion Response
When multiple Internet intrusions on a server are detected, the PRIMARY concern of the information security manager should be to ensure:
Community Votes
70% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests incident response prioritization, with the common trap being immediate hardware isolation that destroys volatile forensic data.
Preserving digital evidence integrity is the primary priority when detecting multiple server intrusions, as confirmed by CISM exam candidates and ISACA guidelines. Proper handling prevents data loss and ensures valid legal or investigative outcomes.
Option A is frequently chosen due to the assumption that executive escalation takes precedence, overlooking the immediate need to secure actionable forensic data before it degrades.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Preserving evidence integrity is the primary concern because it maintains the chain of custody and ensures subsequent investigations rely on untampered data. ISACA’s incident response framework prioritizes securing volatile system states before any remediation or reporting occurs. Without intact forensic artifacts, determining the attack vector and scope becomes legally and technically impossible.Why the Other Options Are Wrong
Reporting to senior management (A) is necessary but secondary, as executives require accurate post-preservation findings to make informed risk decisions. Unplugging the server (C) causes immediate power loss, erasing RAM contents and active network sessions critical for malware analysis. Loading forensic software (D) modifies the system environment, potentially overwriting logs and contaminating the original intrusion footprint.Community Comment Notes
Candidates heavily favor option B, recognizing that legal defensibility hinges on data authenticity. One top-voted comment explains that preserving evidence allows organizations to analyze attacks and support potential court proceedings. While some argue for immediate management escalation or physical isolation, these approaches overlook the irreversible loss of volatile forensic data emphasized in official CISM study materials.Official Reference
Exam Strategy
Always evaluate options through the lens of business impact and legal defensibility rather than purely technical fixes. In CISM scenarios, avoid actions that permanently alter system state unless explicitly authorized for immediate threat neutralization.
Frequently Asked Questions
Why shouldn't I unplug the server immediately upon detecting intrusions?
Unplugging cuts power instantly, wiping volatile RAM contents like running processes and network connections essential for forensic analysis.
When should senior management be notified about server intrusions?
Management notification follows initial containment and evidence preservation, ensuring leaders receive accurate findings rather than premature alerts.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →