正解:C
= Disconnecting the device from the network is the first step when an IoT device in an organization's network is confirmed to have been hacked, as it prevents the attacker from further compromising the device or using it as a pivot point to attack other devices or systems on the network. Disconnecting the device also helps preserve the evidence of the attack for later forensic analysis and remediation. Disconnecting the device should be done in accordance with the incident response plan and the escalation procedures123. References =
* 1: CISM Review Manual 15th Edition, page 2004
* 2: CISM Practice Quiz, question 1072
* 3: IoT Security: Incident Response, Forensics, and Investigations, section "IoT Incident Response"