Be able to sequence incident response phases correctly and pick the right containment action first. The single most important thing: contain the threat before eradicating or recovering, while preserving evidence and following the IR plan.
Start practicing
Incident Response and Recovery — choose a session length
Free · No account required
Domain overview
This domain covers the SSCP incident response lifecycle: preparation, detection and analysis, containment, eradication, recovery, and post-incident lessons learned. Questions test your judgment on ordering actions correctly, selecting containment scope, using evidence-handling and forensic practices, and aligning response with business continuity and disaster recovery priorities.
Exam objectives
Ordering the IR lifecycle phases and selecting preparation components like an IR plan and trained response team
Choosing containment scope (isolate host, segment network, disable account) to stop lateral movement
Applying evidence handling and chain of custody so forensic artifacts remain admissible
Distinguishing incident response from business continuity and disaster recovery roles and triggers
Jumping straight to eradication or recovery before containing the threat, letting the adversary spread further
Confusing business continuity (keep operations running) with disaster recovery (restore IT systems) when choosing the right plan
Treating lessons learned as blame assignment instead of process improvement, missing the primary purpose
Click any question to see the full explanation and answer options, or start a focused practice session above.
During which phase of the NIST SP 800-61 incident response lifecycle are incident response plan updates and lessons learned typically documented?
2A security analyst receives a chain of custody form for a hard drive that was seized from a suspected insider threat. The form shows that the drive was handled by three individuals over two days. Which of the following is the PRIMARY reason for maintaining a chain of custody?
3During incident response, a team needs to isolate an infected workstation that is part of a critical manufacturing network. Which containment method is MOST appropriate to minimize disruption while preventing the spread of malware?
4After a ransomware incident, an organization decides to restore data from backups. The RPO (Recovery Point Objective) is 4 hours. What does this RPO indicate?
5Which DR testing type involves running recovery systems in parallel with production systems to verify functionality without impacting live operations?
6During the eradication phase of a malware incident, a security analyst removes malicious files and cleans registry persistence. What is the MOST critical additional step to prevent reinfection through the same vector?
7A security team is collecting evidence from a compromised server. They need to create a forensic image. Which of the following is the CORRECT procedure to ensure data integrity?
8What is the PRIMARY purpose of a lessons learned meeting after an incident?
9An analyst detects suspicious outbound traffic from a workstation to a known command-and-control IP. Which IoC blocking method is MOST appropriate as an immediate containment measure?
10A company is developing a DR plan for a critical database. The maximum acceptable downtime is 2 hours, and the maximum data loss is 1 hour. What are the RTO and RPO?
11A security analyst is investigating a phishing incident that led to credential theft. Which TWO actions are appropriate during the containment phase? (Select TWO)
12During a ransomware incident, the incident response team needs to recover encrypted servers. Which THREE steps are essential for successful recovery? (Select THREE)
13Which TWO metrics are commonly tracked to measure the effectiveness of the incident response process? (Select TWO)
14During which phase of the NIST SP 800-61 incident response lifecycle are lessons learned meetings conducted and metrics such as MTTD and MTTR tracked?
15A security analyst receives an alert from the EDR system indicating that a workstation has been communicating with a known malicious IP address. The analyst confirms the alert and notes that the user is still logged in. Which immediate containment action should the analyst take FIRST?
16An organization's disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for its critical database. Which of the following DR site configurations BEST meets these requirements?
17Which of the following is the PRIMARY purpose of establishing a chain of custody when handling digital evidence?
18Which type of disaster recovery test involves running the DR systems alongside the production systems to validate functionality without impacting live operations?
19An incident responder needs to create a forensic image of a suspect hard drive. Which of the following steps is ESSENTIAL to ensure the integrity of the evidence?
20During a malware containment operation, the incident response team decides to isolate an infected endpoint using network access controls. However, the malware is spreading via removable media. Which additional containment measure should the team implement?
21An organization has suffered a ransomware attack that encrypted files on several file servers. The incident response team is planning recovery. Which TWO actions should be performed to verify that the restored systems are clean before returning them to production? (Select TWO)
22A forensic investigator is collecting evidence from a compromised Windows server. According to the order of volatility, which THREE pieces of evidence should be collected FIRST? (Select THREE)
23During the preparation phase of incident response, which TWO components are essential for an effective incident response plan? (Select TWO)
24An organization is developing its incident response plan. According to NIST SP 800-61, which phase should include establishing a communication plan, acquiring necessary tools, and conducting exercises?
25A security analyst detects a workstation communicating with a known command-and-control server. The workstation is running critical applications. What should be the analyst's first step according to the NIST incident response lifecycle?
26An organization has experienced a ransomware attack. After containing the incident, the response team plans to restore systems from backups. Which step is most critical before restoring production systems?
27Which of the following is the primary purpose of a chain of custody form in digital forensics?
28An incident responder needs to create a forensic image of a suspect hard drive. What is the correct procedure to ensure evidence integrity?
29A security team detects lateral movement within the network. Which containment strategy should be applied first to limit the spread of the threat?
30During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) was 14 days. Which improvement would most directly reduce MTTD?
31Which type of disaster recovery test involves running the DR systems alongside production systems to verify functionality without impacting operations?
32An organization's disaster recovery plan specifies an RPO of 4 hours and an RTO of 24 hours for a critical database. Which of the following best describes these metrics?
33During the detection and analysis phase, an analyst receives a user report of unusual system behavior. The analyst reviews logs and finds several failed login attempts followed by a successful login from an unusual IP address. What is the next step?
34An incident responder is collecting volatile evidence from a compromised Linux server. Which TWO of the following should be collected first? (Select two.)
35After a security incident, the response team holds a lessons learned meeting. Which TWO are primary objectives of this meeting? (Select two.)
36During the preparation phase of the incident response lifecycle, which of the following is the MOST important component to establish?
37An analyst detects suspicious outbound traffic from a server to a known command-and-control IP address. According to NIST SP 800-61, which phase of the incident response lifecycle does this activity fall under?
38A security analyst receives a user report about a workstation exhibiting unusual behavior, such as unexpected pop-ups and slow performance. The analyst first checks the antivirus logs and finds no alerts. What is the NEXT step in the detection and analysis phase?
39During a malware outbreak, a security analyst needs to contain the spread. The affected systems are on the same VLAN as critical servers. Which of the following containment actions should be performed FIRST to minimize impact?
40An incident responder is collecting evidence from a compromised server. Which of the following is the correct order for collecting volatile data?
41What is the primary purpose of establishing a chain of custody for digital evidence?
42During a forensic investigation, an examiner creates a bit-for-bit copy of a hard drive using a write blocker. What is the purpose of using a write blocker?
43An organization is restoring a critical database from a backup after a ransomware attack. Which of the following steps should be performed BEFORE restoring the data to ensure the restoration is successful and secure?
44Which metric is used to measure the average time it takes to detect an incident?
45After a security incident, the incident response team holds a lessons learned meeting. What is the PRIMARY outcome of this meeting?
46A company's disaster recovery plan specifies an RTO of 4 hours for its customer relationship management (CRM) system. Which of the following DR site types is MOST appropriate to meet this RTO?
47During a full interruption test of the disaster recovery plan, which of the following is the PRIMARY risk?
48A security analyst is responding to a malware incident on a Windows server. Which TWO actions should be taken to properly collect volatile evidence?
49During a post-incident review, the incident response team identifies several areas for improvement. According to NIST SP 800-61, which THREE activities are typically part of the post-incident activity phase?
50A company is conducting a disaster recovery test. Which TWO types of tests involve minimal risk to production operations?
51During the containment phase of incident response, a security analyst identifies malware on a critical server. Which TWO actions should be taken FIRST to contain the threat and preserve evidence? (Choose two.)
52After a ransomware incident, the incident response team is conducting recovery. Which THREE steps are essential to ensure a secure restoration and prevent reinfection? (Choose three.)
53During a post-incident review of a data breach, the incident response team is evaluating the chain of custody for forensic evidence. Which THREE practices demonstrate proper evidence handling? (Choose three.)
54A security analyst receives an alert from the SIEM about a possible malware infection on a workstation. The analyst confirms the infection and begins containment. Which of the following actions BEST aligns with the containment phase of the NIST SP 800-61 incident response lifecycle?
55A financial services firm has just contained a ransomware incident on a file server. The incident response plan requires a formal post-incident activity phase. The CISO wants to know what the team should do FIRST to improve future response. Which action best aligns with NIST SP 800-61 post-incident activity?
56A forensic examiner is preparing to acquire a disk image from a compromised server. The server is still running and contains critical evidence in volatile memory. According to NIST SP 800-86, which of the following should the examiner do FIRST?
57A security incident response team is reviewing their disaster recovery plan. They need to ensure that their backup strategy supports recovery from a ransomware attack that encrypts critical files. Which TWO of the following are essential characteristics of an effective backup strategy for this scenario? (Choose two.)
58A financial services firm's incident response team has just contained a malware outbreak on a file server. The server contains regulated customer data. The team lead instructs the responder to capture the current state of the system before any remediation. According to NIST SP 800-61, which action should the responder take FIRST to preserve the most volatile evidence?
59An incident responder is preparing to acquire volatile data from a compromised Linux server that is still powered on. The server hosts a critical database and cannot be shut down yet. According to order of volatility, which data source should the responder collect FIRST?
60A healthcare provider's incident response team is handling a suspected ransomware incident on a clinical workstation. The team lead wants to determine whether the incident should be escalated to a full response or handled as a false positive. According to NIST SP 800-61, which activity is part of the detection and analysis phase?
61A security analyst is reviewing the incident response plan and wants to ensure the containment strategy is effective for a recent malware outbreak. The analyst must choose containment measures that align with NIST SP 800-61. Which TWO actions are appropriate containment strategies? (Choose two.)
62After a major security incident, an organization conducts a lessons learned meeting. Which of the following is the PRIMARY purpose of this meeting?
63An incident responder is investigating a compromised Linux server and needs to collect volatile data. The responder has root access and wants to ensure that the data collected is admissible in a court of law. Which of the following commands should be used FIRST to capture the contents of physical memory?
64An incident response team is preparing to collect evidence from a compromised Linux web server. The team lead wants to ensure that the evidence will be admissible in a potential legal proceeding. Which TWO actions should the team take to maintain the integrity of the evidence? (Choose two.)
65After a security incident, an organization's legal team requests documentation that shows who had possession of a hard drive at every point from seizure to analysis. Which document should the incident responder provide?
66A security analyst is reviewing the organization's disaster recovery plan and notices that the Recovery Time Objective (RTO) for a critical application is 2 hours, but the current recovery process takes 8 hours. Which of the following should the analyst recommend FIRST?
67A healthcare organization's incident response team has just contained a ransomware outbreak that encrypted several file servers. Before restoring from backups, the incident response manager wants to ensure that the team can determine exactly how the attacker initially gained access and what data was exfiltrated. The organization does not have a dedicated forensic imaging solution, but the servers are still powered on and running. Which of the following actions BEST supports the investigation while preserving evidence?
68After a security incident at a retail company, the incident response team conducts a post-incident review. The team identifies that the attacker gained initial access through an unpatched web server. Which of the following is the PRIMARY purpose of the lessons learned meeting in this scenario?
69A security team is conducting a lessons learned meeting after a major security incident. The team identifies that the incident response plan was not followed because team members were unsure of their roles. Which of the following should be the PRIMARY outcome of this meeting to address the issue?
70An organization is conducting a disaster recovery test for its critical database. The RTO is 4 hours, and the RPO is 15 minutes. During the test, the team restores the database from a backup taken 2 hours before the test. The restore completes in 3 hours. Which statement accurately reflects the test outcome?
71A financial services firm's incident response plan defines a Recovery Time Objective (RTO) of 2 hours for its online trading platform. During a tabletop exercise, the team discovers that the current disaster recovery runbook requires manual steps that take approximately 6 hours to complete. The Chief Information Security Officer (CISO) asks for a recommendation to align the recovery capability with the RTO without increasing the budget significantly. Which of the following is the MOST appropriate recommendation?
72A multinational corporation has a disaster recovery plan with a Recovery Time Objective (RTO) of 2 hours for its customer-facing e-commerce platform. During a regional power outage, the primary data center goes offline. The DR team activates the hot site, but the database replication lag causes the e-commerce platform to come online after 5 hours. Which of the following should the incident response team do FIRST after restoring services?
73A security analyst is reviewing a disaster recovery plan and notes that the organization has a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 2 hours for a critical database. Which of the following backup strategies BEST meets these objectives?
74An incident responder is analyzing a network packet capture to determine the scope of a data exfiltration incident. The responder notices a large volume of outbound traffic to an unfamiliar IP address over port 443. Which of the following should the responder do FIRST to determine if the traffic is malicious?
75A security analyst is responding to a confirmed malware infection on a Windows workstation. The workstation is still powered on and connected to the corporate network. The analyst needs to collect volatile data that could be lost if the system is shut down or the malware is allowed to continue running. Which TWO of the following data sources should the analyst prioritize for collection? (Choose two.)
76A security team is conducting a lessons learned meeting after a major security incident. Which TWO of the following are PRIMARY objectives of this meeting? (Choose two.)
77A security analyst is reviewing the organization's incident response plan and wants to ensure it includes the necessary elements for the preparation phase according to NIST SP 800-61. Which of the following should be included in the preparation phase? (Choose two.)
78After a major security incident, an organization's incident response team conducts a lessons learned meeting. The team identifies that the communication plan was unclear, leading to delays in notifying stakeholders. Which of the following should be the PRIMARY outcome of this meeting?
79A security analyst is reviewing alerts and sees that a user's workstation has begun encrypting files with a new extension, and a ransom note has appeared on the desktop. The analyst confirms this is an active ransomware infection. According to NIST SP 800-61, which action should the analyst take FIRST during the containment phase?
80An incident responder is collecting evidence from a compromised Linux server. The responder uses the 'dd' command to create an image of the hard drive. Which of the following is the PRIMARY reason for using a write blocker during this process?
81A security analyst is documenting an incident that involved unauthorized access to a file server. The analyst needs to record the timeline of events, actions taken, and evidence collected. Which of the following is the PRIMARY purpose of maintaining proper documentation during incident response?
82A forensic examiner is preparing to acquire a forensic image of a running Linux server that is suspected of being compromised. The server has active network connections and encrypted volumes. Which of the following should the examiner do FIRST according to the order of volatility?
83An organization's incident response team has just completed the recovery phase of a major security incident. The team lead is now planning the post-incident activity. According to NIST SP 800-61, which of the following should be the PRIMARY focus of the lessons learned meeting?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to sequence incident response phases correctly and pick the right containment action first. The single most important thing: contain the threat before eradicating or recovering, while preserving evidence and following the IR plan.
The Courseiva SSCP question bank contains 83 questions in the Incident Response and Recovery domain, covering the 14% of the exam attributed to this domain in the official ISC2 blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Incident Response and Recovery domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included