SSCP Incident Response and Recovery • Set 2
SSCP Incident Response and Recovery Practice Test 2 — 15 questions with explanations. Free, no signup.
An organization's security team detects a potential data breach. After confirming the incident, they classify it as P2 (high severity) and begin containment. Which action should be performed FIRST to preserve evidence for forensic analysis?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.