220-1102 Operational Procedures Practice Question
According to IT best practices, which of the following is a key component of an incident response plan?
⚠ Common exam trap
Many candidates confuse preventative maintenance tasks (like software updates) with reactive incident response procedures, leading candidates to choose Option D because they associate 'updates' with security, but incident response plans focus on actions taken *after* an incident, not before.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A procedure for data recovery
An incident response plan must include a procedure for data recovery to ensure that after a security incident (e.g., ransomware attack, data breach), critical systems and data can be restored from verified backups. This aligns with the NIST SP 800-61 incident response lifecycle, specifically the 'recovery' phase, which aims to return operations to normal while preserving forensic evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A list of all employees' personal email addresses
Why it's wrong here
Incident response plans specify official roles, escalation contacts, and communication channels via corporate systems; a blanket list of every employee's personal email addresses introduces privacy and security risks, is not operationally actionable for most responders, and does not support the structured notification procedures required during an incident.
- ✓
A procedure for data recovery
Why this is correct
A procedure for data recovery is a core component of an incident response plan because it defines the ordered steps to restore affected systems and data from verified backups, including validation and reconnection, which is essential for returning to normal operations after events like ransomware or hardware failure. It ensures that responders know the backup locations, recovery point objectives, and how to verify data integrity before restoring production.
- ✗
The names of company executives
Why it's wrong here
Incident response plans typically identify notification and decision-making roles by job title or function, not by listing the names of current executives, because personnel change and the plan must remain current. Executives are informed through defined escalation procedures; a static name list does not aid the technical response and can quickly become outdated.
- ✗
The schedule for software updates
Why it's wrong here
Software update schedules fall under change and patch management, which are proactive maintenance processes, not under incident response. The incident response plan focuses on detection, containment, eradication, and recovery actions to be taken during and immediately after an incident, so a routine patch calendar is out of scope. While poor patch management can contribute to incidents, the schedule itself is not a key element of the response playbook.
Go deeper
Related to this question
Learn chapter
Data Sanitization: Wipe, Degauss, Shred, Incinerate
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.