Courseiva

ISC2 CC Business Continuity, DR & Incident Response Practice Question

A hospital's incident response team is drafting the post-incident activity phase of its plan after a recent malware outbreak. Which two activities belong in this phase? (Choose two.)

⚠ Common exam trap

The trap here is mixing actions from the containment, eradication, and recovery phases into the post-incident phase, when post-incident work is about review and improvement after systems are restored.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the incident response plan and detection signatures based on findings from the investigation

Post-incident activity focuses on learning from the event and improving future response. Conducting a lessons-learned review identifies root cause and gaps, while updating the incident response plan and detection signatures institutionalizes those findings. Containment, eradication, and recovery actions occur earlier in the lifecycle, so isolating hosts, removing malware, or activating a recovery site do not belong in the post-incident phase.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Update the incident response plan and detection signatures based on findings from the investigation

    Why this is correct

    Post-incident activity includes incorporating lessons learned into updated procedures, controls, and detection content so the same weakness is less likely to be exploited again. Revising the incident response plan and tuning detection signatures directly reflects the findings of the investigation. This closes the loop between response and preparation, improving the hospital's posture for the next incident.

  • ✗

    Eradicate the malware by removing malicious files and disabling the persistence mechanism

    Why it's wrong here

    Eradication is a distinct phase that occurs after containment and before recovery. It involves deleting malicious artifacts, closing the initial access vector, and removing backdoors. This activity happens while the incident is still being actively handled, not during the post-incident review. Placing eradication in the post-incident phase confuses the sequence of the incident response lifecycle.

  • ✓

    Conduct a lessons-learned review with stakeholders to identify root cause and improve future response

    Why this is correct

    The post-incident activity phase centers on reviewing what happened, determining root cause, and feeding improvements back into the plan, detection rules, and controls. A structured lessons-learned session with the response team, IT, and business stakeholders captures gaps and produces actionable changes. This is a core post-incident activity that turns a single event into organizational learning.

  • ✗

    Activate the disaster recovery site so clinical applications continue to run during the outage

    Why it's wrong here

    Activating a disaster recovery site is a recovery action, part of the recovery phase, and is triggered when primary systems are unavailable. It is not a post-incident activity. By the time post-incident review begins, clinical applications should already be running normally. Including site activation here misplaces a recovery step and would leave the review phase undefined.

  • ✗

    Isolate infected workstations from the network to prevent the malware from reaching other systems

    Why it's wrong here

    Isolation is a containment action performed while the incident is active, not during post-incident activity. By the time the organization reaches the post-incident phase, the threat has been eradicated and systems recovered. Isolating hosts after the fact would be pointless and could disrupt restored clinical services. This action belongs in the containment step of the response lifecycle.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.