ISC2 CC Business Continuity, DR & Incident Response Practice Question
A hospital's incident response team is drafting the post-incident activity phase of its plan after a recent malware outbreak. Which two activities belong in this phase? (Choose two.)
⚠ Common exam trap
The trap here is mixing actions from the containment, eradication, and recovery phases into the post-incident phase, when post-incident work is about review and improvement after systems are restored.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the incident response plan and detection signatures based on findings from the investigation
Post-incident activity focuses on learning from the event and improving future response. Conducting a lessons-learned review identifies root cause and gaps, while updating the incident response plan and detection signatures institutionalizes those findings. Containment, eradication, and recovery actions occur earlier in the lifecycle, so isolating hosts, removing malware, or activating a recovery site do not belong in the post-incident phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Update the incident response plan and detection signatures based on findings from the investigation
Why this is correct
Post-incident activity includes incorporating lessons learned into updated procedures, controls, and detection content so the same weakness is less likely to be exploited again. Revising the incident response plan and tuning detection signatures directly reflects the findings of the investigation. This closes the loop between response and preparation, improving the hospital's posture for the next incident.
- ✗
Eradicate the malware by removing malicious files and disabling the persistence mechanism
Why it's wrong here
Eradication is a distinct phase that occurs after containment and before recovery. It involves deleting malicious artifacts, closing the initial access vector, and removing backdoors. This activity happens while the incident is still being actively handled, not during the post-incident review. Placing eradication in the post-incident phase confuses the sequence of the incident response lifecycle.
- ✓
Conduct a lessons-learned review with stakeholders to identify root cause and improve future response
Why this is correct
The post-incident activity phase centers on reviewing what happened, determining root cause, and feeding improvements back into the plan, detection rules, and controls. A structured lessons-learned session with the response team, IT, and business stakeholders captures gaps and produces actionable changes. This is a core post-incident activity that turns a single event into organizational learning.
- ✗
Activate the disaster recovery site so clinical applications continue to run during the outage
Why it's wrong here
Activating a disaster recovery site is a recovery action, part of the recovery phase, and is triggered when primary systems are unavailable. It is not a post-incident activity. By the time post-incident review begins, clinical applications should already be running normally. Including site activation here misplaces a recovery step and would leave the review phase undefined.
- ✗
Isolate infected workstations from the network to prevent the malware from reaching other systems
Why it's wrong here
Isolation is a containment action performed while the incident is active, not during post-incident activity. By the time the organization reaches the post-incident phase, the threat has been eradicated and systems recovered. Isolating hosts after the fact would be pointless and could disrupt restored clinical services. This action belongs in the containment step of the response lifecycle.
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.