Courseiva

ISC2 CC Business Continuity, DR & Incident Response Practice Question

A mid-sized hospital experiences a ransomware outbreak that encrypts its electronic health record (EHR) servers on a Friday night. The incident response plan designates a severity classification of 'Critical'. According to established incident response practices, which action should the incident response team take FIRST?

⚠ Common exam trap

The trap here is assuming that immediately restoring from backup or shutting down servers is the fastest fix, when containment and evidence preservation must occur first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the affected systems from the network to contain the spread while preserving evidence

The first priority in an active ransomware incident is to contain the spread while preserving evidence, so isolating affected systems from the network is the correct initial action. Containment prevents further encryption of shared resources and backup repositories. It also keeps the systems in a state suitable for forensic analysis, which is needed to determine scope and root cause before eradication and recovery efforts begin.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restore the EHR servers from the most recent backup immediately so clinical operations can resume

    Why it's wrong here

    Immediate restoration before containment and eradication risks reintroducing the ransomware or re-infecting restored systems if the root cause is not addressed. Restoring also overwrites the compromised environment, hampering forensics and potentially destroying evidence of how the attacker gained access. Recovery should follow containment and eradication, not precede them, especially for a critical severity incident.

  • ✗

    Notify all hospital staff and patients about the breach before taking any technical action

    Why it's wrong here

    Communication and notification are important, but they are not the immediate technical priority during active encryption. Notifying staff broadly before containment could cause confusion and tip off attackers who may still have access. Regulatory and patient notifications follow legal and privacy review, and premature disclosure without accurate scope information can misinform stakeholders and create liability.

  • ✗

    Immediately power down all affected EHR servers to stop the encryption from spreading further

    Why it's wrong here

    Powering down encrypted servers destroys volatile evidence such as RAM contents, running processes, and network connections that are essential for forensic analysis and scoping the breach. It also does not guarantee stopping the malware, which may have already spread to other systems. Isolation through network segmentation is a more controlled and forensically sound containment step than abrupt shutdown.

  • ✓

    Isolate the affected systems from the network to contain the spread while preserving evidence

    Why this is correct

    Isolating affected systems from the network is the standard containment action that limits further propagation of ransomware while preserving the state of the systems for forensic investigation. It aligns with the containment phase of incident response and prevents additional encryption of connected file shares and backups. This controlled isolation supports both damage limitation and evidence collection, which are core goals at this stage.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.