Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

A mid-sized hospital's disaster recovery team is reviewing its incident response plan after a ransomware attack encrypted the electronic health record (EHR) system. The team determines that the attack began 36 hours before it was detected. Which incident response phase was most directly compromised by this delay?

⚠ Common exam trap

The trap here is assuming that a slow response is always a containment failure, when the scenario actually describes a delay in noticing the incident, which belongs to Detection and Analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detection and Analysis

The 36-hour gap between the onset of the ransomware attack and its discovery points directly to a failure in the Detection and Analysis phase, where monitoring and alerting should identify malicious activity quickly. While preparation, containment, and post-incident review all matter, the scenario describes a delay in recognizing the incident, which is the defining activity of detection and analysis. Improving detection capabilities would most directly address this gap.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Preparation

    Why it's wrong here

    Preparation involves creating policies, training staff, and deploying tools before an incident occurs. While better preparation such as endpoint detection could have shortened the delay, the specific failure described is that the organization did not identify the attack for 36 hours. Preparation is a proactive phase, not the phase where detection itself happens, so it is not the most directly compromised phase here.

  • ✗

    Post-Incident Activity

    Why it's wrong here

    Post-Incident Activity involves reviewing lessons learned and improving processes after the incident is resolved. Because the ransomware attack was only just detected and the EHR system remains encrypted, the organization has not reached this phase. The delay in discovery affects the earlier detection phase, not the post-incident review that happens much later.

  • ✓

    Detection and Analysis

    Why this is correct

    Detection and Analysis is the phase where monitoring tools, alerts, and staff identify that an incident is occurring and determine its scope. A 36-hour gap between the start of the ransomware attack and its discovery is a direct failure of this phase. The organization did not detect the unauthorized encryption activity in a timely manner, delaying the entire response effort.

  • ✗

    Containment, Eradication, and Recovery

    Why it's wrong here

    Containment, Eradication, and Recovery focuses on stopping the spread, removing the threat, and restoring systems after an incident is known. In this scenario, the team had not yet identified the attack, so it could not have begun containment. The 36-hour delay occurred before this phase could even start, making it a downstream consequence rather than the directly compromised phase.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.