ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
A multinational corporation is reviewing its incident response plan after a recent data breach. The security team wants to ensure that during future incidents, evidence is properly preserved for potential legal action. Which TWO actions should be included in the incident response plan to support forensic readiness? (Choose two.)
⚠ Common exam trap
The trap here is assuming that immediate shutdown is a good containment step, when it actually destroys volatile evidence and undermines forensic readiness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish a chain of custody for all collected evidence.
Forensic readiness requires that evidence be preserved in a way that is admissible in legal proceedings. Establishing a chain of custody ensures evidence integrity, and training responders on evidence handling ensures that procedures are followed correctly. Together, these actions help a multinational corporation maintain credible evidence for potential litigation or regulatory investigations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Establish a chain of custody for all collected evidence.
Why this is correct
A chain of custody documents who handled evidence, when, and why, ensuring its integrity and admissibility in legal proceedings. For a multinational corporation, this is essential to prove that digital evidence from the breach was not tampered with. It should be part of the incident response plan so that responders know how to label, store, and transfer evidence properly from the moment it is collected.
- ✗
Allow only senior management to access the incident response plan.
Why it's wrong here
Restricting access to the incident response plan would hinder responders who need to follow it during an incident. Forensic readiness requires that all relevant personnel understand their roles in evidence preservation. Senior management should be aware of the plan, but limiting access to them alone would delay response and increase the chance of evidence being compromised due to lack of procedural knowledge.
- ✗
Immediately shut down all affected systems to prevent further data loss.
Why it's wrong here
Shutting down systems can destroy volatile evidence such as memory contents, running processes, and network connections. In forensic readiness, the goal is to preserve evidence, not to power off systems hastily. While containment is important, the plan should specify how to capture volatile data before any shutdown, and shutdown should be a last resort to avoid losing critical forensic artifacts.
- ✗
Delete all logs after 30 days to reduce storage costs.
Why it's wrong here
Deleting logs after 30 days can destroy evidence that may be needed for legal action or forensic analysis. In a data breach, logs are often critical for determining the scope and timeline of the incident. A forensic readiness plan should specify retention periods that align with legal and regulatory requirements, not arbitrary deletion for cost savings. Retaining logs is essential for reconstruction and attribution.
- ✓
Conduct regular training for incident responders on evidence handling procedures.
Why this is correct
Regular training ensures that incident responders know how to identify, collect, and preserve evidence correctly. For a multinational corporation, different legal jurisdictions may have varying requirements, so consistent training is vital. This action supports forensic readiness by building the skills needed to maintain evidence integrity from the first responder through to legal handoff, reducing the risk of mishandling that could invalidate evidence.
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Chain of custody
Chain of custody is a documented process that tracks the handling, transfer, and possession of evidence or digital assets from the moment they are collected until they are presented in court or used in an investigation.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.