Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

A multinational corporation is reviewing its incident response plan after a recent data breach. The security team wants to ensure that during future incidents, evidence is properly preserved for potential legal action. Which TWO actions should be included in the incident response plan to support forensic readiness? (Choose two.)

⚠ Common exam trap

The trap here is assuming that immediate shutdown is a good containment step, when it actually destroys volatile evidence and undermines forensic readiness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establish a chain of custody for all collected evidence.

Forensic readiness requires that evidence be preserved in a way that is admissible in legal proceedings. Establishing a chain of custody ensures evidence integrity, and training responders on evidence handling ensures that procedures are followed correctly. Together, these actions help a multinational corporation maintain credible evidence for potential litigation or regulatory investigations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Establish a chain of custody for all collected evidence.

    Why this is correct

    A chain of custody documents who handled evidence, when, and why, ensuring its integrity and admissibility in legal proceedings. For a multinational corporation, this is essential to prove that digital evidence from the breach was not tampered with. It should be part of the incident response plan so that responders know how to label, store, and transfer evidence properly from the moment it is collected.

  • ✗

    Allow only senior management to access the incident response plan.

    Why it's wrong here

    Restricting access to the incident response plan would hinder responders who need to follow it during an incident. Forensic readiness requires that all relevant personnel understand their roles in evidence preservation. Senior management should be aware of the plan, but limiting access to them alone would delay response and increase the chance of evidence being compromised due to lack of procedural knowledge.

  • ✗

    Immediately shut down all affected systems to prevent further data loss.

    Why it's wrong here

    Shutting down systems can destroy volatile evidence such as memory contents, running processes, and network connections. In forensic readiness, the goal is to preserve evidence, not to power off systems hastily. While containment is important, the plan should specify how to capture volatile data before any shutdown, and shutdown should be a last resort to avoid losing critical forensic artifacts.

  • ✗

    Delete all logs after 30 days to reduce storage costs.

    Why it's wrong here

    Deleting logs after 30 days can destroy evidence that may be needed for legal action or forensic analysis. In a data breach, logs are often critical for determining the scope and timeline of the incident. A forensic readiness plan should specify retention periods that align with legal and regulatory requirements, not arbitrary deletion for cost savings. Retaining logs is essential for reconstruction and attribution.

  • ✓

    Conduct regular training for incident responders on evidence handling procedures.

    Why this is correct

    Regular training ensures that incident responders know how to identify, collect, and preserve evidence correctly. For a multinational corporation, different legal jurisdictions may have varying requirements, so consistent training is vital. This action supports forensic readiness by building the skills needed to maintain evidence integrity from the first responder through to legal handoff, reducing the risk of mishandling that could invalidate evidence.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.