ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
A retail company experiences a distributed denial-of-service (DDoS) attack that overwhelms its online store. The incident response team successfully mitigates the attack, and the store is back online. Which activity should the team perform as part of the post-incident activity phase?
⚠ Common exam trap
The trap here is choosing a technical remediation step like firewall changes or backups, when the question specifically asks for a post-incident activity, which is about review and improvement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a lessons-learned meeting to identify improvements in the DDoS response process.
After an incident is contained and systems are restored, the post-incident activity phase involves reviewing the event to improve future response. A lessons-learned meeting allows the team to document what happened, identify gaps, and update the incident response plan. This is the key activity that distinguishes post-incident work from ongoing operational tasks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct a lessons-learned meeting to identify improvements in the DDoS response process.
Why this is correct
The post-incident activity phase is designed to review the incident, gather feedback from responders, and update plans and controls. A lessons-learned meeting helps the retail company understand how the DDoS was detected, what worked well, and what needs improvement. This aligns with the goal of continuous improvement and is a core activity after the incident is closed.
- ✗
Notify law enforcement and press charges against the attackers.
Why it's wrong here
Notifying law enforcement may be appropriate depending on the organization's policies and the severity of the attack, but it is not the primary post-incident activity for process improvement. The post-incident phase emphasizes internal review, documentation, and updating response capabilities. Legal action is a separate consideration and not a substitute for the lessons-learned process.
- ✗
Immediately reconfigure the firewall to block the attacking IP addresses.
Why it's wrong here
Blocking attacking IP addresses is a containment action that should occur during the incident, not after it. Post-incident activity focuses on reviewing what happened, documenting lessons learned, and improving future response. Reconfiguring the firewall may be part of remediation, but it is not the primary activity once the incident is resolved and the store is back online.
- ✗
Restore the online store from the most recent backup.
Why it's wrong here
Restoring from backup is a recovery step that may be necessary if data was corrupted or lost. In a DDoS attack, the primary issue is availability, not data integrity, and the store is already back online. Performing a restore after the incident could introduce unnecessary downtime and is not a post-incident review activity, which focuses on analysis and improvement.
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Distributed Denial-of-service
A cyberattack where many compromised computers flood a target system with traffic, making it unavailable to legitimate users.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.