Courseiva
Security Operations →mediumMultiple Choice

ISC2 CC Security Operations Practice Question

A security administrator receives an alert that a user's laptop has been infected with ransomware. The user reports that all files on the laptop are encrypted and a ransom note is displayed. The administrator immediately disconnects the laptop from the network. Which of the following should be the NEXT step in the incident response process?

⚠ Common exam trap

The trap here is assuming that recovery or eradication should happen immediately after isolation, when in fact the next step is to identify scope and preserve evidence to avoid incomplete containment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify the scope of the incident and preserve evidence.

Once an infected system is isolated, the next critical step is to determine the full scope of the compromise and preserve evidence. This allows the organization to understand how the ransomware entered, what else may be affected, and how to eradicate it properly. Recovery actions such as restoring backups or rebuilding systems should come after containment and scoping are complete.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restore the encrypted files from the most recent backup.

    Why it's wrong here

    Restoring from backup is a recovery step that should occur only after containment and eradication. If the root cause is not addressed, the ransomware may re-encrypt restored files or spread to other systems. The immediate next step after isolating the infected laptop is to preserve evidence and determine the scope of the incident.

  • ✗

    Pay the ransom to obtain the decryption key and recover the files quickly.

    Why it's wrong here

    Paying the ransom is discouraged because it does not guarantee file recovery, may fund criminal activity, and can encourage further attacks. It also does not address the root cause or prevent future incidents. The immediate focus should be on containment, evidence preservation, and scoping the incident.

  • ✗

    Rebuild the laptop from scratch and return it to the user.

    Why it's wrong here

    Rebuilding the laptop may be part of recovery, but it should not be the immediate next step. Without understanding the scope and preserving evidence, rebuilding could destroy valuable forensic data and fail to prevent reinfection. The priority is to assess the extent of the compromise before wiping and rebuilding.

  • ✓

    Identify the scope of the incident and preserve evidence.

    Why this is correct

    After isolating the infected system, the next step is to determine how many other systems are affected and to preserve volatile evidence such as memory and logs. This aligns with the containment, eradication, and recovery phases of incident response. Identifying scope prevents further spread and informs subsequent eradication and recovery actions.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.