ISC2 CC Security Operations Practice Question
A security administrator receives an alert that a user's laptop has been infected with ransomware. The user reports that all files on the laptop are encrypted and a ransom note is displayed. The administrator immediately disconnects the laptop from the network. Which of the following should be the NEXT step in the incident response process?
⚠ Common exam trap
The trap here is assuming that recovery or eradication should happen immediately after isolation, when in fact the next step is to identify scope and preserve evidence to avoid incomplete containment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify the scope of the incident and preserve evidence.
Once an infected system is isolated, the next critical step is to determine the full scope of the compromise and preserve evidence. This allows the organization to understand how the ransomware entered, what else may be affected, and how to eradicate it properly. Recovery actions such as restoring backups or rebuilding systems should come after containment and scoping are complete.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restore the encrypted files from the most recent backup.
Why it's wrong here
Restoring from backup is a recovery step that should occur only after containment and eradication. If the root cause is not addressed, the ransomware may re-encrypt restored files or spread to other systems. The immediate next step after isolating the infected laptop is to preserve evidence and determine the scope of the incident.
- ✗
Pay the ransom to obtain the decryption key and recover the files quickly.
Why it's wrong here
Paying the ransom is discouraged because it does not guarantee file recovery, may fund criminal activity, and can encourage further attacks. It also does not address the root cause or prevent future incidents. The immediate focus should be on containment, evidence preservation, and scoping the incident.
- ✗
Rebuild the laptop from scratch and return it to the user.
Why it's wrong here
Rebuilding the laptop may be part of recovery, but it should not be the immediate next step. Without understanding the scope and preserving evidence, rebuilding could destroy valuable forensic data and fail to prevent reinfection. The priority is to assess the extent of the compromise before wiping and rebuilding.
- ✓
Identify the scope of the incident and preserve evidence.
Why this is correct
After isolating the infected system, the next step is to determine how many other systems are affected and to preserve volatile evidence such as memory and logs. This aligns with the containment, eradication, and recovery phases of incident response. Identifying scope prevents further spread and informs subsequent eradication and recovery actions.
Go deeper
Related to this question
Learn chapter
Network Security Foundations
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.