Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

A security analyst detects unusual outbound network traffic from a server that normally does not communicate externally. After confirming a malware infection, the analyst isolates the server from the network. Which incident response phase is the analyst performing?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Containment

Isolating the server is a containment action to prevent spread.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Recovery

    Why it's wrong here

    Recovery restores and returns systems to production after the threat is removed, whereas isolation merely contains the server. It is tempting because recovery is the phase that eventually returns the host to service, but no restoration, validation or monitoring has occurred yet.

  • ✗

    Detection

    Why it's wrong here

    Detection is identifying that an incident occurred; the analyst has already confirmed the malware infection and moved to act. It is tempting because the unusual traffic was initially detected, but the isolation action itself is containment, not detection.

  • ✓

    Containment

    Why this is correct

    Isolation halts the malware's spread and external communication while the environment is still compromised, which is the containment phase's defining action. It sits between detection and eradication, satisfying the stem's need to stop ongoing impact before recovery begins.

  • ✗

    Eradication

    Why it's wrong here

    Isolation contains the threat; eradication is the later step of removing malware, reimaging or patching the infected host. It is tempting because eradication follows containment in the response lifecycle, but the analyst has only quarantined the server, not yet eliminated the malicious code.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.