ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
A security analyst detects unusual outbound network traffic from a server that normally does not communicate externally. After confirming a malware infection, the analyst isolates the server from the network. Which incident response phase is the analyst performing?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Containment
Isolating the server is a containment action to prevent spread.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Recovery
Why it's wrong here
Recovery restores and returns systems to production after the threat is removed, whereas isolation merely contains the server. It is tempting because recovery is the phase that eventually returns the host to service, but no restoration, validation or monitoring has occurred yet.
- ✗
Detection
Why it's wrong here
Detection is identifying that an incident occurred; the analyst has already confirmed the malware infection and moved to act. It is tempting because the unusual traffic was initially detected, but the isolation action itself is containment, not detection.
- ✓
Containment
Why this is correct
Isolation halts the malware's spread and external communication while the environment is still compromised, which is the containment phase's defining action. It sits between detection and eradication, satisfying the stem's need to stop ongoing impact before recovery begins.
- ✗
Eradication
Why it's wrong here
Isolation contains the threat; eradication is the later step of removing malware, reimaging or patching the infected host. It is tempting because eradication follows containment in the response lifecycle, but the analyst has only quarantined the server, not yet eliminated the malicious code.
Go deeper
Related to this question
Learn chapter
Network Security Foundations
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.