ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
A security analyst detects unusual outbound network traffic from a server that typically only handles internal file sharing. The traffic appears to be exfiltrating sensitive data. Which phase of the incident response process should the analyst initiate next?
⚠ Common exam trap
It's easy for candidates to confuse the order of incident response phases; candidates might jump to containment because it seems urgent, but the exam expects adherence to the standard sequence where analysis precedes containment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analysis
The analyst has detected unusual outbound traffic indicating potential data exfiltration. According to the incident response process, after detection and initial validation, the next phase is analysis, where the analyst investigates the scope, impact, and nature of the incident. Containment (A) would come after analysis to prevent further damage. Eradication (D) and lessons learned (C) are later phases. Therefore, the analyst should initiate analysis next.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Containment
Why it's wrong here
Containment isolates affected systems to stop the spread, but the analyst has only detected and is still analysing; the next phase is analysis, to scope the exfiltration and confirm the compromise. Containment follows once the incident's extent is understood.
- ✓
Analysis
Why this is correct
Analysis follows detection: the analyst must validate the alert, scope the exfiltration, and determine impact before escalating. This phase satisfies the stem's need to confirm and understand the suspicious outbound traffic prior to containment or eradication.
- ✗
Lessons learned
Why it's wrong here
Lessons learned is a post-incident review held after containment, eradication and recovery are complete, so it cannot address live exfiltration. It is tempting because documenting findings improves future response, and it would be correct once the incident is fully resolved and closed.
- ✗
Eradication
Why it's wrong here
Eradication removes the threat’s foothold, such as deleting malware or closing the exploited entry point, but the analyst has only detected exfiltration and not yet contained it. It is tempting because eradication follows containment in most frameworks, and would be correct once the threat is isolated and its mechanism identified.
Go deeper
Related to this question
Learn chapter
Network Security Foundations
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.