Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

A security analyst detects unusual outbound network traffic from a server that typically only handles internal file sharing. The traffic appears to be exfiltrating sensitive data. Which phase of the incident response process should the analyst initiate next?

⚠ Common exam trap

It's easy for candidates to confuse the order of incident response phases; candidates might jump to containment because it seems urgent, but the exam expects adherence to the standard sequence where analysis precedes containment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analysis

The analyst has detected unusual outbound traffic indicating potential data exfiltration. According to the incident response process, after detection and initial validation, the next phase is analysis, where the analyst investigates the scope, impact, and nature of the incident. Containment (A) would come after analysis to prevent further damage. Eradication (D) and lessons learned (C) are later phases. Therefore, the analyst should initiate analysis next.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Containment

    Why it's wrong here

    Containment isolates affected systems to stop the spread, but the analyst has only detected and is still analysing; the next phase is analysis, to scope the exfiltration and confirm the compromise. Containment follows once the incident's extent is understood.

  • ✓

    Analysis

    Why this is correct

    Analysis follows detection: the analyst must validate the alert, scope the exfiltration, and determine impact before escalating. This phase satisfies the stem's need to confirm and understand the suspicious outbound traffic prior to containment or eradication.

  • ✗

    Lessons learned

    Why it's wrong here

    Lessons learned is a post-incident review held after containment, eradication and recovery are complete, so it cannot address live exfiltration. It is tempting because documenting findings improves future response, and it would be correct once the incident is fully resolved and closed.

  • ✗

    Eradication

    Why it's wrong here

    Eradication removes the threat’s foothold, such as deleting malware or closing the exploited entry point, but the analyst has only detected exfiltration and not yet contained it. It is tempting because eradication follows containment in most frameworks, and would be correct once the threat is isolated and its mechanism identified.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.