ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
A security analyst is prioritizing incidents based on severity. Which TWO factors are most important for determining incident severity?
⚠ Common exam trap
CC often tests whether candidates confuse contextual response factors (time of day, OS type) with true impact drivers (data sensitivity, user count) — only the latter determine severity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitivity of the data potentially compromised
Option A is correct because the sensitivity of the data potentially compromised directly drives severity: exposure of regulated or high-classification data (e.g., PII, PHI, cardholder data under PCI DSS, or trade secrets) raises the potential impact and therefore the incident's severity rating. Option C is correct because the number of users affected measures the scope and blast radius of the incident, and broader impact across more accounts or systems generally elevates severity. The type of operating system involved (B) is not a primary severity factor, since impact depends on the affected assets and data rather than the OS platform itself. The time of day the incident occurred (D) is contextual and may influence response logistics but not the intrinsic severity. The color of the server room (E) is irrelevant to incident severity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sensitivity of the data potentially compromised
Why this is correct
Sensitivity of the data potentially compromised directly determines severity because exposure of regulated, confidential or personal information raises legal, financial and reputational impact. It satisfies the prioritisation criterion by weighting potential harm, alongside factors such as affected system criticality.
- ✗
Type of operating system involved
Why it's wrong here
Operating system type alone does not establish the business impact or scope of an incident, so it cannot drive severity ranking. It is tempting because OS-specific vulnerabilities shape response steps, and it would be relevant when selecting remediation procedures or patch paths rather than prioritising incidents.
- ✓
Number of users affected
Why this is correct
Scope drives severity: an incident touching many accounts or endpoints demands more containment, notification and recovery effort than one affecting a single host. Counting affected users therefore quantifies blast radius, the factor that most directly escalates priority alongside data sensitivity.
- ✗
Time of day the incident occurred
Why it's wrong here
The clock time an incident occurred does not measure its impact or urgency, so it cannot determine severity. It is tempting because off-hours events can delay detection and response, and it would be relevant when assessing staffing coverage or after-hours escalation, not when scoring severity.
- ✗
Color of the server room
Why it's wrong here
Server room colour carries no bearing on impact or urgency, so it cannot rank incidents. It is tempting because physical environment details appear in asset inventories and audit checklists, and it would be relevant when assessing physical security controls, not when scoring an incident's severity.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
Incident severity
Incident severity is a classification used in IT incident management to describe the level of impact and urgency of an event, guiding response priority.
Key term
Remote Authentication Dial-in User Service
RADIUS is a network protocol that provides centralized authentication, authorization, and accounting for users trying to connect to a network service.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.