Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

A security analyst is prioritizing incidents based on severity. Which TWO factors are most important for determining incident severity?

⚠ Common exam trap

CC often tests whether candidates confuse contextual response factors (time of day, OS type) with true impact drivers (data sensitivity, user count) — only the latter determine severity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sensitivity of the data potentially compromised

Option A is correct because the sensitivity of the data potentially compromised directly drives severity: exposure of regulated or high-classification data (e.g., PII, PHI, cardholder data under PCI DSS, or trade secrets) raises the potential impact and therefore the incident's severity rating. Option C is correct because the number of users affected measures the scope and blast radius of the incident, and broader impact across more accounts or systems generally elevates severity. The type of operating system involved (B) is not a primary severity factor, since impact depends on the affected assets and data rather than the OS platform itself. The time of day the incident occurred (D) is contextual and may influence response logistics but not the intrinsic severity. The color of the server room (E) is irrelevant to incident severity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Sensitivity of the data potentially compromised

    Why this is correct

    Sensitivity of the data potentially compromised directly determines severity because exposure of regulated, confidential or personal information raises legal, financial and reputational impact. It satisfies the prioritisation criterion by weighting potential harm, alongside factors such as affected system criticality.

  • ✗

    Type of operating system involved

    Why it's wrong here

    Operating system type alone does not establish the business impact or scope of an incident, so it cannot drive severity ranking. It is tempting because OS-specific vulnerabilities shape response steps, and it would be relevant when selecting remediation procedures or patch paths rather than prioritising incidents.

  • ✓

    Number of users affected

    Why this is correct

    Scope drives severity: an incident touching many accounts or endpoints demands more containment, notification and recovery effort than one affecting a single host. Counting affected users therefore quantifies blast radius, the factor that most directly escalates priority alongside data sensitivity.

  • ✗

    Time of day the incident occurred

    Why it's wrong here

    The clock time an incident occurred does not measure its impact or urgency, so it cannot determine severity. It is tempting because off-hours events can delay detection and response, and it would be relevant when assessing staffing coverage or after-hours escalation, not when scoring severity.

  • ✗

    Color of the server room

    Why it's wrong here

    Server room colour carries no bearing on impact or urgency, so it cannot rank incidents. It is tempting because physical environment details appear in asset inventories and audit checklists, and it would be relevant when assessing physical security controls, not when scoring an incident's severity.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.