ISC2 CC Security Operations Practice Question
A SOC analyst reviews a SIEM alert indicating a high volume of outbound traffic from a server to an external IP address known for command-and-control activity. The analyst has confirmed the alert is not a false positive. What is the most appropriate next step?
⚠ Common exam trap
CC often tests the order of incident response steps, and candidates may jump to containment (blocking) before investigation, which can be counterproductive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a deeper investigation to identify affected systems and data.
After confirming a SIEM alert is not a false positive, the most appropriate next step is to conduct a deeper investigation to identify affected systems and data. This aligns with the incident response process, where containment and eradication should be based on a thorough understanding of the scope and impact. Immediate blocking or rebooting without investigation could destroy evidence or disrupt business operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Escalate the alert to Tier 3 for advanced analysis.
Why it's wrong here
Escalating to Tier 3 hands off the incident without performing the immediate containment that an active, confirmed C2 beacon demands, allowing exfiltration to continue during the handover. It is tempting because Tier 3 handles advanced analysis, and would be correct when the alert requires deep forensic investigation beyond the analyst's remit.
- ✓
Conduct a deeper investigation to identify affected systems and data.
Why this is correct
With the alert confirmed genuine, the analyst must scope the compromise: identify which systems communicated with the command-and-control infrastructure and what data was accessed. Containment decisions depend on that evidence, so deeper investigation precedes remediation.
- ✗
Block the external IP address at the firewall immediately.
Why it's wrong here
Blocking the external IP at the firewall severs one known C2 channel but leaves the compromised server running and the attacker free to use another address or channel. It is tempting because it gives immediate containment, and would be correct when the malicious infrastructure is confirmed and blocking it will not disrupt legitimate business traffic.
- ✗
Reboot the server to terminate any malicious processes.
Why it's wrong here
Rebooting terminates running processes but destroys volatile evidence such as memory-resident malware, network connections and injected code, and the implant may persist via scheduled tasks or services. It is tempting because it appears to stop the activity instantly, and would be correct only when restoring a known-clean system after evidence has been captured.
Go deeper
Related to this question
Learn chapter
Security Operations Basics
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.