Courseiva
Security Operations →hardMultiple Choice

ISC2 CC Security Operations Practice Question

A SOC analyst reviews a SIEM alert indicating a high volume of outbound traffic from a server to an external IP address known for command-and-control activity. The analyst has confirmed the alert is not a false positive. What is the most appropriate next step?

⚠ Common exam trap

CC often tests the order of incident response steps, and candidates may jump to containment (blocking) before investigation, which can be counterproductive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a deeper investigation to identify affected systems and data.

After confirming a SIEM alert is not a false positive, the most appropriate next step is to conduct a deeper investigation to identify affected systems and data. This aligns with the incident response process, where containment and eradication should be based on a thorough understanding of the scope and impact. Immediate blocking or rebooting without investigation could destroy evidence or disrupt business operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Escalate the alert to Tier 3 for advanced analysis.

    Why it's wrong here

    Escalating to Tier 3 hands off the incident without performing the immediate containment that an active, confirmed C2 beacon demands, allowing exfiltration to continue during the handover. It is tempting because Tier 3 handles advanced analysis, and would be correct when the alert requires deep forensic investigation beyond the analyst's remit.

  • ✓

    Conduct a deeper investigation to identify affected systems and data.

    Why this is correct

    With the alert confirmed genuine, the analyst must scope the compromise: identify which systems communicated with the command-and-control infrastructure and what data was accessed. Containment decisions depend on that evidence, so deeper investigation precedes remediation.

  • ✗

    Block the external IP address at the firewall immediately.

    Why it's wrong here

    Blocking the external IP at the firewall severs one known C2 channel but leaves the compromised server running and the attacker free to use another address or channel. It is tempting because it gives immediate containment, and would be correct when the malicious infrastructure is confirmed and blocking it will not disrupt legitimate business traffic.

  • ✗

    Reboot the server to terminate any malicious processes.

    Why it's wrong here

    Rebooting terminates running processes but destroys volatile evidence such as memory-resident malware, network connections and injected code, and the implant may persist via scheduled tasks or services. It is tempting because it appears to stop the activity instantly, and would be correct only when restoring a known-clean system after evidence has been captured.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.