ISC2 CC Business Continuity, DR & Incident Response Practice Question
After a security incident has been contained and eradicated, which of the following should be done to improve future incident response?
⚠ Common exam trap
Many exam-takers confuse post-incident review with immediate remediation actions like reinstalling OS or disabling accounts, thinking they are 'improvements' rather than part of containment/eradication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a post-incident review
A post-incident review (also called a lessons-learned meeting) is the correct next step after containment and eradication because it systematically analyzes what went wrong, what worked, and what can be improved in the incident response plan. This review directly feeds into updating playbooks, refining detection rules, and adjusting security controls to prevent recurrence. Without this step, the organization misses the opportunity to close the loop on the incident lifecycle and may repeat the same mistakes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct a post-incident review
Why this is correct
A post-incident review examines what happened, why, and how controls failed, producing documented lessons and remediation actions. It directly satisfies the stem's requirement to improve future incident response after containment and eradication, feeding updates back into plans, playbooks and defences.
- ✗
Reinstall the operating system
Why it's wrong here
Reinstalling the operating system is a recovery action for a specific rebuilt host, not a process change that improves future response. It is tempting because it feels thorough and clean, and would be correct when eradication requires rebuilding a compromised system from trusted media.
- ✗
Disable the affected user accounts
Why it's wrong here
Disabling accounts is a containment action, already performed before eradication; repeating it after eradication adds no detection or prevention capability. It is tempting because account disablement feels security-hardening, and would be correct during containment to stop an active attacker using compromised credentials.
- ✗
Delete all incident-related logs
Why it's wrong here
Deleting incident logs destroys the forensic evidence needed for root-cause analysis and lessons-learned improvements. It is tempting because removing attacker artefacts feels like good hygiene, and would be correct only for securely retaining logs under a defined evidence-retention policy, never deleting them.
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.