Courseiva

ISC2 CC Business Continuity, DR & Incident Response Practice Question

After a security incident has been contained and eradicated, which of the following should be done to improve future incident response?

⚠ Common exam trap

Many exam-takers confuse post-incident review with immediate remediation actions like reinstalling OS or disabling accounts, thinking they are 'improvements' rather than part of containment/eradication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a post-incident review

A post-incident review (also called a lessons-learned meeting) is the correct next step after containment and eradication because it systematically analyzes what went wrong, what worked, and what can be improved in the incident response plan. This review directly feeds into updating playbooks, refining detection rules, and adjusting security controls to prevent recurrence. Without this step, the organization misses the opportunity to close the loop on the incident lifecycle and may repeat the same mistakes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conduct a post-incident review

    Why this is correct

    A post-incident review examines what happened, why, and how controls failed, producing documented lessons and remediation actions. It directly satisfies the stem's requirement to improve future incident response after containment and eradication, feeding updates back into plans, playbooks and defences.

  • ✗

    Reinstall the operating system

    Why it's wrong here

    Reinstalling the operating system is a recovery action for a specific rebuilt host, not a process change that improves future response. It is tempting because it feels thorough and clean, and would be correct when eradication requires rebuilding a compromised system from trusted media.

  • ✗

    Disable the affected user accounts

    Why it's wrong here

    Disabling accounts is a containment action, already performed before eradication; repeating it after eradication adds no detection or prevention capability. It is tempting because account disablement feels security-hardening, and would be correct during containment to stop an active attacker using compromised credentials.

  • ✗

    Delete all incident-related logs

    Why it's wrong here

    Deleting incident logs destroys the forensic evidence needed for root-cause analysis and lessons-learned improvements. It is tempting because removing attacker artefacts feels like good hygiene, and would be correct only for securely retaining logs under a defined evidence-retention policy, never deleting them.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.