ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
After an incident is resolved, which phase involves reviewing what happened, documenting lessons learned, and updating procedures?
⚠ Common exam trap
The trap is confusing the order of incident response phases — candidates may pick Recovery because it sounds like the final step, but the exam expects you to know that Lessons Learned is the post-incident review phase.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lessons learned
The Lessons Learned phase occurs after an incident is resolved and focuses on reviewing the response, documenting what happened, and updating procedures to prevent recurrence. It is a post-incident activity, distinct from the active response phases. Containment, eradication, and recovery all happen during the incident lifecycle before lessons learned.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Eradication
Why it's wrong here
Eradication removes the root cause, such as malware or the exploited vulnerability, from affected systems; it does not cover post-incident review. Eradication would be the correct answer when the question asks which phase eliminates the threat, whereas lessons learned and procedure updates belong to post-incident activity.
- ✗
Containment
Why it's wrong here
Containment limits the incident's spread and impact while it is still active, so it occurs before resolution and cannot cover post-incident review. It is tempting because containment is a recognised incident-response phase; it would be correct when isolating affected systems to stop lateral movement during an ongoing breach.
- ✓
Lessons learned
Why this is correct
The lessons learned phase follows eradication and recovery, reviewing the incident, documenting findings and updating procedures to prevent recurrence. This matches the stem's post-resolution review, documentation and procedure-update criteria, distinguishing it from containment and recovery activities.
- ✗
Recovery
Why it's wrong here
Recovery restores and validates services after disruption, so it precedes the post-incident review rather than performing it. It is tempting because recovery is the final incident-response phase and does involve verification; it would be correct when restoring systems and confirming normal operations after containment and eradication.
Visual reference
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Eradication
Eradication is the phase in incident response where the root cause of a security breach is completely removed from the system to prevent the attack from happening again.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.