Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

After an incident is resolved, which phase involves reviewing what happened, documenting lessons learned, and updating procedures?

⚠ Common exam trap

The trap is confusing the order of incident response phases — candidates may pick Recovery because it sounds like the final step, but the exam expects you to know that Lessons Learned is the post-incident review phase.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Lessons learned

The Lessons Learned phase occurs after an incident is resolved and focuses on reviewing the response, documenting what happened, and updating procedures to prevent recurrence. It is a post-incident activity, distinct from the active response phases. Containment, eradication, and recovery all happen during the incident lifecycle before lessons learned.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Eradication

    Why it's wrong here

    Eradication removes the root cause, such as malware or the exploited vulnerability, from affected systems; it does not cover post-incident review. Eradication would be the correct answer when the question asks which phase eliminates the threat, whereas lessons learned and procedure updates belong to post-incident activity.

  • ✗

    Containment

    Why it's wrong here

    Containment limits the incident's spread and impact while it is still active, so it occurs before resolution and cannot cover post-incident review. It is tempting because containment is a recognised incident-response phase; it would be correct when isolating affected systems to stop lateral movement during an ongoing breach.

  • ✓

    Lessons learned

    Why this is correct

    The lessons learned phase follows eradication and recovery, reviewing the incident, documenting findings and updating procedures to prevent recurrence. This matches the stem's post-resolution review, documentation and procedure-update criteria, distinguishing it from containment and recovery activities.

  • ✗

    Recovery

    Why it's wrong here

    Recovery restores and validates services after disruption, so it precedes the post-incident review rather than performing it. It is tempting because recovery is the final incident-response phase and does involve verification; it would be correct when restoring systems and confirming normal operations after containment and eradication.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.