Courseiva

ISC2 CC Business Continuity, DR & Incident Response Practice Question

An organization has detected a ransomware infection. What is the FIRST step in the incident response process?

⚠ Common exam trap

The trap is choosing 'run antivirus scans' because it feels like an immediate technical fix, but the exam tests the NIST ordering where containment must precede eradication to prevent further spread.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate affected systems

Isolating affected systems is the correct first step because containment stops the ransomware from spreading laterally to other hosts and encrypting additional data, preserving evidence and limiting blast radius. In standard incident response frameworks such as NIST SP 800-61, containment immediately follows detection and precedes eradication, recovery, and any external reporting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Isolate affected systems

    Why this is correct

    Isolating affected systems immediately contains the ransomware, preventing lateral spread to file shares and other hosts while forensic evidence is preserved. Containment precedes eradication and recovery, satisfying the stem's requirement for the first incident response step: stopping active encryption before it reaches further assets.

  • ✗

    Pay the ransom

    Why it's wrong here

    Paying the ransom funds criminal activity and does not guarantee data recovery; it is never a prescribed incident response step. The first step is preparation, then detection and analysis, followed by containment. Payment might be considered only as a last-resort business decision after containment.

  • ✗

    Run antivirus scans

    Why it's wrong here

    Scanning treats the infection rather than containing it, so the ransomware keeps encrypting shares and spreading laterally while the scan runs. Antivirus scans belong in the eradication and recovery phases, after isolation, to confirm no residual malware remains before restoring systems.

  • ✗

    Report to law enforcement

    Why it's wrong here

    Notification to law enforcement occurs during post-incident activity or coordination, after containment and eradication. The first step is preparation, followed by detection and analysis, then containment. Reporting would be appropriate once the incident is contained and evidence preserved.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.