ISC2 CC Business Continuity, DR & Incident Response Practice Question
An organization has detected a ransomware infection. What is the FIRST step in the incident response process?
⚠ Common exam trap
The trap is choosing 'run antivirus scans' because it feels like an immediate technical fix, but the exam tests the NIST ordering where containment must precede eradication to prevent further spread.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate affected systems
Isolating affected systems is the correct first step because containment stops the ransomware from spreading laterally to other hosts and encrypting additional data, preserving evidence and limiting blast radius. In standard incident response frameworks such as NIST SP 800-61, containment immediately follows detection and precedes eradication, recovery, and any external reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Isolate affected systems
Why this is correct
Isolating affected systems immediately contains the ransomware, preventing lateral spread to file shares and other hosts while forensic evidence is preserved. Containment precedes eradication and recovery, satisfying the stem's requirement for the first incident response step: stopping active encryption before it reaches further assets.
- ✗
Pay the ransom
Why it's wrong here
Paying the ransom funds criminal activity and does not guarantee data recovery; it is never a prescribed incident response step. The first step is preparation, then detection and analysis, followed by containment. Payment might be considered only as a last-resort business decision after containment.
- ✗
Run antivirus scans
Why it's wrong here
Scanning treats the infection rather than containing it, so the ransomware keeps encrypting shares and spreading laterally while the scan runs. Antivirus scans belong in the eradication and recovery phases, after isolation, to confirm no residual malware remains before restoring systems.
- ✗
Report to law enforcement
Why it's wrong here
Notification to law enforcement occurs during post-incident activity or coordination, after containment and eradication. The first step is preparation, followed by detection and analysis, then containment. Reporting would be appropriate once the incident is contained and evidence preserved.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.