Courseiva

CCNA Business Continuity, DR & Incident Response Questions

64 questions · Business Continuity, DR & Incident Response · All types, answers revealed

1
MCQhard

Refer to the exhibit. Which statement best describes compliance with the recovery objectives?

A.Compliant with both RTO and RPO
B.Compliant with RTO but not RPO
C.Compliant with neither
D.Compliant with RPO but not RTO
AnswerB

RTO likely achievable, but RPO is violated due to infrequent backups.

Why this answer

The exhibit shows the required RTO is 4 hours and the actual RTO is 4 hours, meaning the system recovers within the allowed downtime, so it is compliant with RTO. However, the backup interval is 4 hours, so the actual RPO is 4 hours, which exceeds the required RPO of 1 hour. This means up to 4 hours of data could be lost, failing RPO compliance.

Therefore, the correct answer is B.

Exam trap

ISC2 often tests the distinction between RTO and RPO by presenting a scenario where one objective is met and the other is not, and the trap is that candidates confuse which metric measures downtime versus data loss, leading them to incorrectly select A or D.

How to eliminate wrong answers

Option A is wrong because it claims compliance with both RTO and RPO, but the actual RPO of 2 hours exceeds the required 1 hour, so RPO is not met. Option C is wrong because it states compliance with neither, but the actual RTO of 4 hours meets the required 4 hours, so RTO is compliant. Option D is wrong because it claims compliance with RPO but not RTO, which is the reverse of the actual situation: RTO is met and RPO is not.

2
MCQmedium

A company's BCP requires that critical systems be restored within 2 hours of disruption. Which metric defines this?

A.Mean Time to Repair (MTTR)
B.Recovery Time Objective (RTO)
C.Service Level Agreement (SLA)
D.Recovery Point Objective (RPO)
AnswerB

Recovery Time Objective defines the maximum acceptable time to restore a system after disruption. A two-hour restoration requirement is therefore an RTO, distinguishing it from Recovery Point Objective, which instead specifies tolerable data loss measured in time.

Why this answer

The Recovery Time Objective (RTO) defines the maximum acceptable time that a system or application can be unavailable after a disruption. In this scenario, the requirement to restore critical systems within 2 hours directly specifies the RTO. It is a key metric in business continuity planning that drives the design of failover and recovery strategies.

Exam trap

ISC2 often tests the distinction between RTO and RPO, where candidates confuse the time to restore service (RTO) with the acceptable data loss window (RPO).

How to eliminate wrong answers

Option A is wrong because Mean Time to Repair (MTTR) measures the average time taken to repair a failed component, not the maximum allowable downtime for a business process. Option C is wrong because a Service Level Agreement (SLA) is a contractual commitment between a provider and customer, often including uptime percentages, but it does not define the specific recovery time target for a BCP. Option D is wrong because Recovery Point Objective (RPO) defines the maximum acceptable data loss measured in time (e.g., how far back in time data may be lost), not the time to restore service.

3
Multi-Selecthard

A multinational corporation is reviewing its business continuity plan (BCP) and disaster recovery plan (DRP). The chief information security officer (CISO) wants to clarify the distinct roles of each plan. Which of the following statements accurately describe the relationship between the BCP and DRP? (Choose two.)

Select 2 answers
A.The DRP takes precedence over the BCP during a disaster.
B.The BCP is only concerned with IT systems, while the DRP covers all business units.
C.The DRP is a component of the BCP and provides detailed procedures for recovering technology assets.
D.The BCP focuses on maintaining critical business functions during a disruption, while the DRP focuses on restoring IT infrastructure and systems.
E.The BCP and DRP are mutually exclusive and should be developed independently.
AnswersC, D

The DRP is indeed a component of the broader BCP. It provides the technical procedures and steps necessary to restore IT infrastructure and applications. The BCP relies on the DRP to recover the technology that supports critical business functions. This nested relationship ensures that business continuity and technology recovery are integrated, preventing gaps between business and IT recovery efforts.

Why this answer

The BCP is the overarching plan that ensures critical business functions continue during a disruption, covering people, processes, and facilities. The DRP is a component of the BCP that focuses specifically on restoring IT infrastructure and systems. These two statements accurately reflect the relationship, while the others misstate the scope or interdependence of the plans.

Exam trap

The trap here is assuming that the BCP and DRP are either independent or that one takes precedence, when in fact the DRP is a subordinate component of the BCP.

4
MCQhard

An organization's incident response plan specifies containment, eradication, and recovery phases. During containment, the team isolates a compromised server from the network. However, the server is a domain controller. What is the PRIMARY risk of this action?

A.Data loss on the server
B.Violation of chain of custody
C.Propagation of malware to other systems
D.Loss of authentication services
AnswerD

A domain controller handles Kerberos ticket granting and directory authentication. Isolating it from the network immediately denies those services to domain members, so users and services cannot authenticate, potentially disrupting more of the environment than the original compromise.

Why this answer

Isolating a domain controller from the network prevents it from processing authentication requests (Kerberos and NTLM), which halts user logins, resource access, and group policy updates across the domain. This loss of authentication services is the primary risk because the domain controller is the authoritative source for identity verification in Active Directory.

Exam trap

The trap here is that candidates may focus on the general containment goal of stopping malware spread (Option C) rather than recognizing that isolating a domain controller specifically cripples the authentication infrastructure, which is the most critical and immediate risk.

How to eliminate wrong answers

Option A is wrong because data loss on the server is not the primary risk; domain controllers store Active Directory databases (NTDS.dit), but isolation does not inherently cause data loss—it prevents replication and authentication. Option B is wrong because chain of custody relates to preserving evidence for forensic analysis, not to the immediate operational impact of isolating a domain controller. Option C is wrong because propagation of malware to other systems is the very risk containment aims to prevent; isolating the server stops further spread, not causes it.

5
MCQmedium

A financial services firm suffers a ransomware outbreak that encrypts file servers and the backup catalog. The incident response team must decide the immediate next step while the attack is still spreading. Which action BEST aligns with the containment objective of the incident response plan?

A.Notify regulators and affected customers about the data breach before taking any technical action
B.Immediately restore encrypted file servers from the most recent offline backup to shorten downtime
C.Rebuild all servers from scratch using the original installation media and reapply the latest patches
D.Disconnect affected network segments and disable compromised accounts to stop lateral movement
AnswerD

Containment focuses on stopping the spread of the incident and limiting damage. Isolating affected network segments prevents the ransomware from reaching additional hosts, and disabling compromised accounts blocks further authenticated lateral movement. These actions preserve evidence and buy time for eradication and recovery. This is the textbook containment step for an active ransomware outbreak.

Why this answer

Containment aims to stop an incident from spreading and to limit its damage. With ransomware actively propagating, isolating affected network segments and disabling compromised accounts halts lateral movement and preserves the environment for eradication and recovery. Restoring, notifying, or rebuilding before the threat is contained risks reinfection, destroys evidence, and expands the breach rather than limiting it.

Exam trap

The trap here is confusing recovery actions, such as restoring backups or rebuilding servers, with containment, when containment must happen first to stop an active threat from spreading.

6
MCQhard

During a tabletop exercise, the IT team realizes that the backup tapes are stored in the same building as the servers. Which risk does this highlight?

A.Insufficient off-site storage
B.Single point of failure
C.Lack of redundancy
D.Inadequate segregation of duties
AnswerA

Storing tapes in the same building as the servers creates a single point of failure: any incident destroying the site, such as fire or flood, would destroy both production data and its backups. This directly violates the off-site storage requirement, since no geographically separate copy survives to enable recovery.

Why this answer

Storing backup tapes in the same building as the primary servers violates the fundamental principle of geographic separation for disaster recovery. If a fire, flood, or physical security breach destroys the building, both the primary data and the backup tapes are lost simultaneously, rendering the backups useless. This directly indicates a lack of off-site storage, which is a core requirement for a viable backup strategy.

Exam trap

ISC2 often tests the distinction between 'lack of redundancy' (duplicate hardware) and 'insufficient off-site storage' (geographic separation of backups), trapping candidates who confuse high-availability concepts with disaster recovery requirements.

How to eliminate wrong answers

Option B is wrong because 'single point of failure' typically refers to a component (like a power supply or network link) whose failure stops the entire system, not to the physical co-location of backups. Option C is wrong because 'lack of redundancy' implies missing duplicate components (e.g., a second server or disk array), whereas the issue here is the absence of geographic separation for existing backups. Option D is wrong because 'inadequate segregation of duties' is a security control related to separating administrative roles (e.g., backup operator vs. system admin), not a physical storage location problem.

7
MCQmedium

An organization has detected a ransomware infection. What is the FIRST step in the incident response process?

A.Isolate affected systems
B.Pay the ransom
C.Run antivirus scans
D.Report to law enforcement
AnswerA

Isolating affected systems immediately contains the ransomware, preventing lateral spread to file shares and other hosts while forensic evidence is preserved. Containment precedes eradication and recovery, satisfying the stem's requirement for the first incident response step: stopping active encryption before it reaches further assets.

Why this answer

Isolating affected systems is the correct first step because containment stops the ransomware from spreading laterally to other hosts and encrypting additional data, preserving evidence and limiting blast radius. In standard incident response frameworks such as NIST SP 800-61, containment immediately follows detection and precedes eradication, recovery, and any external reporting.

Exam trap

The trap is choosing 'run antivirus scans' because it feels like an immediate technical fix, but the exam tests the NIST ordering where containment must precede eradication to prevent further spread.

How to eliminate wrong answers

Option B is wrong because paying the ransom is never a recommended response step, does not guarantee decryption, funds criminal activity, and may violate sanctions or regulatory guidance. Option C is wrong because running antivirus scans before containment allows the malware to continue spreading and may alter or destroy forensic evidence. Option D is wrong because reporting to law enforcement is important but occurs after containment and internal escalation, not as the immediate first technical action.

8
MCQhard

An organization's BCP identifies a customer-facing order system as critical. The BIA shows the business can tolerate 12 hours of downtime and 1 hour of data loss. The current architecture uses nightly full backups to tape with a 10-hour restore time. Which change BEST closes the gap between current capability and the stated requirements?

A.Implement continuous replication to a secondary site with automated failover to meet the 12-hour RTO and 1-hour RPO
B.Document a manual workaround in the BCP that allows order entry staff to record transactions on paper until systems return
C.Increase backup frequency to every hour while keeping the nightly tape full backup and 10-hour restore process
D.Move backups from tape to disk to reduce restore time, keeping the nightly full backup schedule
AnswerA

Continuous replication addresses the RPO by keeping data loss well under one hour, and automated failover at a secondary site brings the order system back online far faster than a 10-hour tape restore, comfortably meeting the 12-hour RTO. This solution targets both metrics simultaneously and provides a resilient architecture rather than incremental tweaks to a slow tape process.

Why this answer

The stated requirements are a 12-hour RTO and a 1-hour RPO. Nightly tape backups with a 10-hour restore already meet the RTO but leave up to 24 hours of potential data loss, violating the RPO. Continuous replication to a secondary site with automated failover reduces data loss to minutes and restores service quickly, satisfying both the recovery point and recovery time objectives in one architectural change.

Exam trap

The trap here is treating backup frequency as a fix for recovery time, when backup frequency primarily governs the recovery point objective and does not by itself speed up restoration.

9
MCQeasy

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

A.Determine the cost of implementing security controls
B.List all IT assets
C.Identify critical business processes and their recovery priorities
D.Assign incident response roles
AnswerC

A BIA determines which business processes are most critical and sets their recovery priorities, typically through impact ratings over time. This directly satisfies the stem's focus on prioritisation, distinguishing it from risk assessment or purely technical recovery sequencing activities.

Why this answer

The primary purpose of a business impact analysis (BIA) is to identify critical business processes and quantify the impact of their disruption, which directly determines recovery priorities and objectives (RTO/RPO). This output drives the business continuity and disaster recovery strategy, not asset inventory or cost estimation.

Exam trap

ISC2 often tests the distinction between a BIA (which identifies critical processes and their recovery priorities) and a risk assessment (which identifies threats and vulnerabilities), leading candidates to confuse the BIA's purpose with asset listing or cost analysis.

How to eliminate wrong answers

Option A is wrong because determining the cost of implementing security controls is a function of risk management and cost-benefit analysis, not the BIA, which focuses on impact quantification rather than solution pricing. Option B is wrong because listing all IT assets is an inventory management or configuration management task (e.g., CMDB), whereas the BIA prioritizes business processes and their dependencies, not a simple asset list. Option D is wrong because assigning incident response roles is part of the incident response plan (IRP) development, not the BIA, which identifies recovery priorities before any roles are assigned.

10
MCQmedium

Refer to the exhibit. An administrator needs to restore a database file from two weeks ago, but the backup log shows success. What is the most likely reason the file cannot be restored?

A.The retention policy deleted it
B.The schedule was incorrect
C.The backup source did not include that file
D.The encryption key changed
AnswerC

Successful backup logs only confirm the job ran; they do not prove the file was selected. If the backup source or selection list omitted that database file, no restore point exists, regardless of job status.

Why this answer

The backup log only records the success or failure of the backup job as a whole, not the inclusion of every individual file. If the database file was not selected in the backup source configuration (e.g., a file-level backup job that excluded the database directory or a volume shadow copy that did not include the file), the backup would complete successfully without backing up that file. When the administrator attempts to restore, the file is missing from the backup set, even though the job log shows success.

Exam trap

ISC2 often tests the misconception that a successful backup log guarantees all intended data was backed up, when in reality the backup source configuration determines what is actually captured.

How to eliminate wrong answers

Option A is wrong because a retention policy deletes backup sets after a specified period, but the question states the backup log shows success from two weeks ago, implying the backup set still exists; if the retention policy had deleted it, the restore would fail with a 'backup set not found' error, not a missing file error. Option B is wrong because an incorrect schedule would cause the backup to run at the wrong time or not run at all, but the log shows a successful backup, so the schedule executed correctly. Option D is wrong because an encryption key change would affect the ability to decrypt the backup data, not the presence of the file in the backup; the restore would fail with a decryption error, not a missing file error.

11
MCQhard

A financial services firm conducts an annual test of its business continuity plan. Management wants to evaluate how well the team performs its roles and procedures during a simulated disruption without actually moving operations to alternate sites. Which type of exercise BEST meets this requirement?

A.A tabletop exercise where participants discuss their roles and responses to a simulated scenario
B.A simulation exercise that tests the team's execution of procedures without activating alternate sites
C.A full-scale exercise that activates the alternate processing site and relocates critical staff
D.A structured walkthrough in which each team member reviews the plan document individually
AnswerB

A simulation exercise, sometimes called a functional exercise, tests the performance of specific teams and procedures in a realistic scenario without the full disruption of relocating to an alternate site. It evaluates how well participants execute their roles and use their plans, which directly matches management's goal. It provides more operational realism than a tabletop while avoiding the cost and disruption of a full-scale activation.

Why this answer

A simulation or functional exercise tests the team's ability to execute procedures and fulfill roles in a realistic scenario without the expense and disruption of activating alternate sites. It bridges the gap between discussion-based tabletop exercises and full-scale exercises by focusing on operational performance. This matches management's requirement to evaluate team performance while keeping operations in place.

Exam trap

The trap here is confusing the levels of exercise realism, treating a tabletop as sufficient for evaluating performance when the scenario calls for operational execution.

12
MCQhard

During a disaster recovery exercise, the system fails to achieve the RTO. Analysis shows that restoring the database from tape takes 3 hours, but the RTO is 2 hours. Which is the most effective solution?

A.Use differential instead of full backups
B.Switch from tape to disk-based backups
C.Implement a hot standby database replica
D.Increase the RTO to 3 hours
AnswerC

Tape restore takes three hours, exceeding the two-hour RTO. A hot standby replica maintains a continuously synchronised copy, enabling failover in minutes rather than hours, directly satisfying the RTO constraint that tape restoration cannot meet.

Why this answer

The RTO (Recovery Time Objective) is a business requirement that cannot be changed by simply adjusting the backup method. A hot standby database replica (e.g., using synchronous replication or Oracle Data Guard) provides near-instant failover, reducing recovery time to minutes, which directly meets the 2-hour RTO. This solution addresses the root cause—the restore process is too slow—by eliminating the need to restore from backup entirely.

Exam trap

ISC2 often tests the misconception that improving backup speed (e.g., switching to disk or differential backups) is sufficient to meet RTO, when the real solution is to eliminate the restore process entirely with a high-availability replica.

How to eliminate wrong answers

Option A is wrong because differential backups reduce the amount of data to restore but still require a full restore from tape, which takes 3 hours; the bottleneck is the tape read speed, not the backup type. Option B is wrong because switching to disk-based backups improves restore speed but still involves restoring a full database from backup, which may not reduce the time below 2 hours if the database is large; the fundamental issue is the restore process itself, not the media. Option D is wrong because increasing the RTO to 3 hours violates the business requirement and is not a technical solution; RTO is a predefined objective, not a negotiable parameter in a disaster recovery exercise.

13
Multi-Selectmedium

Which TWO are essential elements of a business impact analysis (BIA)?

Select 2 answers
A.A network topology diagram
B.List of all employees
C.Identification of critical business functions
D.Assignment of IP addresses
E.Determination of maximum acceptable outage (MAO)
AnswersC, E

A BIA must catalogue the business processes whose disruption would halt operations, because every later figure — recovery time objectives, resource priorities, continuity strategies — is derived from that inventory. Without identifying critical business functions, the analysis has no scope to measure impact against.

Why this answer

Option C is correct because a BIA must identify the critical business functions (and the processes and resources supporting them) so that recovery priorities, dependencies, and RTO/RPO targets can be established. Option E is correct because the BIA must determine the maximum acceptable outage (MAO), also expressed as maximum tolerable downtime (MTD), which sets the upper limit of tolerable disruption and drives the recovery time objective (RTO) and continuity strategies. Options A, B, and D are not essential BIA elements: a network topology diagram is a technical/infrastructure artifact used in DR planning, a list of all employees is an HR record rather than an impact analysis input, and IP address assignment is a network administration task unrelated to assessing business impact.

Exam trap

ISC2 often tests the distinction between BIA elements (like critical functions and MAO) and technical implementation details (like IP addresses or network diagrams), so candidates mistakenly choose options that sound technical but are irrelevant to the BIA process.

14
MCQmedium

A healthcare provider's incident response team is handling a breach of patient records. The team has contained the breach and is now eradicating the threat. Which of the following activities is MOST appropriate during the eradication phase?

A.Restoring patient records from a clean backup
B.Conducting a lessons-learned meeting with the incident response team
C.Notifying affected patients about the data breach
D.Applying security patches to the vulnerable server
AnswerD

Eradication involves removing the root cause of the incident, such as eliminating malware, closing vulnerabilities, and patching exploited systems. Applying security patches to the vulnerable server directly addresses the flaw that allowed the breach, preventing re-infection. This activity is a core part of eradication and must be completed before moving to recovery and restoration of normal operations.

Why this answer

During eradication, the incident response team focuses on eliminating the root cause of the incident, such as patching vulnerabilities, removing malware, and disabling compromised accounts. Applying security patches to the vulnerable server directly addresses the flaw that enabled the breach. Notification, restoration, and lessons-learned are activities for later phases.

Exam trap

The trap here is confusing eradication with recovery or post-incident activities, such as restoring backups or notifying victims.

15
MCQmedium

A cloud-hosted retailer's disaster recovery plan relies on backups stored in the same cloud region as production. A regional outage takes the production environment offline. Which weakness does this scenario PRIMARILY expose in the disaster recovery strategy?

A.The backup schedule is too infrequent to meet the stated recovery point objective
B.Production and backups share a single geographic failure domain, so a regional outage affects both
C.The backups lack encryption at rest, exposing customer payment data to unauthorized access
D.The recovery time objective is not documented in the business continuity plan
AnswerB

Storing backups in the same cloud region as production means both are subject to the same regional failure. When that region goes offline, the backups are unavailable exactly when they are needed, defeating the purpose of disaster recovery. This is the primary weakness: a lack of geographic separation between primary systems and recovery data.

Why this answer

Disaster recovery requires that backups be isolated from the failure domain that affects production. Keeping backups in the same cloud region means a regional outage disables both production and the recovery data, leaving no viable restore path. Geographic separation, such as cross-region or cross-provider replication, ensures backups remain accessible when the primary region fails.

Exam trap

The trap here is focusing on backup frequency or encryption details, when the decisive flaw is that production and backups share one geographic failure domain.

16
MCQmedium

A mid-sized hospital experiences a ransomware outbreak that encrypts its electronic health record (EHR) servers on a Friday night. The incident response plan designates a severity classification of 'Critical'. According to established incident response practices, which action should the incident response team take FIRST?

A.Restore the EHR servers from the most recent backup immediately so clinical operations can resume
B.Notify all hospital staff and patients about the breach before taking any technical action
C.Immediately power down all affected EHR servers to stop the encryption from spreading further
D.Isolate the affected systems from the network to contain the spread while preserving evidence
AnswerD

Isolating affected systems from the network is the standard containment action that limits further propagation of ransomware while preserving the state of the systems for forensic investigation. It aligns with the containment phase of incident response and prevents additional encryption of connected file shares and backups. This controlled isolation supports both damage limitation and evidence collection, which are core goals at this stage.

Why this answer

The first priority in an active ransomware incident is to contain the spread while preserving evidence, so isolating affected systems from the network is the correct initial action. Containment prevents further encryption of shared resources and backup repositories. It also keeps the systems in a state suitable for forensic analysis, which is needed to determine scope and root cause before eradication and recovery efforts begin.

Exam trap

The trap here is assuming that immediately restoring from backup or shutting down servers is the fastest fix, when containment and evidence preservation must occur first.

17
Multi-Selecthard

Which TWO are appropriate methods to test a disaster recovery plan?

Select 2 answers
A.Parallel test
B.Regression test
C.Acceptance test
D.Simulation test
E.Unit test
AnswersA, D

A parallel test runs the recovery environment alongside production without disrupting live services, satisfying the requirement to validate recovery capability while avoiding outage risk. Unlike full interruption testing, it exercises actual failover procedures and confirms data integrity, making it appropriate for disaster recovery plan validation.

Why this answer

A parallel test (A) is a recognized DR testing method in which the recovery site is brought online and processes data alongside the primary production site without cutting over live operations, so recovery capability is validated with minimal risk to the business. A simulation test (D) is also a standard DR testing approach, typically a tabletop or walkthrough exercise where the team rehearses roles, procedures, and decision-making for a disaster scenario without actually activating recovery systems. Regression testing (B) is a software quality technique that re-runs existing test cases to confirm changes did not break prior functionality, so it does not validate disaster recovery.

Acceptance testing (C) verifies that a system meets business or user requirements before go-live, not the organization's ability to recover from a disaster. Unit testing (E) validates individual code components in isolation and has no bearing on DR plan validation.

Exam trap

ISC2 often tests the distinction between DR testing methods (parallel, simulation, walkthrough) and software development testing types (unit, regression, acceptance), leading candidates to incorrectly select development tests as valid DR validation techniques.

18
MCQmedium

During a disaster recovery test, backup tapes fail to restore data due to format incompatibility. Which element of the Business Continuity Plan should be updated?

A.Plan testing and maintenance
B.Business Impact Analysis (BIA)
C.Recovery strategies
D.Communication plan
AnswerA

Updating plan testing and maintenance ensures recovery procedures are validated against actual backup formats before a disaster, exposing incompatibilities during exercises rather than live recovery. This directly addresses the stem's constraint: tapes failing to restore because format compatibility was never verified, so the maintenance schedule must mandate periodic restore testing.

Why this answer

The failure of backup tapes to restore data due to format incompatibility indicates that the recovery procedures and tools were not validated during testing. This directly points to a deficiency in the 'Plan testing and maintenance' element, which ensures that backup media formats, restoration tools, and procedures are regularly verified and updated to match the current production environment. Without scheduled testing and maintenance, format drift between backup software versions or hardware changes can render tapes unreadable.

Exam trap

ISC2 often tests the distinction between 'plan testing and maintenance' (which validates technical execution) and 'recovery strategies' (which are high-level design choices), leading candidates to mistakenly select recovery strategies when the root cause is a failure in validation and upkeep.

How to eliminate wrong answers

Option B is wrong because the Business Impact Analysis (BIA) identifies critical business functions, recovery time objectives (RTOs), and recovery point objectives (RPOs), but it does not address the technical compatibility of backup media or the validation of restoration procedures. Option C is wrong because recovery strategies define the high-level approach to restoring operations (e.g., hot site, cold site, cloud failover), not the specific testing of backup tape formats or restoration tools. Option D is wrong because the communication plan covers notification and escalation procedures during an incident, not the technical verification of backup media compatibility or the maintenance of restoration capabilities.

19
Drag & Dropmedium

Drag and drop the steps for the TCP three-way handshake into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The TCP three-way handshake is a three-step process used to establish a reliable connection. The client initiates by sending a SYN (synchronize) packet to the server. The server responds with a SYN-ACK (synchronize-acknowledge) packet, acknowledging the client's request and indicating its own synchronization.

Finally, the client sends an ACK (acknowledge) packet to confirm the connection establishment. This sequence ensures both sides agree on initial sequence numbers and that the connection is ready for data transfer.

20
MCQhard

The exhibit shows a syslog-ng client configuration and a firewall rule on the central logging server (IP 10.0.0.10). The client (192.168.1.100) is not sending logs to the server. What is the most likely cause?

A.The syslog-ng configuration uses TLS, but the firewall rule does not allow TLS traffic
B.The firewall rule restricts source port 6514, but the client uses a random ephemeral source port
C.The syslog-ng client uses UDP by default, but the firewall allows only TCP
D.The firewall rule does not include the client IP 192.168.1.100
AnswerB

Firewall rules filtering on source port 6514 break syslog-ng's TCP transport, because clients originate connections from random ephemeral ports; only the destination port is 6514. Since the stem's rule constrains the source port, the client's packets are dropped before reaching 10.0.0.10, preventing log delivery.

Why this answer

The firewall rule on the central logging server (10.0.0.10) specifies a source port of 6514. However, syslog-ng clients, when sending over TCP or TLS, typically use a random ephemeral source port (e.g., above 1024) rather than a fixed source port. Since the firewall restricts the source port to exactly 6514, the client's packets are dropped, preventing logs from reaching the server.

Exam trap

The trap here is that candidates assume the firewall rule's source port 6514 is irrelevant or that the client must use the same port as the server, when in fact the client uses an ephemeral source port, making the rule overly restrictive and the cause of the failure.

How to eliminate wrong answers

Option A is wrong because the exhibit does not indicate that the syslog-ng client is configured to use TLS; the default transport for syslog-ng is TCP or UDP, and the firewall rule allows TCP on destination port 6514, which is the standard syslog-over-TLS port, but the issue is the source port restriction, not the protocol. Option C is wrong because the syslog-ng client does not use UDP by default when configured for TCP-based logging; the firewall rule explicitly allows TCP on destination port 6514, so if the client were using UDP, it would be blocked, but the client's configuration (not shown) would specify the transport, and the core problem is the source port mismatch. Option D is wrong because the firewall rule does not include a source IP restriction; it only specifies source port 6514 and destination port 6514, so the client IP 192.168.1.100 is not filtered out by the rule.

21
MCQhard

A multinational financial services organization operates three data centers in different geographic regions. Each data center runs a mix of critical and non-critical applications. The DR plan specifies Recovery Time Objectives (RTOs) ranging from 4 hours for critical applications to 72 hours for non-critical. During a scheduled DR test, the team attempts to fail over the primary customer database to the secondary site. The failover fails because the replication link between sites was saturated due to a large data synchronization job running concurrently. The test is declared a failure, and senior management is concerned about the DR plan's reliability. The IT director suggests increasing bandwidth between sites. The security architect proposes implementing network prioritization for replication traffic. The business continuity manager recommends revising the RTOs to be more realistic based on current bandwidth. The system administrator thinks the issue will resolve if the test is repeated during off-peak hours. Which of the following is the BEST course of action to address the root cause of the failure?

A.Implement Quality of Service (QoS) policies to prioritize database replication traffic over other data transfers.
B.Increase the bandwidth on the replication link by ordering a faster circuit from the ISP.
C.Reschedule the next DR test to occur during a scheduled maintenance window with no other replication activity.
D.Revise the RTO for the customer database from 4 hours to 8 hours to account for current bandwidth limitations.
AnswerA

QoS policies prioritise database replication traffic, preventing bulk synchronisation jobs from saturating the link and causing failover failure. This addresses the root cause—unmanaged bandwidth contention—rather than merely adding capacity or relaxing RTOs, satisfying the stem's requirement to fix the underlying fault.

Why this answer

The root cause is that the replication link was saturated by a large data synchronization job, which delayed the critical database replication traffic needed to meet the 4-hour RTO. Implementing Quality of Service (QoS) policies directly addresses this by prioritizing database replication traffic over other data transfers, ensuring that critical replication gets the necessary bandwidth even during concurrent large jobs. This is the most effective solution because it resolves the contention without requiring additional bandwidth or changing RTOs.

Exam trap

ISC2 often tests the misconception that simply adding more bandwidth (Option B) solves all congestion issues, but the trap is that without traffic prioritization, the root cause of contention between different traffic types remains unaddressed.

How to eliminate wrong answers

Option B is wrong because simply increasing bandwidth does not guarantee that replication traffic will be prioritized; without QoS, other data transfers can still saturate the link, and it may not be cost-effective or timely. Option C is wrong because rescheduling the test avoids the problem rather than fixing it; the same issue could occur during a real disaster when other replication activity is unavoidable. Option D is wrong because revising the RTO to 8 hours accepts a degraded recovery capability instead of addressing the technical root cause of traffic prioritization, which could be solved with QoS.

22
MCQmedium

Which is a key benefit of a cold site as a recovery location?

A.Real-time data synchronization
B.Low cost
C.Reduced need for testing
D.Fast recovery time
AnswerB

A cold site provides only basic space and power, with no pre-installed hardware or replicated data, so the organisation pays minimal ongoing facility costs. That low cost is the defining benefit, accepting lengthy activation and restoration times.

Why this answer

A cold site is a backup facility that provides only the physical infrastructure (power, cooling, and space) but no pre-installed hardware or live data. Because it lacks equipment and requires manual setup before recovery can begin, it has the lowest capital and operational costs among recovery site options, making low cost its key benefit.

Exam trap

ISC2 often tests the misconception that 'cold site' implies lower testing requirements, but in reality, cold sites demand more rigorous and frequent testing because the manual recovery process is error-prone and must be validated to avoid failure during an actual disaster.

How to eliminate wrong answers

Option A is wrong because real-time data synchronization requires active replication technologies like synchronous replication or database mirroring, which are not supported by a cold site that has no live systems or network connectivity until activated. Option C is wrong because cold sites actually increase the need for testing, as the recovery process involves manual installation and configuration of hardware and software, which must be validated through regular drills to ensure it works under pressure. Option D is wrong because cold sites have the slowest recovery time (often days or weeks) due to the absence of pre-configured equipment and data, whereas fast recovery is a benefit of hot or warm sites.

23
MCQeasy

An organization discovers a ransomware infection on a critical server. According to the incident response phases, what should be the first action after detection?

A.Notify law enforcement
B.Eradicate the malware from the server
C.Restore from backup
D.Contain the affected system
AnswerD

Containment isolates the infected server, preventing lateral spread to other systems before eradication begins. The stem's constraint is sequencing: detection precedes containment, which must precede eradication and recovery. Containing first limits encryption scope and preserves evidence, satisfying the immediate priority of stopping propagation rather than remediating the already-compromised host.

Why this answer

Immediately after detection, the priority is to contain the ransomware to prevent it from spreading laterally to other systems. According to NIST SP 800-61 and standard incident response frameworks, containment is the first step after detection and analysis, as it limits damage and preserves evidence for forensic investigation.

Exam trap

The trap here is that candidates confuse the urgency of recovery actions (like restoring from backup) with the correct incident response sequence, forgetting that containment must always come first to stop the spread and preserve forensic evidence.

How to eliminate wrong answers

Option A is wrong because notifying law enforcement is a post-containment step, typically done after the scope is understood and evidence is preserved; premature notification can disrupt the response. Option B is wrong because eradicating the malware before containment risks alerting the attacker or causing the ransomware to trigger encryption of additional data; containment must precede eradication. Option C is wrong because restoring from backup before containment can reintroduce the infection if the backup is compromised or if the ransomware is still active on the network; containment ensures the environment is clean before recovery.

24
MCQhard

Which statement best describes a warm site in disaster recovery?

A.It has replicated data but no active systems
B.It is fully operational with real-time data synchronization
C.It has hardware and network equipment but requires data restoration from backups
D.It has no hardware or infrastructure installed
AnswerC

Warm sites pre-stage hardware and network connectivity but hold no live replicated data, so operations resume only after backups are restored. This matches the scenario's requirement precisely: infrastructure exists, yet data restoration from backups remains necessary before systems become operational.

Why this answer

A warm site is a middle-ground disaster recovery option that has hardware and network infrastructure pre-installed but does not have live, synchronized data. Instead, data must be restored from backups (e.g., tape or disk snapshots) before operations can resume. This contrasts with a hot site, which maintains real-time data replication and fully active systems.

Exam trap

ISC2 often tests the distinction between warm and hot sites by making candidates confuse 'pre-installed hardware' (warm) with 'real-time data synchronization' (hot), so the trap is assuming that any site with hardware must also have live data.

How to eliminate wrong answers

Option A is wrong because a site with replicated data but no active systems describes a cold site with data replication, not a warm site; warm sites have hardware but require data restoration. Option B is wrong because a fully operational site with real-time data synchronization defines a hot site, which has zero recovery time objective (RTO) and continuous replication (e.g., synchronous SAN replication). Option D is wrong because a site with no hardware or infrastructure installed is a cold site, which requires full setup before recovery can begin.

25
Multi-Selectmedium

A hospital's incident response team is drafting the post-incident activity phase of its plan after a recent malware outbreak. Which two activities belong in this phase? (Choose two.)

Select 2 answers
A.Update the incident response plan and detection signatures based on findings from the investigation
B.Eradicate the malware by removing malicious files and disabling the persistence mechanism
C.Conduct a lessons-learned review with stakeholders to identify root cause and improve future response
D.Activate the disaster recovery site so clinical applications continue to run during the outage
E.Isolate infected workstations from the network to prevent the malware from reaching other systems
AnswersA, C

Post-incident activity includes incorporating lessons learned into updated procedures, controls, and detection content so the same weakness is less likely to be exploited again. Revising the incident response plan and tuning detection signatures directly reflects the findings of the investigation. This closes the loop between response and preparation, improving the hospital's posture for the next incident.

Why this answer

Post-incident activity focuses on learning from the event and improving future response. Conducting a lessons-learned review identifies root cause and gaps, while updating the incident response plan and detection signatures institutionalizes those findings. Containment, eradication, and recovery actions occur earlier in the lifecycle, so isolating hosts, removing malware, or activating a recovery site do not belong in the post-incident phase.

Exam trap

The trap here is mixing actions from the containment, eradication, and recovery phases into the post-incident phase, when post-incident work is about review and improvement after systems are restored.

26
MCQmedium

An organization's recovery time objective (RTO) for its customer database is 4 hours. During a disaster, the backup restore process takes 2 hours, but reconfigure and test tasks add another 3 hours. Which action best addresses this gap?

A.Conduct the restore test only during annual disaster recovery drills.
B.Reduce the recovery point objective (RPO) to minimize data loss.
C.Increase the RTO to 6 hours.
D.Automate the configuration and validation steps after restore.
AnswerD

Restore takes two hours, but manual reconfiguration and validation add three, totalling five hours and breaching the four-hour RTO. Automating those post-restore configuration and validation steps removes manual delay, bringing total recovery within the four-hour objective.

Why this answer

The RTO is 4 hours, but the actual recovery time is 2 hours (restore) + 3 hours (reconfigure and test) = 5 hours, exceeding the RTO by 1 hour. Automating the configuration and validation steps (option D) reduces the post-restore manual effort, bringing the total recovery time closer to or within the 4-hour RTO. This directly addresses the gap without altering the RTO or neglecting testing.

Exam trap

ISC2 often tests the distinction between RTO and RPO, and the trap here is that candidates confuse reducing RPO (data loss) with fixing a time-based gap, or they incorrectly assume that simply increasing the RTO is an acceptable solution without considering process improvement.

How to eliminate wrong answers

Option A is wrong because conducting the restore test only during annual drills does not fix the daily operational gap; it merely postpones validation, leaving the recovery process untested and potentially non-compliant with the RTO. Option B is wrong because reducing the RPO (recovery point objective) addresses data loss tolerance, not recovery time; it does not reduce the 5-hour total recovery duration. Option C is wrong because increasing the RTO to 6 hours accepts the inefficiency rather than fixing it; best practice is to improve the process to meet the original RTO, not relax the requirement.

27
Multi-Selectmedium

Which TWO are best practices for managing backup media?

Select 2 answers
A.Encrypt backup data
B.Keep backups on the same server for easy access
C.Store backups in a separate physical location
D.Use only tape media
E.Test backups annually
AnswersA, C

Encrypting backup data protects the confidentiality of information at rest on removable media, which is the specific control needed when tapes or drives leave a secured data centre. It satisfies the stem's media-handling constraint by ensuring that theft or loss of physical media does not expose the backed-up contents.

Why this answer

Option A (Encrypt backup data) is correct because backups contain sensitive data at rest, and encryption protects confidentiality if media is lost, stolen, or accessed by unauthorized parties, satisfying compliance and security best practices. Option C (Store backups in a separate physical location) is correct because offsite storage ensures survivability against site-wide disasters such as fire, flood, or theft, enabling recovery even if the primary site is destroyed. Option B is wrong because keeping backups only on the same server leaves them vulnerable to the same failure, ransomware, or disaster that affects the production system.

Option D is wrong because best practice is a tiered or diversified media strategy (disk, tape, cloud) based on RPO/RTO and cost, not reliance on a single media type. Option E is wrong because backups should be tested regularly — ideally after each backup cycle or at least quarterly — not just annually, since untested backups may be unusable when needed.

Exam trap

ISC2 often tests the 3-2-1 backup rule (three copies, two different media, one offsite) to trick candidates into thinking that keeping backups on the same server is acceptable for convenience, when it actually violates the core principle of redundancy.

28
MCQmedium

Refer to the exhibit. A security analyst observes repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port. What is the MOST likely interpretation?

A.The server is being used for remote desktop access
B.The server is performing a port scan
C.The server is a legitimate mail server
D.The server is infected with malware
AnswerD

Repeated outbound connections to external IPs on a non-standard port indicate beaconing or command-and-control traffic, characteristic of malware on the internal server. The stem's pattern of repeated attempts, rather than a single connection, distinguishes malicious callback behaviour from legitimate application traffic.

Why this answer

Repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port are a classic indicator of malware command-and-control (C2) activity. Malware often uses non-standard ports to evade detection and establish outbound communication with an external attacker. This behavior is not typical of legitimate services, which use well-known ports and protocols.

Exam trap

ISC2 often tests the distinction between outbound connection attempts (indicative of malware C2) and inbound connection attempts (indicative of remote access or scanning), leading candidates to mistakenly choose remote desktop or port scanning.

How to eliminate wrong answers

Option A is wrong because remote desktop access (e.g., RDP) uses TCP port 3389 by default, not a non-standard port, and would typically involve inbound connections, not repeated outbound attempts. Option B is wrong because a port scan involves sending packets to multiple ports on a target to discover open services, not repeated outbound connection attempts from a single server to external IPs on a single non-standard port. Option C is wrong because a legitimate mail server uses standard ports such as TCP 25 (SMTP), 587 (submission), or 993 (IMAPS), and would not repeatedly connect to arbitrary external IPs on a non-standard port.

29
MCQeasy

Refer to the exhibit. An SOC analyst pulled this log snippet. Which type of attack is most likely in progress?

A.Phishing
B.DDoS attack
C.Man-in-the-middle
D.Insider threat
AnswerB

A DDoS attack floods a target with traffic from many distributed sources, exhausting bandwidth or connection tables so legitimate users cannot connect. The log's high-volume, multi-source pattern matches this volumetric signature, satisfying the scenario's requirement to identify an availability-focused attack rather than a credential or injection attempt.

Why this answer

The log snippet shows a massive volume of incoming traffic from multiple source IPs targeting a single destination, which is characteristic of a distributed denial-of-service (DDoS) attack. The high packet rate and diverse source addresses indicate an attempt to overwhelm the target's resources, such as bandwidth or server capacity, making services unavailable to legitimate users.

Exam trap

ISC2 often tests the distinction between DDoS and DoS by including logs with multiple source IPs, where candidates might mistakenly focus on the high traffic volume alone and overlook the distributed nature, leading them to choose a generic 'DoS' or another attack type.

How to eliminate wrong answers

Option A is wrong because phishing involves deceptive messages (e.g., emails) to trick users into revealing credentials or installing malware, not a flood of network traffic from many sources. Option C is wrong because a man-in-the-middle attack intercepts and potentially alters communications between two parties, which would show unusual traffic patterns or certificate anomalies, not a high-volume flood from multiple IPs. Option D is wrong because an insider threat originates from within the organization, typically involving unauthorized access or data exfiltration, not a distributed traffic flood from external sources.

30
Multi-Selecthard

In incident response, which TWO are considered volatile data that should be collected first? (Select exactly 2.)

Select 2 answers
A.Hard drive contents
B.Network connections
C.Backup tapes
D.System logs
E.Memory contents
AnswersB, E

Network connections exist only in running memory and vanish on shutdown or reboot, so they must be captured before disk imaging. Collecting them first preserves evidence of active command-and-control, lateral movement and exfiltration that the stem's volatile-data ordering demands.

Why this answer

Option B (Network connections) is correct because active connections, ARP caches, routing tables, and open sockets reside only in memory and kernel state and are lost on shutdown or reboot, making them highly volatile and requiring immediate capture with tools like netstat, ss, or netflow. Option E (Memory contents) is correct because RAM holds running processes, encryption keys, injected code, and uncommitted data that vanish when power is removed, so it must be acquired first using a memory imager such as FTK Imager or WinPmem. Option A (Hard drive contents) is not the most volatile since disk data persists across reboots and is collected later in the order of volatility.

Option C (Backup tapes) is non-volatile offline media that retains data indefinitely and is not time-sensitive. Option D (System logs) may be stored on disk and, while useful, are less volatile than live network state and RAM, so they are not among the first two to collect.

Exam trap

ISC2 often tests the distinction between volatile and non-volatile data, and the trap here is that candidates mistakenly classify system logs as volatile because they change frequently, but logs are stored on disk and are not lost on power-off, whereas network connections and memory are lost immediately.

31
MCQeasy

During a ransomware incident, the incident response team isolates affected systems. Which of the following is the NEXT best step?

A.Preserve forensic evidence from the isolated systems.
B.Wipe and rebuild all affected systems.
C.Notify law enforcement immediately.
D.Pay the ransom to restore operations quickly.
AnswerA

Isolation halts propagation but volatile evidence such as memory and running processes degrades quickly. Capturing forensic artefacts from the isolated hosts before remediation preserves the timeline and attacker indicators, satisfying the need to understand the intrusion while preventing further encryption.

Why this answer

After isolating affected systems during a ransomware incident, the next best step is to preserve forensic evidence from those systems. This ensures that data such as memory dumps, logs, and encrypted files are captured intact for analysis, which is critical for understanding the attack vector, identifying the ransomware variant, and potentially recovering data without paying the ransom. Forensic preservation must occur before any remediation steps like wiping or rebuilding, as those actions would destroy the evidence needed for investigation and legal proceedings.

Exam trap

ISC2 often tests the misconception that containment (isolation) is the final step, but the trap here is that candidates skip forensic preservation and jump to remediation (wipe/rebuild) or external actions (law enforcement/payment), failing to recognize that evidence must be secured first to support both investigation and potential recovery.

How to eliminate wrong answers

Option B is wrong because wiping and rebuilding all affected systems destroys forensic evidence and prevents analysis of the ransomware's behavior, encryption keys, or entry point, which is essential for preventing future incidents and potentially recovering data. Option C is wrong because notifying law enforcement immediately is not the next operational step; while it may be required later, the immediate priority is preserving evidence to support any law enforcement investigation, and premature notification without evidence could hinder the response. Option D is wrong because paying the ransom does not guarantee data recovery, encourages further attacks, and violates many organizational policies and legal guidelines; the incident response team should never recommend payment as a first step.

32
MCQhard

During a disaster recovery exercise, the team discovers that the backup site does not have the latest security patches applied. Which of the following steps should be taken FIRST?

A.Patch the backup site immediately
B.Shut down the backup site
C.Document the finding and assess risk
D.Continue the exercise and note the issue
AnswerC

Discovering missing patches at the backup site is a risk finding, not an immediate remediation trigger. Documenting it and assessing risk first determines severity and prioritisation, avoiding unplanned changes during the exercise that could invalidate results.

Why this answer

The first step in any incident or exercise finding is to document the issue and assess the risk it poses. Patching the backup site immediately (Option A) could introduce instability or conflicts with the current exercise, while shutting it down (Option B) would disrupt the DR test. By documenting and assessing risk first, the team can determine the appropriate remediation priority based on the backup site's role and the criticality of the missing patches.

Exam trap

ISC2 often tests the principle that 'document and assess' must precede any corrective action, even in an exercise, to avoid impulsive changes that could invalidate the test results or introduce new risks.

How to eliminate wrong answers

Option A is wrong because applying patches without first assessing the risk could break the backup site's configuration or introduce new vulnerabilities during the exercise, and it may not be the highest priority action. Option B is wrong because shutting down the backup site would halt the disaster recovery exercise and potentially leave the organization without any failover capability, which is counterproductive. Option D is wrong because simply continuing the exercise without documenting or assessing the issue ignores the security gap and could lead to a false sense of readiness, violating standard incident response procedures (NIST SP 800-61).

33
MCQeasy

A mid-sized law firm experiences a ransomware attack that encrypts its document management system. The IT director wants to ensure the firm can resume operations quickly. Which of the following BEST describes the primary purpose of a disaster recovery plan in this scenario?

A.To define penalties for employees who violate security policies
B.To identify and classify information assets by their sensitivity
C.To restore IT infrastructure and critical data after a disruption
D.To outline steps for communicating with the media during a crisis
AnswerC

A disaster recovery plan focuses specifically on restoring IT systems, applications, and data after an incident. In this ransomware scenario, the plan would guide steps to recover the encrypted document management system from backups, rebuild affected servers, and validate data integrity so the firm can resume work. It directly addresses the technical recovery of technology assets, which is the core objective here.

Why this answer

A disaster recovery plan is specifically designed to restore IT infrastructure, applications, and data after a disruption. In a ransomware scenario, the plan details how to recover encrypted systems from backups, rebuild servers, and verify data integrity. The other options describe asset classification, HR discipline, and media communication, which are not the primary focus of disaster recovery.

Exam trap

The trap here is confusing disaster recovery with broader business continuity or incident response activities, such as crisis communication or asset classification.

34
MCQmedium

A healthcare organization experiences a ransomware attack that encrypts all files on file servers and workstations. The incident response team has isolated the infected systems. The backup policy includes daily incremental backups and weekly full backups stored on a separate network segment. The most recent full backup is 5 days old. The incremental backups from the past 4 days are available but are stored on the same backup server that might be compromised. To restore data with minimal loss, what should the team do?

A.Use the most recent incremental backup to restore files directly.
B.Assume all backups are compromised and rebuild systems from scratch.
C.First verify the integrity of the backups by scanning them on an isolated system, then restore the full backup and apply the most recent clean incremental backups.
D.Restore the weekly full backup and then apply all incremental backups from the past 5 days.
AnswerC

Scanning backups on an isolated host confirms they are free of the ransomware before anything is written back, and restoring the five-day-old full set plus the clean incrementals recovers all data up to the last good backup, minimising loss without reintroducing the payload.

Why this answer

The correct approach is to verify backup integrity on an isolated system before restoring, because the backup server may be compromised by the same ransomware. Once verified clean, the team restores the weekly full backup and then applies the most recent clean incremental backups to minimize data loss. This balances recovery point objective (RPO) with security assurance.

Exam trap

The trap here is assuming that because backups are stored on a separate network segment they are automatically safe, leading candidates to skip verification and choose direct restore options.

How to eliminate wrong answers

Option A is wrong because restoring directly from an incremental backup on a potentially compromised backup server risks reintroducing malware or restoring corrupted data. Option B is wrong because assuming all backups are compromised and rebuilding from scratch causes unnecessary data loss and downtime when verification could prove backups are clean. Option D is wrong because it skips the critical verification step and blindly applies all incremental backups, including any that may be infected, and also incorrectly assumes all 5 days of incrementals are needed when only the most recent clean ones are required.

35
MCQmedium

During an incident, an organization needs to preserve volatile data. Which of the following should be collected FIRST?

A.Backup tapes
B.Memory contents
C.Hard drive contents
D.Network logs
AnswerB

Memory contents are the most volatile, lost on power-off or reboot, so they must be captured before disk or logs. Order of volatility dictates collecting RAM first to preserve evidence such as running processes and encryption keys.

Why this answer

Volatile data is lost when the system loses power. Memory content is the most volatile.

36
MCQeasy

After a ransomware attack, which team is primarily responsible for coordinating the response?

A.Executive Management
B.Incident Response Team
C.IT Support
D.Legal Department
AnswerB

The Incident Response Team owns coordination during a ransomware attack, executing the containment, eradication and recovery phases while liaising with legal, communications and management. This satisfies the stem's coordination constraint, since neither the security operations centre alone nor business units hold that cross-functional mandate.

Why this answer

The Incident Response Team (IRT) is primarily responsible for coordinating the response to a ransomware attack because it follows a predefined incident response plan (IRP) that includes containment, eradication, and recovery procedures. The IRT typically includes security analysts, forensic experts, and system administrators who execute technical steps such as isolating affected systems, analyzing the ransomware strain, and restoring from backups. This team operates under the NIST SP 800-61 framework, ensuring a structured and rapid response to minimize damage.

Exam trap

ISC2 often tests the misconception that Executive Management or Legal should lead the response due to their authority or compliance role, but the exam emphasizes that technical coordination belongs to the Incident Response Team as defined in the CC curriculum's incident response process.

How to eliminate wrong answers

Option A is wrong because Executive Management provides strategic oversight and approves budget/resource allocation, but they lack the technical expertise to coordinate hands-on incident response activities like network isolation or forensic analysis. Option C is wrong because IT Support focuses on routine user troubleshooting and system maintenance, not on executing the specialized containment and eradication steps required during a ransomware incident, such as analyzing malware indicators of compromise (IOCs) or applying firewall rules. Option D is wrong because the Legal Department handles regulatory compliance, breach notification, and liability issues, but they do not perform the technical coordination of response actions like system restoration or evidence preservation.

37
MCQeasy

A company's primary data center is destroyed by a natural disaster. The backup site has been fully synchronized but needs to be activated. Which process addresses the activation of the backup site?

A.Risk Management Plan
B.Incident Response Plan (IRP)
C.Disaster Recovery Plan (DRP)
D.Business Continuity Plan (BCP)
AnswerC

A DRP is the documented, tested process that governs failover and activation of a standby site after a disruptive event, covering roles, sequencing and communication. It directly satisfies the stem's requirement to activate the synchronised backup site, unlike backup or continuity planning alone.

Why this answer

The Disaster Recovery Plan (DRP) specifically outlines the procedures for activating a backup site after a primary data center failure. In this scenario, the backup site is fully synchronized but requires activation, which involves steps like DNS changes, storage array failover (e.g., using synchronous replication with a quorum witness), and network reconfiguration. The DRP is the document that contains these technical recovery steps, distinguishing it from broader continuity or incident response plans.

Exam trap

ISC2 often tests the distinction between BCP and DRP by presenting a scenario where the backup site is already synchronized but needs activation, leading candidates to incorrectly choose BCP because they confuse business continuity with technical disaster recovery.

How to eliminate wrong answers

Option A is wrong because a Risk Management Plan identifies, assesses, and mitigates risks before an incident occurs; it does not contain the step-by-step activation procedures for a backup site. Option B is wrong because an Incident Response Plan (IRP) focuses on immediate containment, eradication, and recovery from security incidents (e.g., malware, data breaches), not on activating a backup data center after a natural disaster. Option D is wrong because a Business Continuity Plan (BCP) addresses maintaining critical business functions during a disruption, often through alternative work arrangements or manual processes, but it does not provide the technical failover steps for activating a backup data center.

38
MCQeasy

An organization's business continuity plan (BCP) requires that its payroll system be operational within 8 hours of a disruption, but the system can tolerate losing up to 4 hours of payroll transaction data. Which pair of metrics BEST represents these two requirements?

A.RPO = 8 hours; MTD = 4 hours
B.RTO = 4 hours; RPO = 8 hours
C.MTD = 8 hours; RTO = 4 hours
D.RTO = 8 hours; RPO = 4 hours
AnswerD

The recovery time objective (RTO) defines the maximum acceptable time to restore the payroll system after a disruption, which matches the 8-hour requirement. The recovery point objective (RPO) defines the maximum acceptable data loss measured in time, which matches the 4-hour tolerance. Together they correctly capture both the downtime and data-loss constraints stated in the BCP.

Why this answer

The recovery time objective (RTO) is the maximum acceptable time to restore a system after disruption, so the 8-hour restoration requirement maps to RTO. The recovery point objective (RPO) is the maximum acceptable data loss expressed in time, so the 4-hour data-loss tolerance maps to RPO. These two metrics together define how quickly the payroll system must return and how much payroll data the organization can afford to lose.

Exam trap

The trap here is assuming the larger time value must be the RPO, when in fact the metric is determined by what is being measured (downtime versus data loss), not by which number is bigger.

39
MCQmedium

A security analyst receives an alert of unusual network traffic from an internal host to an external IP known for command-and-control. After isolating the host, what should be the next step?

A.Wipe the host and reinstall OS
B.Preserve forensic evidence and analyze
C.Reimage the host from backup
D.Notify law enforcement
AnswerB

Preserving volatile memory and disk artefacts captures command-and-control indicators, persistence mechanisms and lateral-movement evidence before remediation destroys them. This satisfies the stem's sequencing constraint: after containment, evidence collection must precede eradication, otherwise attribution and scope assessment become impossible.

Why this answer

Preserving forensic evidence and analyzing the host is the correct next step because incident response methodology (e.g., NIST SP 800-61) requires containment followed by evidence collection and analysis to determine the scope of compromise, identify indicators of compromise (IOCs), and understand the attack vector. Wiping or reimaging destroys volatile data (e.g., memory, running processes, network connections) and artifacts (e.g., registry keys, prefetch files, event logs) that are critical for attribution and remediation. Analysis may involve memory forensics (using tools like Volatility) and disk forensics to extract malware samples, C2 communication logs, and lateral movement traces.

Exam trap

ISC2 often tests the misconception that immediate containment (like wiping or reimaging) is the priority, but the trap here is that the CC exam emphasizes the incident response process order: isolate, then preserve evidence, then analyze, then remediate — skipping evidence preservation violates standard forensic procedures.

How to eliminate wrong answers

Option A is wrong because wiping the host and reinstalling the OS destroys all forensic evidence, preventing root cause analysis and potentially allowing the attacker to persist if the infection vector is not identified. Option C is wrong because reimaging from backup may reintroduce the same vulnerability or malware if the backup is also compromised, and it skips the critical step of evidence preservation and analysis. Option D is wrong because notifying law enforcement is premature before internal investigation confirms the incident's nature and scope; law enforcement involvement typically occurs after evidence is preserved and a decision is made to pursue legal action, not as an immediate next step.

40
MCQeasy

Based on the incident log, at which step did the incident response team contain the threat?

A.14:30 - Scanned system, detected Trojan.Downloader
B.14:45 - Removed malware via AV
C.14:25 - Isolated WKS-045 from network
D.14:35 - Escalated to incident handler
AnswerC

Isolating WKS-045 at 14:25 satisfies the containment requirement by severing the compromised endpoint's network connectivity, preventing lateral movement and further command-and-control communication. Containment means limiting spread, not eradication or recovery, so this action directly matches the incident response phase the question asks about.

Why this answer

Containment is the immediate step to prevent the threat from spreading, and isolating WKS-045 from the network at 14:25 achieves this by cutting off its network connectivity. This aligns with the NIST SP 800-61 incident response lifecycle, where containment is prioritized before eradication or recovery. The log shows isolation occurred before scanning or removal, making it the correct containment action.

Exam trap

ISC2 often tests the distinction between containment and eradication, where candidates mistakenly choose removal (Option B) as containment, but containment must stop the spread before any cleanup occurs.

How to eliminate wrong answers

Option A is wrong because scanning the system and detecting Trojan.Downloader at 14:30 is a detection and analysis step, not containment; containment must happen before or concurrently with analysis to stop lateral movement. Option B is wrong because removing malware via AV at 14:45 is an eradication step, which occurs after containment to eliminate the threat from the isolated system. Option D is wrong because escalating to the incident handler at 14:35 is a communication and coordination step, not a technical containment action; it does not directly stop the threat from spreading.

41
Multi-Selectmedium

Which TWO actions are most effective in reducing the mean time to detect (MTTD) a security incident?

Select 2 answers
A.Requiring multi-factor authentication for all remote access
B.Implementing a SIEM with centralized logging from critical systems
C.Conducting annual security awareness training for all employees
D.Deploying endpoint detection and response (EDR) agents on all workstations
E.Standardizing firewall rules across all network segments
AnswersB, D

SIEM correlates events and alerts analysts, reducing detection time.

Why this answer

A SIEM with centralized logging aggregates and correlates logs from critical systems, enabling real-time analysis and automated alerting. This drastically reduces MTTD by surfacing indicators of compromise (IoCs) within minutes rather than hours or days, as manual log review would require.

Exam trap

The trap here is that candidates confuse preventive controls (MFA, training, firewall rules) with detective controls, failing to recognize that only logging and monitoring tools directly reduce the time to detect an incident.

42
MCQeasy

Which metric defines the maximum acceptable amount of data loss measured in time?

A.Recovery Point Objective (RPO)
B.Mean Time Between Failures (MTBF)
C.Mean Time to Repair (MTTR)
D.Recovery Time Objective (RTO)
AnswerA

Recovery Point Objective (RPO) specifies the maximum tolerable data loss expressed as elapsed time before an incident, directly satisfying the stem's requirement for a time-measured loss threshold. It determines backup frequency, unlike Recovery Time Objective, which bounds service restoration duration instead.

Why this answer

The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, typically expressed in seconds, minutes, or hours. It represents the age of the most recent backup or replicated data that must be available to resume operations after a disaster, directly determining the frequency of backups or replication intervals.

Exam trap

ISC2 often tests the distinction between RPO and RTO, where candidates confuse 'data loss' (RPO) with 'downtime' (RTO); the trap is that both are time-based metrics, but RPO is about how far back in time you can recover data, while RTO is about how long it takes to restore service.

How to eliminate wrong answers

Option B is wrong because Mean Time Between Failures (MTBF) measures the average time between system failures, not data loss; it is a reliability metric used for hardware or component failure prediction. Option C is wrong because Mean Time to Repair (MTTR) measures the average time required to restore a failed system or component, not the acceptable data loss window. Option D is wrong because Recovery Time Objective (RTO) defines the maximum acceptable downtime after a disaster, not the amount of data loss measured in time; RTO focuses on service restoration speed, while RPO focuses on data currency.

43
Multi-Selecteasy

Which TWO are key outputs of a Business Impact Analysis (BIA)?

Select 2 answers
A.List of critical business processes
B.Password policy
C.Network diagram
D.Risk register
E.Recovery Time Objectives
AnswersA, E

A BIA identifies and documents the business processes whose disruption most affects the organisation, ranking them by criticality. This list drives subsequent recovery prioritisation, satisfying the BIA's core purpose of establishing what must be restored first after a disruptive incident.

Why this answer

A Business Impact Analysis (BIA) identifies and prioritizes the business functions whose disruption would most affect the organization, so option A, the list of critical business processes, is a core output because it establishes what must be protected and restored first. Option E, Recovery Time Objectives (RTOs), is also a key BIA output because the BIA determines the maximum tolerable downtime for each critical process, which then drives continuity and recovery planning targets. By contrast, option B (password policy) is an access-control/security governance artifact, not a BIA deliverable.

Option C (network diagram) is a technical architecture document produced by network or infrastructure teams, not by a BIA. Option D (risk register) is an output of risk assessment/risk management processes, where risks are logged and tracked; while a BIA may inform risk analysis, the risk register itself is not a primary BIA output.

Exam trap

The trap here is conflating BIA outputs with general risk-management or security artifacts; candidates often pick 'risk register' because BIA and risk assessment are frequently discussed together in BCP training.

44
MCQeasy

A company has a disaster recovery plan that includes a hot site. Which of the following is the PRIMARY advantage of a hot site over a cold site?

A.Easier maintenance
B.Faster recovery time
C.Greater security
D.Lower cost
AnswerB

A hot site maintains fully configured, synchronised hardware and near-real-time data replication, so operations resume within hours rather than the days or weeks a cold site requires. This directly satisfies the stem's demand for the primary advantage: minimal recovery time.

Why this answer

A hot site is a fully operational duplicate of the primary data center, complete with live servers, storage, networking, and synchronized data. This eliminates the need to procure and configure hardware after a disaster, enabling recovery in minutes or hours rather than days or weeks. The primary advantage is therefore a significantly faster recovery time objective (RTO) compared to a cold site, which has no pre-installed equipment.

Exam trap

ISC2 often tests the distinction that a hot site's primary benefit is speed of recovery (RTO), not cost or security, and candidates mistakenly choose 'lower cost' because they confuse hot sites with warm sites or assume all DR sites are expensive.

How to eliminate wrong answers

Option A is wrong because hot sites require more complex maintenance, including continuous data replication and live system updates, whereas cold sites have minimal upkeep. Option C is wrong because a hot site does not inherently provide greater security; security depends on the specific controls implemented at each site, and both hot and cold sites can be equally secure. Option D is wrong because a hot site is far more expensive than a cold site due to the cost of maintaining duplicate hardware, software licenses, and ongoing data synchronization.

45
Drag & Dropmedium

Drag and drop the steps for the proper disposal of a hard drive containing sensitive data into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Proper disposal includes identification, backup, sanitization, verification, and documentation.

46
MCQhard

During a disaster recovery exercise, the backup systems are not available because the storage array failed. Which of the following should be done FIRST?

A.Activate the disaster recovery plan
B.Contact the vendor
C.Restore from offsite tape
D.Order replacement hardware
AnswerA

The storage array failure has made backups unavailable, breaching the assumptions underpinning normal recovery. Escalating to the disaster recovery plan first invokes the documented alternate-site procedures and recovery team, rather than attempting in-place restoration against failed infrastructure.

Why this answer

When backup systems are unavailable due to a storage array failure, the first action must be to activate the disaster recovery plan (DRP). The DRP is the predefined, documented set of procedures that guides the organization through the recovery process, including escalation, communication, and alternative recovery methods. Without activating the plan, subsequent steps like contacting vendors or restoring from tape lack coordination and may violate recovery time objectives (RTOs) and recovery point objectives (RPOs).

Exam trap

ISC2 often tests the principle that the disaster recovery plan must be activated before any technical recovery action is taken, trapping candidates who jump to a specific recovery step like restoring from tape or contacting a vendor without first following the documented process.

How to eliminate wrong answers

Option B is wrong because contacting the vendor is a tactical step that should be performed after the DRP is activated, as the plan specifies when and how to engage vendors. Option C is wrong because restoring from offsite tape is a specific recovery action that must be directed by the DRP, which first requires assessing the situation and authorizing the restore process. Option D is wrong because ordering replacement hardware is a procurement action that occurs later in the recovery timeline, after the DRP has been activated and a gap analysis has been performed.

47
MCQhard

A company's business continuity plan requires a maximum tolerable downtime of 2 hours for the ERP system. The current backup process takes 3 hours to restore. Which of the following is the BEST corrective action?

A.Reduce RTO to 1 hour
B.Increase backup frequency
C.Implement synchronous replication
D.Perform restoration testing quarterly
AnswerC

Synchronous replication writes to both primary and secondary sites before acknowledging the transaction, giving near-zero data loss and rapid failover within the two-hour recovery time objective. It directly satisfies the maximum tolerable downtime constraint that the three-hour restore breaches.

Why this answer

The maximum tolerable downtime (MTD) is 2 hours, but the current restore process takes 3 hours, which exceeds the MTD. Synchronous replication writes data to both primary and secondary storage simultaneously, ensuring that the secondary copy is always current and can be failed over to in seconds or minutes, not hours. This reduces the recovery time objective (RTO) to well under the required 2 hours, directly addressing the gap.

Exam trap

ISC2 often tests the distinction between RTO and RPO, and the trap here is that candidates confuse backup frequency (which affects RPO) with restore speed (which affects RTO), leading them to incorrectly choose Option B.

How to eliminate wrong answers

Option A is wrong because reducing the RTO to 1 hour does not fix the underlying problem—the restore process still takes 3 hours, and simply changing a target number without improving the technology does not achieve compliance. Option B is wrong because increasing backup frequency reduces the recovery point objective (RPO), not the recovery time objective (RTO); the restore time remains 3 hours regardless of how often backups are taken. Option D is wrong because quarterly restoration testing validates that backups work but does not reduce the 3-hour restore time; testing alone cannot bring the RTO below the MTD.

48
MCQeasy

A small retail company is developing its first incident response plan. The owner asks which phase of the incident response lifecycle involves developing policies, assigning roles, and acquiring tools. Which phase should be recommended?

A.Containment, eradication, and recovery
B.Preparation
C.Post-incident activity
D.Detection and analysis
AnswerB

Preparation is the first phase of the incident response lifecycle. It involves establishing policies, defining roles and responsibilities, training personnel, and acquiring necessary tools and resources. For a small retail company, this phase ensures they are ready to handle incidents before they occur. Without preparation, response efforts are ad hoc and likely ineffective, making this the correct recommendation.

Why this answer

The preparation phase is where organizations develop incident response policies, define team roles, and acquire tools and resources. It is the foundation of the incident response lifecycle. Detection and analysis, containment/eradication/recovery, and post-incident activity are subsequent phases that depend on preparation.

For a small retail company starting from scratch, preparation is the essential first step.

Exam trap

The trap here is confusing the preparation phase with later phases, such as detection or post-incident activity, where policies and tools are used but not initially developed.

49
MCQhard

According to the NIST 800-61 incident response lifecycle, after containment and eradication have been performed, what is the next phase?

A.Recovery
B.Post-incident activity
C.Detection and analysis
D.Preparation
AnswerA

Recovery follows containment and eradication in the NIST 800-61 lifecycle, restoring affected systems to normal operation and validating they are free of residual threats before returning them to production. This directly satisfies the stem's sequencing constraint, as the standard orders the phases: preparation, detection and analysis, containment, eradication, recovery, then post-incident activity.

Why this answer

According to the NIST 800-61 incident response lifecycle, the phases are Preparation, Detection & Analysis, Containment/Eradication, and Recovery. After containment (isolating the threat) and eradication (removing malware, patching vulnerabilities), the next phase is Recovery, where systems are carefully restored to normal operations, often using clean backups and verifying system integrity before reconnecting to the network.

Exam trap

ISC2 often tests the exact NIST 800-61 phase order, and the trap here is that candidates confuse 'Post-incident activity' as the immediate next step after eradication, when in fact Recovery must occur first to restore operations before conducting the final review.

How to eliminate wrong answers

Option B is wrong because Post-incident activity is the final phase that occurs after Recovery, involving lessons learned, documentation, and evidence retention. Option C is wrong because Detection and analysis occurs before containment/eradication, not after. Option D is wrong because Preparation is the initial phase that happens before any incident occurs, establishing policies, tools, and training.

50
MCQeasy

Which document outlines the procedures for maintaining critical business functions during a disruption?

A.Business Continuity Plan
B.Continuity of Operations Plan
C.Incident Response Plan
D.Disaster Recovery Plan
AnswerA

The Business Continuity Plan documents how critical business functions continue during and after a disruption, covering people, processes and alternate working arrangements. It is broader than disaster recovery, which addresses only restoring IT systems and infrastructure.

Why this answer

The Business Continuity Plan (BCP) is the correct answer because it specifically outlines the procedures and strategies to maintain critical business functions during a disruption. Unlike other plans that focus on IT recovery or incident response, the BCP ensures that essential business operations continue, often by leveraging alternate work sites, manual workarounds, or scaled-down processes, until normal operations can be restored.

Exam trap

ISC2 often tests the distinction between BCP and DRP, where candidates mistakenly choose Disaster Recovery Plan because they focus only on IT recovery, forgetting that BCP covers the broader business continuity including non-IT functions like manual order processing or alternate facilities.

How to eliminate wrong answers

Option B (Continuity of Operations Plan) is wrong because it is a U.S. government-specific framework (COOP) focused on maintaining essential government functions at an alternate facility, not a general business continuity document. Option C (Incident Response Plan) is wrong because it focuses on detecting, containing, and eradicating security incidents (e.g., malware outbreaks or data breaches), not on maintaining ongoing business functions during a disruption. Option D (Disaster Recovery Plan) is wrong because it is a subset of BCP that specifically addresses the recovery of IT infrastructure and systems after a disaster, not the broader maintenance of critical business functions.

51
MCQeasy

A company's business continuity plan includes an alternate work site with full IT capabilities. Which type of recovery site does this describe?

A.Hot site
B.Mobile site
C.Cold site
D.Warm site
AnswerA

A hot site is a fully equipped alternate facility with hardware, connectivity and data already operational, enabling near-immediate resumption. It satisfies the full IT capabilities requirement because recovery needs no equipment provisioning or restoration from backup, unlike warm or cold sites.

Why this answer

A hot site is a fully equipped alternate work site with all necessary IT infrastructure—servers, networking, telecommunications, and power—ready to take over operations immediately. The question specifies 'full IT capabilities,' which aligns with the hot site's purpose of enabling rapid failover with minimal downtime, typically within hours.

Exam trap

ISC2 often tests the distinction between hot, warm, and cold sites by emphasizing the 'full IT capabilities' phrase—candidates may confuse a warm site (which has some equipment) with a hot site, but the key differentiator is that a hot site is fully operational and ready for immediate use, while a warm site requires additional setup.

How to eliminate wrong answers

Option B (Mobile site) is wrong because a mobile site is a portable, temporary facility (e.g., a trailer) that may not have full IT capabilities pre-installed and is used for short-term emergencies, not as a permanent alternate work site with full IT readiness. Option C (Cold site) is wrong because a cold site provides only basic physical infrastructure (space, power, cooling) but lacks IT equipment, requiring days or weeks to procure and configure systems, which contradicts 'full IT capabilities.' Option D (Warm site) is wrong because a warm site has some pre-installed hardware and connectivity but not full IT capabilities; it typically requires additional configuration and data restoration before operations can resume, making it slower than a hot site.

52
MCQhard

You are the incident response lead for a financial services company. At 09:00, the SOC detects unusual outbound traffic from a server in the DMZ to an external IP known to be a command-and-control (C2) server. The server runs a legacy application that cannot be patched. The server is critical for customer transactions, but an alternate manual process can sustain operations for up to 4 hours. The CTO wants to keep the server online to avoid customer impact. The CEO is concerned about data exfiltration. The compliance officer reminds you of regulatory requirements to report breaches within 72 hours. Which action should you take FIRST?

A.Report the incident to the regulatory authority immediately.
B.Perform a forensic analysis of the server to determine the scope of compromise.
C.Disconnect the server from the network and activate the manual process.
D.Keep the server online under close monitoring to minimize customer disruption.
AnswerC

Disconnecting the server immediately halts the active C2 channel, stopping potential data exfiltration while the unpatched legacy application cannot be remediated. The four-hour manual process comfortably covers containment and investigation, and rapid isolation supports the 72-hour breach reporting obligation.

Why this answer

The correct first action is to disconnect the server from the network and activate the manual process. This immediately stops potential data exfiltration to the C2 server and contains the incident, aligning with the NIST incident response lifecycle's containment phase. Since the server runs a legacy application that cannot be patched and the manual process can sustain operations for up to 4 hours, isolation is both feasible and necessary to prevent further compromise while maintaining business continuity.

Exam trap

ISC2 often tests the principle that containment must precede any other action, even when business pressure or regulatory deadlines exist, to prevent candidates from prioritizing reporting or analysis over stopping the active threat.

How to eliminate wrong answers

Option A is wrong because reporting to the regulatory authority immediately (within 72 hours) is a post-containment step; the priority is to stop the active C2 communication and data loss first. Option B is wrong because performing forensic analysis on a live, compromised server connected to a C2 server risks altering evidence and allows continued data exfiltration; containment must precede forensics. Option D is wrong because keeping the server online under close monitoring does not stop the active outbound traffic to the C2 server, allowing ongoing data exfiltration and potential lateral movement, which violates the containment principle.

53
MCQeasy

Refer to the exhibit. What is the first action the incident responder should take?

A.Disable the web application
B.Block the source IP in firewall
C.Ignore the alert as false positive
D.Investigate the web server at 192.168.1.10
AnswerD

The exhibit shows the web server as the likely compromised host, so containing or examining it first stops further spread. Investigating 192.168.1.10 directly addresses the identified source of malicious activity before other remediation steps, satisfying the incident response priority of scoping the affected system.

Why this answer

The incident responder must first investigate the web server at 192.168.1.10 to confirm whether the alert is a true positive or a false positive. Jumping to containment actions like disabling the application or blocking the IP without verification could disrupt legitimate services or overlook the root cause. The initial step in any incident response process (as per NIST SP 800-61) is to validate the alert through analysis of logs, processes, and system state.

Exam trap

ISC2 often tests the candidate's understanding that the first step in incident response is always to investigate and validate the alert, not to immediately contain or dismiss it, tempting candidates to jump to a reactive action like blocking the IP or disabling the application.

How to eliminate wrong answers

Option A is wrong because disabling the web application immediately could cause unnecessary business disruption and may destroy volatile evidence (e.g., running processes, memory contents) before the incident is confirmed. Option B is wrong because blocking the source IP in the firewall is a containment action that should only occur after the alert is verified and the scope of the incident is understood; premature blocking could also block legitimate traffic if the IP is spoofed or shared. Option C is wrong because ignoring the alert as a false positive without investigation violates the fundamental incident response principle of 'trust but verify' and could allow an actual breach to go undetected.

54
Multi-Selecteasy

Which THREE are phases of the incident response process according to NIST SP 800-61?

Select 3 answers
A.Containment, Eradication, and Recovery
B.Risk Assessment
C.Detection and Analysis
D.Preparation
E.Vendor Management
AnswersA, C, D

Containment, Eradication, and Recovery form one combined phase in NIST SP 800-61, covering limiting incident spread, removing the root cause, and restoring normal operations. Naming this phase satisfies the question's requirement for a documented stage within the four-phase incident response lifecycle.

Why this answer

NIST SP 800-61 defines the incident response life cycle with four phases, three of which appear here. Option D, Preparation, is the first phase, covering establishing an incident response capability, acquiring tools and resources, and developing policies before incidents occur. Option C, Detection and Analysis, is the second phase, where events are monitored, indicators are validated, and incidents are confirmed and scoped.

Option A, Containment, Eradication, and Recovery, is the third phase, where the incident is limited, the root cause removed, and systems restored to normal operation. The remaining options are not phases in the NIST SP 800-61 life cycle: Risk Assessment (B) is a broader risk management activity, and Vendor Management (E) is an organizational/procurement practice, neither of which is one of the defined incident response phases.

Exam trap

ISC2 often tests whether candidates recognize that 'Containment, Eradication, and Recovery' is a single phase in NIST SP 800-61, not three separate phases, and that 'Risk Assessment' and 'Vendor Management' are common distractors because they appear in other security frameworks but are not part of the incident response process.

55
MCQeasy

Which metric is used to define the maximum amount of data loss an organization can tolerate during a disaster?

A.RTO
B.RPO
C.SLA
D.MTBF
AnswerB

RPO (Recovery Point Objective) defines the maximum tolerable data loss, measured backwards from the disruption to the last recoverable copy. It directly satisfies the stem's constraint by quantifying acceptable data loss in time, unlike RTO, which bounds downtime instead.

Why this answer

RPO (Recovery Point Objective) defines the maximum acceptable amount of data loss measured in time, such as seconds, minutes, or hours. It determines the age of the backup or replication data that must be restored to resume normal operations after a disaster. For example, an RPO of 1 hour means the organization can tolerate losing up to 1 hour's worth of data.

Exam trap

ISC2 often tests the distinction between RTO and RPO, where candidates mistakenly select RTO because they confuse 'time to recover' with 'time of data loss' — remember RTO is about downtime, RPO is about data loss.

How to eliminate wrong answers

Option A (RTO) is wrong because RTO (Recovery Time Objective) defines the maximum acceptable downtime, not data loss; it measures how quickly systems must be restored after a disaster. Option C (SLA) is wrong because SLA (Service Level Agreement) is a contractual commitment between a provider and customer covering performance metrics like uptime, not a specific measure of tolerable data loss. Option D (MTBF) is wrong because MTBF (Mean Time Between Failures) is a reliability metric that predicts the average time between system failures, not a measure of data loss tolerance.

56
MCQhard

During a tabletop exercise for a data center outage, the IT manager realizes that the disaster recovery plan does not specify how to failover the database cluster. The primary data center fails completely. The standby site has a replica of the database, but the application team cannot promote it because they lack the necessary privileges. What is the most likely cause of this gap?

A.The standby site's network connectivity was not tested
B.The database replication configuration was incorrect
C.The database failover procedure was not documented
D.The DR plan did not include role-based access for failover operations
AnswerD

Failover stalled because the application team lacked privileges to promote the replica, so the DR plan omitted the role-based access assignments needed for that operation. Documenting those permissions satisfies the stem's requirement that failover steps be executable during a primary-site outage.

Why this answer

The scenario explicitly states that the application team lacks the necessary privileges to promote the standby database. This indicates that the disaster recovery plan did not define role-based access controls (RBAC) or assign failover permissions to specific personnel or groups. Without documented roles and privileges, even a fully replicated standby database cannot be promoted, causing a failover gap.

Exam trap

ISC2 often tests the distinction between a missing procedure (documentation gap) and missing authorization (access control gap), leading candidates to pick 'procedure not documented' when the real issue is that the team lacks the privileges to execute any procedure.

How to eliminate wrong answers

Option A is wrong because network connectivity, while important for replication and access, is not the root cause here—the standby site has a replica, implying connectivity exists. Option B is wrong because the replication configuration is correct (the standby has a replica), so the issue is not with replication setup but with authorization to promote. Option C is wrong because while the failover procedure may not be documented, the core problem is the lack of privileges to execute any documented procedure—documentation alone does not grant access rights.

57
MCQmedium

A financial services company's business continuity plan includes a recovery time objective (RTO) of 4 hours for its trading platform. During a recent test, the platform was restored in 6 hours. Which of the following should be the PRIMARY focus of the after-action review?

A.Increasing the frequency of full-scale disaster recovery tests
B.Identifying the causes of the delay and implementing improvements
C.Updating the RTO to 6 hours to match actual performance
D.Replacing the entire disaster recovery team
AnswerB

The after-action review should analyze why recovery took longer than the RTO and recommend corrective actions. This might involve additional training, better documentation, more frequent backups, or infrastructure upgrades. The goal is to close the gap between actual and target recovery times, ensuring the trading platform can be restored within 4 hours in a real event. This directly addresses the shortfall.

Why this answer

When a recovery test exceeds the RTO, the after-action review must identify the root causes of the delay and implement corrective measures. This ensures the trading platform can meet its 4-hour RTO in a real disruption. Adjusting the RTO, replacing the team, or merely increasing test frequency does not address the specific performance gap revealed by the test.

Exam trap

The trap here is thinking that the RTO should be adjusted to match actual recovery time, rather than improving recovery capabilities to meet the business requirement.

58
MCQhard

Refer to the exhibit. A DBA is investigating a replication issue. What should be the FIRST action?

A.Restore table from backup
B.Verify data integrity on primary
C.Reseed replication
D.Fail over to standby
AnswerB

Before altering replication configuration, confirm the primary's data is intact. If corruption exists on the source, resynchronising replicas propagates bad data. Verifying integrity establishes whether the fault lies in the primary or the replication channel.

Why this answer

When investigating a replication issue, the first step should be to verify data integrity on the primary database. This ensures that the source data is consistent and not corrupted, which could be the root cause of replication failures. Checking the primary helps determine whether the issue is with the data itself or with the replication process.

Exam trap

The trap here is that candidates may jump to corrective actions like reseeding or failover without first diagnosing the root cause, which is a common mistake in troubleshooting questions.

How to eliminate wrong answers

Option A is wrong because restoring a table from backup is a drastic action that should only be taken after diagnosing the issue; it could cause data loss and does not address the root cause. Option C is wrong because reseeding replication is a corrective action that should be performed after identifying the problem, not as a first step. Option D is wrong because failing over to a standby is a high-availability action that does not fix replication issues and may complicate diagnosis.

59
Multi-Selecthard

Which TWO actions are appropriate during the identification phase of incident response?

Select 2 answers
A.Conduct a post-mortem analysis.
B.Correlate alerts from multiple sources.
C.Review system logs for anomalies.
D.Restore data from backups.
E.Disconnect affected systems from the network.
AnswersB, C

Correlating alerts from multiple sources consolidates indicators during identification, distinguishing genuine incidents from isolated noise. This satisfies the phase's goal of scoping and validating what occurred, enabling accurate classification before containment or eradication activities begin.

Why this answer

During the identification phase, responders must determine whether an incident has actually occurred and scope it, so option B (correlate alerts from multiple sources) is correct because aggregating and cross-referencing alerts from SIEM, IDS/IPS, EDR, and other telemetry helps confirm a true positive and establish the incident's extent. Option C (review system logs for anomalies) is also correct because examining OS, application, and security logs for unusual events, timestamps, and indicators of compromise is a core identification activity that validates and characterizes the suspected incident. Option A (post-mortem analysis) belongs to the lessons-learned/ post-incident phase after containment, eradication, and recovery.

Option D (restore data from backups) is a recovery-phase action, and option E (disconnect affected systems from the network) is a containment action, both of which occur after the incident has been identified.

Exam trap

ISC2 often tests the distinction between identification and containment, so the trap here is that candidates mistake disconnecting systems (a containment step) for an identification action, when in fact identification must occur first to confirm the incident.

60
Multi-Selectmedium

A company is developing a business continuity plan (BCP). Which TWO of the following are essential components that must be included in a BCP?

Select 2 answers
A.Asset inventory
B.Vulnerability assessment
C.Business Impact Analysis (BIA)
D.Recovery Time Objective (RTO)
E.Network diagram
AnswersC, D

The Business Impact Analysis identifies critical business functions, their dependencies and the consequences of disruption, establishing the maximum tolerable downtime. It supplies the foundational data from which recovery priorities, strategies and objectives within the BCP are derived.

Why this answer

Option C, Business Impact Analysis (BIA), is essential because it identifies critical business functions, quantifies the operational and financial impact of their disruption, and establishes the priorities and dependencies that drive the entire BCP strategy. Option D, Recovery Time Objective (RTO), is essential because it defines the maximum acceptable downtime for each critical process, directly shaping the recovery strategies, resource allocation, and backup/replication design documented in the BCP. Options A, B, and E are supporting inputs rather than mandatory BCP components: an asset inventory and network diagram are useful technical references, and a vulnerability assessment belongs to risk assessment activities that inform, but are not part of, the core BCP structure.

Exam trap

ISC2 often tests the distinction between components that are 'essential' to the BCP itself versus supporting documents or risk management activities, causing candidates to select asset inventory or vulnerability assessment as core BCP elements.

61
Multi-Selectmedium

Which TWO are true about a differential backup? (Select two.)

Select 2 answers
A.It copies files changed since the last backup of any type
B.It requires a full backup to be restored first
C.It copies files changed since the last full backup
D.It resets the archive bit on backed-up files
E.It is faster to restore than a full backup
AnswersB, C

A differential backup captures only changes since the last full backup, so it cannot be applied alone. Restoring requires the originating full backup first, then the latest differential, which is why this dependency is a defining characteristic.

Why this answer

Option B is correct because a differential backup only contains data changed since the last full backup, so restoring requires the original full backup plus the most recent differential backup to reconstruct the complete data set. Option C is correct because a differential backup by definition copies all files that have changed since the last full backup, not since the last incremental or differential backup. Option A is incorrect because copying files changed since the last backup of any type describes an incremental backup, not a differential backup.

Option D is incorrect because resetting the archive bit is characteristic of incremental backups (and some full backups), whereas differential backups do not reset the archive bit, which is why each successive differential grows larger. Option E is incorrect because a differential restore requires two restore operations (full plus differential) and is therefore not faster than restoring a single full backup.

Exam trap

ISC2 often tests the distinction between differential and incremental backups by making candidates confuse 'changed since last full' (differential) with 'changed since last backup of any type' (incremental), and by implying that differential backups reset the archive bit when they do not.

62
Multi-Selecthard

Which THREE are differences between a hot site and a cold site? (Select three.)

Select 3 answers
A.Hot site is more expensive to maintain
B.Cold site has pre-installed software and applications
C.Hot site has real-time data synchronization
D.Both have the same recovery time objective (RTO)
E.Cold site has no hardware or infrastructure installed
AnswersA, C, E

A hot site duplicates production infrastructure with live systems, so maintaining it demands continuous hardware, software, connectivity and staffing costs. A cold site holds basic space and power only, making it markedly cheaper to maintain.

Why this answer

Option A is correct because a hot site requires fully redundant, continuously powered hardware, software licenses, and network connectivity that mirror production, making its ongoing maintenance and operational costs significantly higher than a cold site's. Option C is correct because a hot site maintains real-time or near-real-time replication of data (e.g., via synchronous or asynchronous replication) so it can take over almost immediately, whereas a cold site has no such synchronization. Option E is correct because a cold site is essentially an empty facility with power, cooling, and network cabling but no pre-installed hardware or infrastructure, requiring equipment to be brought in and configured after a disaster.

Option B is incorrect because pre-installed software and applications are characteristic of a hot site (or at least a warm site), not a cold site. Option D is incorrect because a hot site typically has a much lower RTO (minutes to hours) than a cold site (days to weeks), so their RTOs are not the same.

Exam trap

ISC2 often tests the misconception that a cold site has some pre-installed infrastructure or software, when in fact it is a completely empty facility with only power and cooling, and that RTO is identical across site types, whereas RTO is a key differentiator between hot, warm, and cold sites.

63
MCQmedium

After a security incident has been contained and eradicated, which of the following should be done to improve future incident response?

A.Conduct a post-incident review
B.Reinstall the operating system
C.Disable the affected user accounts
D.Delete all incident-related logs
AnswerA

A post-incident review examines what happened, why, and how controls failed, producing documented lessons and remediation actions. It directly satisfies the stem's requirement to improve future incident response after containment and eradication, feeding updates back into plans, playbooks and defences.

Why this answer

A post-incident review (also called a lessons-learned meeting) is the correct next step after containment and eradication because it systematically analyzes what went wrong, what worked, and what can be improved in the incident response plan. This review directly feeds into updating playbooks, refining detection rules, and adjusting security controls to prevent recurrence. Without this step, the organization misses the opportunity to close the loop on the incident lifecycle and may repeat the same mistakes.

Exam trap

The trap here is that candidates confuse post-incident review with immediate remediation actions like reinstalling OS or disabling accounts, thinking they are 'improvements' rather than part of containment/eradication.

How to eliminate wrong answers

Option B is wrong because reinstalling the operating system is a remediation step that should have already been performed during the eradication phase, not after the incident is closed; doing it afterward indicates the incident was not properly contained. Option C is wrong because disabling affected user accounts is a containment action that should have been executed during the containment phase, not after eradication; leaving accounts enabled until after the incident is over would risk further compromise. Option D is wrong because deleting all incident-related logs destroys forensic evidence needed for legal proceedings, regulatory compliance, and the post-incident review itself; logs must be preserved per retention policies (e.g., NIST SP 800-61).

64
MCQhard

During an incident, the IR team identifies that the root cause is a zero-day vulnerability. Which of the following is the best immediate action?

A.Report to CERT/CC
B.Rebuild all affected systems
C.Apply a vendor patch
D.Implement compensating controls
AnswerD

No patch exists for a zero-day, so patching cannot remove the exposure. Compensating controls—such as network segmentation, tightened firewall rules or enhanced monitoring—reduce exploitability or impact immediately, containing the threat while the vendor develops a fix. This directly addresses the stem's demand for the best immediate action.

Why this answer

When a zero-day vulnerability is the root cause, no vendor patch exists yet (option C is impossible). Rebuilding systems (option B) without addressing the vulnerability leaves them re-exposed. The best immediate action is to implement compensating controls—such as firewall rules, IDS/IPS signatures, or application-layer filtering—to mitigate the risk until a permanent fix is available.

This aligns with incident response containment strategies that prioritize reducing impact while preserving forensic evidence.

Exam trap

ISC2 often tests the misconception that 'rebuilding systems' or 'applying a patch' are immediate actions for a zero-day, when in reality the absence of a patch and the need for containment make compensating controls the only viable first step.

How to eliminate wrong answers

Option A is wrong because reporting to CERT/CC is a post-incident coordination step, not an immediate containment action; it does not stop the ongoing attack. Option B is wrong because rebuilding affected systems without first containing the vulnerability will result in immediate re-infection, as the zero-day exploit vector remains active. Option C is wrong because a zero-day vulnerability, by definition, has no vendor patch available at the time of discovery; applying a non-existent patch is impossible.

Ready to test yourself?

Try a timed practice session using only Business Continuity, DR & Incident Response questions.