Courseiva

ISC2 CC Business Continuity, DR & Incident Response Practice Question

During a disaster recovery exercise, the team discovers that the backup site does not have the latest security patches applied. Which of the following steps should be taken FIRST?

⚠ Common exam trap

ISC2 often tests the principle that 'document and assess' must precede any corrective action, even in an exercise, to avoid impulsive changes that could invalidate the test results or introduce new risks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the finding and assess risk

The first step in any incident or exercise finding is to document the issue and assess the risk it poses. Patching the backup site immediately (Option A) could introduce instability or conflicts with the current exercise, while shutting it down (Option B) would disrupt the DR test. By documenting and assessing risk first, the team can determine the appropriate remediation priority based on the backup site's role and the criticality of the missing patches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Patch the backup site immediately

    Why it's wrong here

    Patching immediately skips triage: the exercise's purpose is to identify gaps, and unverified patches could break the recovery configuration mid-test. It is tempting because remediation is the eventual goal, and would be correct once the exercise concludes and the gap is documented, prioritised and scheduled.

  • ✗

    Shut down the backup site

    Why it's wrong here

    Shutting down the backup site removes the only recovery capability during the exercise, leaving the organisation with no failover target and no diagnostic data. It is tempting as a containment reflex when an unpatched host is discovered, and would be correct if the site were actively compromised and spreading malware to production.

  • ✓

    Document the finding and assess risk

    Why this is correct

    Discovering missing patches at the backup site is a risk finding, not an immediate remediation trigger. Documenting it and assessing risk first determines severity and prioritisation, avoiding unplanned changes during the exercise that could invalidate results.

  • ✗

    Continue the exercise and note the issue

    Why it's wrong here

    Continuing without recording the missing patches in a formal risk or findings log leaves the gap untracked and unowned after the exercise ends. It is tempting because exercises are time-boxed and disruption is unwelcome, and would be correct if the exercise already captured findings through an automated compliance-reporting tool.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.