ISC2 CC Business Continuity, DR & Incident Response Practice Question
During a disaster recovery exercise, the team discovers that the backup site does not have the latest security patches applied. Which of the following steps should be taken FIRST?
⚠ Common exam trap
ISC2 often tests the principle that 'document and assess' must precede any corrective action, even in an exercise, to avoid impulsive changes that could invalidate the test results or introduce new risks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the finding and assess risk
The first step in any incident or exercise finding is to document the issue and assess the risk it poses. Patching the backup site immediately (Option A) could introduce instability or conflicts with the current exercise, while shutting it down (Option B) would disrupt the DR test. By documenting and assessing risk first, the team can determine the appropriate remediation priority based on the backup site's role and the criticality of the missing patches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patch the backup site immediately
Why it's wrong here
Applying patches without assessment may interfere with the test objectives.
- ✗
Shut down the backup site
Why it's wrong here
Shutting down is unnecessarily disruptive; the site may still be usable.
- ✓
Document the finding and assess risk
Why this is correct
Proper incident response documentation and risk assessment are critical first steps.
- ✗
Continue the exercise and note the issue
Why it's wrong here
The issue should be formally documented and risk assessed, not just noted.
Go deeper
Related to this question
Learn chapter
Introduction to Security Principles
Key term
Disaster recovery
Disaster recovery is a set of policies, procedures, and tools that help an organization restore critical IT systems and data after a disruptive event.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CC question is part of Courseiva's 976-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.