ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
During which phase of the incident response process would the team identify the root cause of a security incident?
⚠ Common exam trap
Watch out — candidates often confuse the Analysis phase with Eradication, because many candidates think root cause is identified while removing the threat; however, eradication is purely about elimination, and analysis must precede it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analysis
The Analysis phase (also called Investigation) is where the incident response team examines all available data—logs, memory dumps, network captures—to determine how the incident occurred, what systems were affected, and the root cause. This phase follows Detection and precedes Eradication. Identifying the root cause is essential to ensure the same vulnerability isn't exploited again after containment and recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Eradication
Why it's wrong here
Eradication removes the threat and restores systems after the cause is known; root-cause analysis happens earlier, during analysis. It tempts because eradication follows directly from understanding the incident, but identifying the cause is the input to eradication, not its activity.
- ✗
Preparation
Why it's wrong here
Preparation builds plans, tooling and team readiness before any incident occurs, so no root cause exists yet to identify. It tempts because preparation defines the analysis procedures later used, but the actual cause-finding occurs during the analysis phase.
- ✓
Analysis
Why this is correct
Analysis is the phase where investigators examine evidence to determine how the incident occurred, establishing root cause and scope. This directly satisfies the stem's requirement to identify root cause, distinguishing it from containment or eradication, which address the incident itself rather than understanding its origin.
- ✗
Detection
Why it's wrong here
Detection confirms that an incident is occurring and scopes its immediate impact; determining why it happened is analysis. It tempts because detection gathers the initial evidence, yet root-cause identification is a distinct, deeper activity performed in the analysis phase.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.