Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

During which phase of the incident response process would the team identify the root cause of a security incident?

⚠ Common exam trap

Watch out — candidates often confuse the Analysis phase with Eradication, because many candidates think root cause is identified while removing the threat; however, eradication is purely about elimination, and analysis must precede it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analysis

The Analysis phase (also called Investigation) is where the incident response team examines all available data—logs, memory dumps, network captures—to determine how the incident occurred, what systems were affected, and the root cause. This phase follows Detection and precedes Eradication. Identifying the root cause is essential to ensure the same vulnerability isn't exploited again after containment and recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Eradication

    Why it's wrong here

    Eradication removes the threat and restores systems after the cause is known; root-cause analysis happens earlier, during analysis. It tempts because eradication follows directly from understanding the incident, but identifying the cause is the input to eradication, not its activity.

  • ✗

    Preparation

    Why it's wrong here

    Preparation builds plans, tooling and team readiness before any incident occurs, so no root cause exists yet to identify. It tempts because preparation defines the analysis procedures later used, but the actual cause-finding occurs during the analysis phase.

  • ✓

    Analysis

    Why this is correct

    Analysis is the phase where investigators examine evidence to determine how the incident occurred, establishing root cause and scope. This directly satisfies the stem's requirement to identify root cause, distinguishing it from containment or eradication, which address the incident itself rather than understanding its origin.

  • ✗

    Detection

    Why it's wrong here

    Detection confirms that an incident is occurring and scopes its immediate impact; determining why it happened is analysis. It tempts because detection gathers the initial evidence, yet root-cause identification is a distinct, deeper activity performed in the analysis phase.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.