ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
Which incident category involves an attempt to make a system or network resource unavailable to its intended users?
⚠ Common exam trap
The trap here is conflating 'availability' attacks with 'confidentiality' or 'integrity' attacks; candidates may pick 'data breach' because they associate all cyber incidents with data theft, missing the specific wording about making resources unavailable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Denial of service
A denial-of-service (DoS) incident is defined as any attempt to make a system or network resource unavailable to its intended users, typically by flooding it with traffic or exploiting resource exhaustion. This matches the question's description exactly. Other categories like malware or data breach involve different objectives such as data theft or code execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Malware
Why it's wrong here
Malware covers malicious code such as viruses, ransomware and trojans, whose primary effects are data corruption, encryption or exfiltration rather than rendering a resource unreachable. It is tempting because ransomware can disrupt services, but the defining category for deliberately exhausting a system so intended users cannot reach it is denial of service.
- ✗
Data breach
Why it's wrong here
A data breach concerns unauthorised access to or disclosure of confidential information, an impact on confidentiality rather than availability. It is tempting because breaches dominate incident reporting, and it would be the correct category for stolen records or exfiltration, but the stem describes denying legitimate users access to a resource.
- ✓
Denial of service
Why this is correct
Denial-of-service attacks exhaust a system's capacity — flooding bandwidth, connection tables or CPU — so legitimate users cannot reach the resource, directly matching the stem's unavailability criterion. Unlike data-theft or intrusion categories, the objective here is disruption rather than access, making this the precise incident classification.
- ✗
Social engineering
Why it's wrong here
Social engineering manipulates people into divulging credentials or granting access, producing confidentiality or fraud impact rather than service outage. It is tempting because it is a recognised incident category, and it would be correct for phishing or pretexting scenarios, but availability loss through resource exhaustion is denial of service.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.