Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

Which phase of the incident response process involves actions to stop the incident from causing further damage, such as isolating affected systems?

⚠ Common exam trap

Watch out — candidates often confuse containment with eradication — candidates often pick eradication because both 'stop the incident,' but containment limits spread while eradication removes the threat entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Containment

Containment is the incident response phase focused on limiting the scope and impact of an incident — isolating affected systems, disabling compromised accounts, and blocking malicious traffic to prevent further damage. It occurs after detection and analysis but before eradication and recovery. The goal is to stop the spread while preserving evidence for investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Eradication

    Why it's wrong here

    Eradication removes the root cause — malware, compromised accounts, vulnerable software — after containment has already stopped the spread. Isolating affected systems is containment, which limits blast radius while the threat is still active. Eradication would be correct once the incident is contained and you are ready to eliminate the underlying cause.

  • ✗

    Analysis

    Why it's wrong here

    Analysis examines evidence to determine scope, impact and root cause; it does not itself halt spread. Containment is the phase that isolates affected systems. Analysis is tempting because it precedes containment and often triggers it, and it would be the correct answer if the question asked which phase identifies what happened and which systems are compromised.

  • ✓

    Containment

    Why this is correct

    Containment limits an incident's spread by isolating affected systems, such as disconnecting compromised hosts from the network. This directly satisfies the stem's requirement to stop further damage, distinguishing it from eradication, which removes the threat's root cause after containment.

  • ✗

    Detection

    Why it's wrong here

    Detection identifies that an incident is occurring and scopes its extent; it does not isolate systems or halt spread. Containment performs those actions. Detection would be correct when the requirement is monitoring, alerting or triaging suspicious activity before any response action begins.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.