Courseiva
easyMultiple Select

ISC2 CC Practice Question: Which THREE of the following are important steps…

Which THREE of the following are important steps in the incident response process as defined by the NIST framework? (Choose three.)

⚠ Common exam trap

The trap is that candidates might confuse proactive security activities like vulnerability scanning with incident response phases. The NIST framework is specific, and 'Post-incident auditing' is a distractor that sounds similar to 'Post-Incident Activity' but is not the exact phase name.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detection and Analysis

The NIST SP 800-61 incident response lifecycle defines four phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity. Option D (Preparation) is correct because it is the first phase, covering establishing an IR capability, tools, communications, and training before incidents occur. Option A (Detection and Analysis) is correct because it is the phase where events are validated as incidents and their scope, impact, and root cause are analyzed. Option C (Containment, Eradication, and Recovery) is correct because it is the phase where the incident is limited, the threat removed, and systems restored to normal operation. Option B (Vulnerability scanning) is not a distinct NIST IR phase; it is a proactive security control that may feed Preparation or Detection but is not one of the defined steps. Option E (Post-incident auditing) is not the NIST phase name; the correct fourth phase is Post-Incident Activity, which includes lessons learned and evidence retention rather than a standalone 'auditing' step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Detection and Analysis

    Why this is correct

    Detection and Analysis is a core NIST SP 800-61 phase, covering monitoring, alert triage and validating whether an event is genuinely an incident. It satisfies the framework's requirement to identify and investigate suspicious activity before containment, eradication and recovery steps are undertaken.

  • ✗

    Vulnerability scanning

    Why it's wrong here

    Vulnerability scanning is a proactive assessment activity, not one of NIST's incident response phases (Preparation; Detection and Analysis; Containment, Eradication and Recovery; Post-Incident Activity). It tempts because scanning supports preparation and hardening, but it occurs outside the response lifecycle itself.

  • ✓

    Containment, Eradication, and Recovery

    Why this is correct

    Containment, eradication and recovery form the third phase of the NIST incident response lifecycle, following preparation and detection/analysis. Containment limits further damage, eradication removes the threat, and recovery restores normal operations — satisfying the stem's requirement for steps defined within the NIST framework.

  • ✓

    Preparation

    Why this is correct

    Preparation is the first of the NIST SP 800-61 phases, covering policy, tooling, training and communications before an incident occurs. It satisfies the framework's requirement to establish response capability in advance, so it counts among the three steps the question asks for.

  • ✗

    Post-incident auditing

    Why it's wrong here

    NIST SP 800-61 defines four phases: preparation; detection and analysis; containment, eradication and recovery; and post-incident activity. Post-incident auditing is not a named phase, though reviewing logs after resolution fits the post-incident activity phase's lessons-learned meeting.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.