mediumMultiple Select
ISC2 CC Practice Question: Which TWO are key components of an effective…
Which TWO are key components of an effective incident response plan? (Select TWO.)
⚠ Common exam trap
ISC2 often tests the distinction between incident response and adjacent processes (like business continuity or disaster recovery) to see if candidates confuse overlapping but distinct security operations concepts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Communication plan for stakeholders
A communication plan for stakeholders (D) is a core component because an incident response plan must define who notifies executives, legal, PR, regulators, and customers, along with escalation paths, contact rosters, and approved messaging to control reputational and regulatory impact. A post-incident review process (E) is also essential because it establishes the lessons-learned/after-action review that captures root cause, timeline, and remediation items to improve future response. The other options, while valuable in related programs, are not the two key components of an incident response plan: business continuity procedures (A) belong to BC/DR planning, a list of forensic tools (B) is a supporting resource rather than a plan component, and a backup verification schedule (C) is an operational control within backup/recovery management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Business continuity procedures
Why it's wrong here
Business continuity procedures cover sustaining or restoring operations during disruption, not the structured detection, containment, eradication and recovery of a security incident. They are tempting because continuity planning overlaps with response in scope, but an incident response plan instead requires defined roles, communication channels and escalation criteria.
- ✗
List of forensic tools
Why it's wrong here
A list of forensic tools names products rather than defining response actions, so it does not tell the team who does what during containment or eradication. It is tempting because tooling supports evidence handling, yet an incident response plan needs documented roles, communication paths and escalation criteria, with tool selection handled separately.
- ✗
Backup verification schedule
Why it's wrong here
Backup verification confirms recoverability of data, which supports restoration but does not itself direct incident handling. It is tempting because backups are essential to recovery, yet an incident response plan requires defined roles, communication channels and escalation criteria; verification schedules belong to business continuity and backup policy instead.
- ✓
Communication plan for stakeholders
Why this is correct
A stakeholder communication plan defines who is notified, when, and through which channels during an incident, ensuring coordinated escalation and regulatory notification. This satisfies the stem's requirement for a key component of an effective incident response plan.
- ✓
Post-incident review process
Why this is correct
A post-incident review process examines root cause, response effectiveness, and lessons learned after containment, feeding improvements back into the plan. This satisfies the stem's requirement for a key component of an effective incident response plan.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.