mediumMultiple Select
ISC2 CC Practice Question: Which TWO of the following are essential elements…
Which TWO of the following are essential elements of an incident response plan?
⚠ Common exam trap
ISC2 often tests the distinction between 'essential operational elements' (like procedures and roles) and 'supporting documentation' (like compliance lists or full employee directories), causing candidates to mistake administrative details for core response components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Step-by-step procedures for each incident type.
Option C is correct because an incident response plan must include step-by-step procedures for each incident type, giving responders a documented, repeatable playbook (e.g., containment, eradication, recovery steps) so they can act quickly and consistently during an actual event. Option E is correct because defined roles and responsibilities establish who leads the response, who handles communications, who performs forensics, and who has authority to make decisions, which is essential for coordination and accountability under pressure. Options A, B, and D do not belong: a list of compliance standards is a governance/audit reference rather than a core response element, personal phone numbers of executives are too narrow and not a structural component of the plan, and contact information for all employees is an overly broad directory detail rather than an essential element of the incident response plan itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A list of compliance standards.
Why it's wrong here
Compliance standards are governance references, not operational incident response content; they do not tell responders whom to call or what to do during an incident. A compliance list would be relevant when preparing audit evidence or mapping controls, not as an essential element of the response plan itself.
- ✗
Personal phone numbers of executives.
Why it's wrong here
Executive personal phone numbers are neither scalable nor appropriate for incident escalation; they bypass the documented on-call and escalation chain. Such a list would be the correct choice only for a narrow crisis-communications contact sheet, not as an essential element of the incident response plan.
- ✓
Step-by-step procedures for each incident type.
Why this is correct
Step-by-step procedures translate policy into executable actions, specifying exactly who does what, in which order, during each incident class. This satisfies the stem's demand for essential plan elements: without predefined playbooks, responders improvise under pressure, delaying containment and recovery. Procedures also enable consistent handling and post-incident review across the organisation.
- ✗
Contact information for all employees.
Why it's wrong here
A full employee contact list is too broad to be actionable during an incident and does not identify who holds response roles. Contact information for the incident response team and key stakeholders is essential; a company-wide directory would be the right choice for general HR or business continuity communications.
- ✓
Defined roles and responsibilities.
Why this is correct
Defined roles and responsibilities assign clear ownership for detection, containment, communication and recovery, preventing gaps or duplicated effort during an incident. This satisfies the stem's requirement for an essential element of an incident response plan.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.