ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
Which type of incident involves an attacker attempting to make a system or network resource unavailable to legitimate users?
⚠ Common exam trap
Candidates often confuse the goal of an attack with the method; candidates might select malware or social engineering because they are common attack types, but the question specifically asks for the incident type defined by the objective of making resources unavailable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Denial of service
A Denial of Service (DoS) attack explicitly aims to disrupt the availability of a system or network resource, making it inaccessible to legitimate users. This aligns with the definition of a DoS incident, which focuses on overwhelming the target with traffic or exploiting vulnerabilities to exhaust resources. The other options describe different attack categories: social engineering targets human trust, malware is malicious software, and data breach involves unauthorized data access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Denial of service
Why this is correct
Denial of service floods a system or network with traffic or malformed requests, exhausting bandwidth, connections or processing capacity so legitimate users cannot access the resource. Availability, rather than confidentiality or integrity, is the target of this incident type.
- ✗
Social engineering
Why it's wrong here
Social engineering manipulates people into divulging information or performing actions, targeting human trust rather than exhausting system resources. It would be the answer if the scenario described phishing or pretexting to obtain credentials, not denial of availability to legitimate users.
- ✗
Malware
Why it's wrong here
Malware is malicious software that executes on a host to steal data, encrypt files or gain control; resource exhaustion is only incidental to some variants. Malware would be correct if the stem described infected files or ransomware, not the deliberate flooding of a service.
- ✗
Data breach
Why it's wrong here
A data breach is the unauthorised access, disclosure or exfiltration of confidential information, affecting confidentiality rather than availability. It would be correct if the scenario described stolen records or leaked personal data, not an attacker denying access to a resource.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.