SSCP Incident Response and Recovery Practice Question
A healthcare organization's incident response team has just contained a ransomware outbreak that encrypted several file servers. Before restoring from backups, the incident response manager wants to ensure that the team can determine exactly how the attacker initially gained access and what data was exfiltrated. The organization does not have a dedicated forensic imaging solution, but the servers are still powered on and running. Which of the following actions BEST supports the investigation while preserving evidence?
⚠ Common exam trap
The trap here is assuming that containment always requires immediately powering off or restoring systems, which destroys volatile evidence needed to determine the root cause and scope of the incident.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture a memory image and relevant logs from the running servers, then isolate them from the network before restoration.
The best action is to capture volatile evidence such as memory and logs from the running servers before isolating them. This preserves critical artifacts that reveal the attacker's methods and data exfiltration while preventing further damage. Restoring from backup or powering off the servers would destroy evidence, and antivirus scanning could alter the compromised state, undermining the investigation's goals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on each server and quarantine any detected malware, then review the scan reports.
Why it's wrong here
Antivirus scanning can alter or delete malicious files and modify system state, potentially destroying evidence. Scan reports are not a substitute for forensic analysis of memory, logs, and file system artifacts. This action may also trigger the attacker's malware to take further destructive actions. It does not adequately support determining initial access or data exfiltration and risks contaminating the evidence.
- ✗
Immediately power off the servers to prevent further encryption, then remove the hard drives for later analysis.
Why it's wrong here
Powering off the servers destroys volatile evidence such as running processes, network connections, and encryption keys in memory that could reveal the attacker's entry point and lateral movement. Removing drives without a proper forensic image also risks altering metadata. This approach prioritizes containment over evidence preservation, which is not the best action when the investigation goals include determining initial access and exfiltration.
- ✓
Capture a memory image and relevant logs from the running servers, then isolate them from the network before restoration.
Why this is correct
Capturing volatile data like memory and logs while the systems are still running preserves critical evidence about the attacker's tools, credentials, and network connections. Isolating the servers prevents further damage without destroying evidence. This approach aligns with incident response best practices by balancing containment and forensic preservation, enabling the team to determine initial access and exfiltration methods before restoring from backups.
- ✗
Restore the servers from the most recent backup immediately, then review backup logs to identify the initial compromise.
Why it's wrong here
Restoring from backup before collecting evidence overwrites the compromised state and destroys volatile and non-volatile artifacts that could show how the attacker gained access and what data was taken. Backup logs alone typically do not contain the detailed forensic artifacts needed for root cause analysis. This action prioritizes recovery over investigation, which is inappropriate when the goal is to understand the incident fully.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.