SSCP Incident Response and Recovery Practice Question
A healthcare provider's incident response team is handling a suspected ransomware incident on a clinical workstation. The team lead wants to determine whether the incident should be escalated to a full response or handled as a false positive. According to NIST SP 800-61, which activity is part of the detection and analysis phase?
⚠ Common exam trap
Candidates often confuse containment or eradication actions with detection and analysis, because responders often want to act immediately rather than first validating whether the incident is real.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Validating the incident by correlating alerts with known indicators and impact.
Detection and analysis in NIST SP 800-61 involves validating alerts, correlating indicators, scoping the incident, and determining impact. Validation is the critical step that separates real incidents from false positives and informs escalation decisions. Eradication, containment, and post-incident review occur in later phases, so they are not part of detection and analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Validating the incident by correlating alerts with known indicators and impact.
Why this is correct
Validation is a core detection and analysis activity: responders correlate alerts, indicators, and impact to confirm whether an event is a real incident. This step prevents wasted resources on false positives and determines the appropriate response. In the ransomware scenario, validating the alert against known ransomware indicators and assessing clinical impact directly supports the decision to escalate or dismiss.
- ✗
Implementing a network access control list to block the ransomware's command-and-control domain.
Why it's wrong here
Blocking a command-and-control domain is a containment action, which follows detection and analysis. While it may be appropriate later, doing it during detection and analysis without first validating the incident could be ineffective or disruptive. The detection and analysis phase should confirm the incident and gather indicators before containment measures are applied.
- ✗
Conducting a lessons learned meeting with clinical staff.
Why it's wrong here
Lessons learned meetings occur in the post-incident activity phase, after the incident is resolved. At this point in the scenario, the team is still determining whether the event is a real incident, so holding a lessons learned session would be premature. The detection and analysis phase is about validation, scoping, and notification, not retrospective review.
- ✗
Eradicating the malware by reimaging the workstation.
Why it's wrong here
Reimaging is an eradication and recovery activity that occurs after containment, not during detection and analysis. Performing eradication before validation could destroy evidence and disrupt clinical operations unnecessarily if the alert turns out to be a false positive. The detection and analysis phase focuses on confirming and scoping the incident, not on removing the threat.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.