easyMultiple Choice
SSCP Practice Question: A medium-sized company recently experienced a…
A medium-sized company recently experienced a phishing attack where an employee downloaded a malicious attachment, leading to a data breach. The incident response team has identified the affected user and the malware. However, the team is unsure whether the attacker has established persistence. The security analyst must recommend the next step. The company has a standard incident response plan that includes detection, containment, eradication, recovery, and lessons learned. The malware sample has been isolated for analysis. The user's account has been disabled temporarily. The network team has quarantined the user's workstation. The analyst needs to ensure the attacker cannot regain access after the initial cleanup. What should the analyst recommend next?
⚠ Common exam trap
The trap here is that candidates may jump to reimaging (Option D) as a quick fix, but without first verifying and removing persistence, the attacker could have established footholds on other systems or in the backup itself, making reimaging ineffective.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check system logs for unauthorized registry modifications, scheduled tasks, or startup entries.
The immediate priority after containment is to identify and remove any persistence mechanisms the attacker may have established. Checking system logs for unauthorized registry modifications (e.g., Run keys), scheduled tasks (e.g., schtasks), and startup entries (e.g., Startup folder or services) directly addresses the uncertainty about persistence. This step ensures the attacker cannot regain access after cleanup, aligning with the eradication phase of the incident response plan.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check system logs for unauthorized registry modifications, scheduled tasks, or startup entries.
Why this is correct
Persistence mechanisms such as registry Run keys, scheduled tasks and startup entries let malware survive reboots and credential resets. Auditing these locations on the quarantined workstation confirms whether the attacker retained a foothold before eradication and recovery proceed.
- ✗
Perform a full malware analysis of the file to understand its capabilities.
Why it's wrong here
Analysing the sample reveals malware capabilities but does not itself remove attacker persistence, so access could be regained after cleanup. It is tempting because understanding the malware informs eradication, and it would be correct earlier, during scoping, before containment and remediation decisions are finalised.
- ✗
Notify affected customers immediately as required by data breach notification laws.
Why it's wrong here
Customer notification is a legal obligation triggered after scope and impact are established, not a step that prevents the attacker regaining access. It is tempting because breach notification deadlines are strict, and it would be correct once forensic investigation confirms what personal data was actually exfiltrated.
- ✗
Reimage the user's workstation from a known good backup.
Why it's wrong here
Reimaging the workstation eradicates malware on that host but leaves attacker persistence elsewhere — stolen credentials, tokens or additional accounts — intact. It is tempting because reimaging is standard host remediation, and it would be correct once persistence mechanisms are identified and the scope of compromise is known.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.