easyMultiple ChoiceObjective-mapped
SSCP Practice Question: A medium-sized company recently experienced a…
A medium-sized company recently experienced a phishing attack where an employee downloaded a malicious attachment, leading to a data breach. The incident response team has identified the affected user and the malware. However, the team is unsure whether the attacker has established persistence. The security analyst must recommend the next step. The company has a standard incident response plan that includes detection, containment, eradication, recovery, and lessons learned. The malware sample has been isolated for analysis. The user's account has been disabled temporarily. The network team has quarantined the user's workstation. The analyst needs to ensure the attacker cannot regain access after the initial cleanup. What should the analyst recommend next?
⚠ Common exam trap
The trap here is that candidates may jump to reimaging (Option D) as a quick fix, but without first verifying and removing persistence, the attacker could have established footholds on other systems or in the backup itself, making reimaging ineffective.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check system logs for unauthorized registry modifications, scheduled tasks, or startup entries.
The immediate priority after containment is to identify and remove any persistence mechanisms the attacker may have established. Checking system logs for unauthorized registry modifications (e.g., Run keys), scheduled tasks (e.g., schtasks), and startup entries (e.g., Startup folder or services) directly addresses the uncertainty about persistence. This step ensures the attacker cannot regain access after cleanup, aligning with the eradication phase of the incident response plan.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check system logs for unauthorized registry modifications, scheduled tasks, or startup entries.
Why this is correct
Correct: This directly checks for common persistence mechanisms used by attackers.
- ✗
Perform a full malware analysis of the file to understand its capabilities.
Why it's wrong here
Incorrect: Malware analysis provides intelligence but does not immediately identify persistence on the system.
- ✗
Notify affected customers immediately as required by data breach notification laws.
Why it's wrong here
Incorrect: Notification should occur after confirming the breach scope and impact, not before investigation.
- ✗
Reimage the user's workstation from a known good backup.
Why it's wrong here
Incorrect: Reimaging may remove persistence but if other systems are compromised, the attacker could still have access; also need to understand the full extent first.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 920-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.