mediumMultiple Choice
SSCP Practice Question: A security administrator notices that a critical…
A security administrator notices that a critical server's event log shows repeated failed login attempts from an internal IP address that normally does not generate any traffic. The administrator immediately blocks the IP at the firewall and resets the account password. However, the incident response team later determines that the attacker had already gained access to the server. What is the MOST likely reason the administrator's actions were insufficient?
⚠ Common exam trap
SSCP often tests the distinction between containment and other incident response steps — candidates may focus on evidence preservation or malware scanning, but the key is that without isolation, the attacker retains access and can continue malicious activities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The administrator did not isolate the server from the network.
The most likely reason the administrator's actions were insufficient is that the server was not isolated from the network. If the attacker already gained access, blocking the IP and resetting the password does not remove the attacker's presence or prevent lateral movement or data exfiltration. Isolation is a critical containment step in incident response that limits the attacker's ability to maintain persistence or cause further damage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The administrator did not preserve the log evidence for forensic analysis.
Why it's wrong here
Blocking the IP and resetting the password addresses containment, but the attacker already held valid access, so evidence preservation would not have prevented the breach. It is tempting because forensic integrity matters in incident response, and would be correct if the question asked why attribution or legal action later failed.
- ✗
The administrator neglected to perform a full system scan for malware.
Why it's wrong here
Malware scanning addresses persistence mechanisms, but the attacker already held valid credentials, so blocking the source IP and resetting the password leaves existing sessions and any backdoor accounts untouched. Scanning suits post-compromise cleanup; here the gap is that compromised credentials were used, not malicious code.
- ✓
The administrator did not isolate the server from the network.
Why this is correct
Blocking the source IP and resetting the password only evict future attempts; they do not terminate an established session or remove malware already resident. Without isolating the server, the attacker retained active access, so containment failed despite the firewall and credential changes.
- ✗
The administrator failed to notify the data owner about the incident.
Why it's wrong here
Notifying the data owner is a governance and communication step, not a containment control. The attacker's access persisted because the compromised credential remained valid elsewhere, so the response failed technically. Data-owner notification is required under privacy obligations once a breach is confirmed, but it never removes an attacker's foothold.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.