SSCP Incident Response and Recovery Practice Question
A security analyst is reviewing the incident response plan and wants to ensure the containment strategy is effective for a recent malware outbreak. The analyst must choose containment measures that align with NIST SP 800-61. Which TWO actions are appropriate containment strategies? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse eradication and recovery actions with containment, when containment specifically aims to stop the spread without necessarily removing the threat.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Applying a temporary firewall rule to block command-and-control traffic
Containment strategies in NIST SP 800-61 focus on limiting the scope and impact of an incident. Disconnecting infected systems and blocking command-and-control traffic both prevent further spread or attacker communication. Deleting files, restoring backups, and holding lessons learned meetings are eradication, recovery, or post-incident activities, not containment. The two correct actions directly stop the incident from expanding while analysis continues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restoring the infected systems from a known good backup
Why it's wrong here
Restoring from backup is a recovery action that occurs after containment and eradication. It does not stop the spread of malware and may reintroduce the threat if the backup is not clean or if the vulnerability remains. NIST SP 800-61 sequences recovery after containment and eradication. Therefore, this is not a containment strategy.
- ✗
Immediately deleting all files created in the last 24 hours on the infected systems
Why it's wrong here
Deleting files is an eradication action, not containment, and it may destroy evidence needed for analysis. Containment aims to stop the spread, not remove malware. NIST SP 800-61 separates containment from eradication; performing eradication prematurely can hinder root cause analysis. This action is inappropriate as a containment measure.
- ✓
Applying a temporary firewall rule to block command-and-control traffic
Why this is correct
Blocking command-and-control traffic via firewall rules is a containment technique that cuts off attacker communication without necessarily disconnecting all systems. NIST SP 800-61 supports using network controls to contain incidents. This approach can be more surgical than full isolation, allowing business operations to continue while preventing further malicious activity. It is a valid containment strategy.
- ✗
Conducting a lessons learned meeting with the incident response team
Why it's wrong here
A lessons learned meeting is a post-incident activity that happens after the incident is resolved. It does not contain an active malware outbreak. NIST SP 800-61 places lessons learned in the post-incident phase. While valuable for improvement, it is not a containment measure and does nothing to stop the current spread, making it incorrect.
- ✓
Disconnecting the infected systems from the network
Why this is correct
Disconnecting infected systems from the network is a classic containment strategy that prevents malware from spreading to other systems. NIST SP 800-61 lists network isolation as a containment method. It limits lateral movement and further compromise while allowing the incident response team to analyze and remediate. This action directly addresses the goal of containment, making it correct.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.