SSCP Incident Response and Recovery Practice Question
A security analyst is reviewing the organization's incident response plan and wants to ensure it includes the necessary elements for the preparation phase according to NIST SP 800-61. Which of the following should be included in the preparation phase? (Choose two.)
⚠ Common exam trap
Candidates often confuse activities from other phases, such as lessons learned, eradication, or recovery, with preparation phase elements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Developing an incident response policy that defines roles and responsibilities.
The preparation phase of the NIST SP 800-61 incident response lifecycle includes activities that establish the capability to respond to incidents. This includes creating an incident response policy that defines roles and responsibilities, and establishing a communication plan with stakeholders. These elements ensure the organization is ready to detect, analyze, and respond to incidents effectively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Eradicating malware from infected systems.
Why it's wrong here
Eradication is part of the containment, eradication, and recovery phase, not preparation. It involves removing the threat from the environment after containment. The preparation phase focuses on planning, training, and equipping the team, not on active response actions.
- ✗
Recovering data from backups.
Why it's wrong here
Recovery is part of the containment, eradication, and recovery phase. It involves restoring systems and data to normal operations after the threat has been eradicated. Preparation includes ensuring backups are available and tested, but the act of recovering data occurs during the recovery phase.
- ✓
Developing an incident response policy that defines roles and responsibilities.
Why this is correct
An incident response policy is a foundational element of the preparation phase. It establishes the authority, scope, and responsibilities for incident response, ensuring that all stakeholders understand their roles. NIST SP 800-61 specifically lists the creation of an incident response policy as a key preparation activity, as it provides the framework for the entire incident response lifecycle.
- ✓
Establishing a communication plan with internal and external stakeholders.
Why this is correct
A communication plan is critical for the preparation phase. It defines how information will be shared during an incident, including contact information for team members, legal counsel, and public relations. NIST SP 800-61 highlights the need for communication procedures to ensure timely and accurate information flow, which is essential for effective incident response.
- ✗
Conducting a lessons learned meeting after an incident.
Why it's wrong here
Lessons learned meetings are part of the post-incident activity phase, not preparation. They are conducted after an incident to identify improvements. While the outcomes may feed back into preparation, the activity itself occurs post-incident. Therefore, it is not a preparation phase element.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.