Courseiva
easyMultiple Select

SSCP Practice Question: A security analyst notices unusual outbound…

A security analyst notices unusual outbound traffic from a server. Which TWO actions should be taken immediately as part of the incident response process?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the affected system from the network.

Isolating the affected system (B) prevents further damage or data exfiltration. Capturing memory and network traffic (D) preserves volatile evidence for analysis. Conducting a vulnerability scan (A) is not immediate. Reimaging (C) is premature before investigation. Notifying law enforcement (E) is not an immediate step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct a full vulnerability scan on the system.

    Why it's wrong here

    A full vulnerability scan is slow, generates heavy traffic and does not contain the active incident, so it delays isolation and evidence preservation. It is tempting because scanning is a familiar security task; it would be correct during routine assessment or after containment, not in the immediate response phase.

  • ✓

    Isolate the affected system from the network.

    Why this is correct

    Isolating the affected system from the network contains the incident, preventing further data exfiltration or command-and-control communication while preserving the host for investigation. Containment is an immediate priority once unusual outbound traffic confirms possible compromise.

  • ✗

    Reimage the system to remove any malware.

    Why it's wrong here

    Reimaging destroys volatile memory and disk artefacts needed for root-cause analysis, and the compromise vector may persist, causing reinfection. It is tempting because it appears to guarantee malware removal; reimaging would be correct during recovery, after containment and forensic capture are complete.

  • ✓

    Capture memory and network traffic for analysis.

    Why this is correct

    Capturing memory and network traffic preserves volatile evidence before it is lost through reboots or process termination, supporting later forensic analysis of the unusual outbound traffic. This evidence-gathering step complements containment during the immediate incident response phase.

  • ✗

    Notify law enforcement authorities.

    Why it's wrong here

    Law enforcement notification follows internal escalation, containment and evidence gathering, and premature contact can compromise forensic handling. It is tempting because unusual outbound traffic may indicate criminal activity; notifying authorities would be correct once the incident is confirmed and organisational policy requires it.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.