SSCP Incident Response and Recovery Practice Question
A security team is conducting a lessons learned meeting after a major security incident. Which TWO of the following are PRIMARY objectives of this meeting? (Choose two.)
⚠ Common exam trap
The trap here is thinking that assigning blame or determining financial costs are key objectives, when the focus should be on learning and improvement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify the root cause of the incident to prevent recurrence.
The primary objectives of a lessons learned meeting are to identify the root cause of the incident and to evaluate the effectiveness of the incident response process. These objectives help the organization prevent future incidents and improve its response capabilities. Blame assignment, financial cost determination, and specific plan updates are not primary goals of this meeting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identify the root cause of the incident to prevent recurrence.
Why this is correct
One primary objective of a lessons learned meeting is to determine the root cause of the incident. By understanding what allowed the incident to occur, the team can implement corrective actions to prevent similar incidents in the future. This analysis is a core part of the post-incident activity phase in NIST SP 800-61.
- ✗
Determine the financial cost of the incident for insurance claims.
Why it's wrong here
While financial impact may be discussed, determining cost for insurance is not a primary objective of a lessons learned meeting. The meeting's focus is on technical and procedural improvements, not on financial recovery. Cost analysis is typically handled separately by management and finance teams.
- ✓
Evaluate the effectiveness of the incident response process and identify improvements.
Why this is correct
Another primary objective is to assess how well the incident response process worked and where it can be improved. This includes reviewing detection, analysis, containment, eradication, and recovery steps. Identifying gaps and successes helps refine the incident response plan and enhance future readiness.
- ✗
Assign blame to the individuals responsible for the incident.
Why it's wrong here
Assigning blame is counterproductive and not an objective of a lessons learned meeting. The focus should be on improving processes and systems, not on punishing individuals. A blame-oriented culture can discourage reporting and hinder open communication, which is essential for effective incident response.
- ✗
Update the disaster recovery plan with new backup procedures.
Why it's wrong here
Updating the disaster recovery plan may result from lessons learned, but it is not a primary objective of the meeting itself. The meeting aims to identify improvements, which could include changes to the DR plan, but the primary objectives are root cause analysis and process evaluation. The actual update would occur afterward.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.