Courseiva
easyMultiple Choice

SSCP Practice Question: A small financial services company has deployed a…

A small financial services company has deployed a SIEM solution collecting logs from their firewall, web server, and domain controller. They also have an IDS monitoring the network perimeter. The security analyst receives an alert from the IDS indicating a potential exploit attempt against the web server from an external IP. The analyst checks the SIEM and sees that the firewall log shows the connection was allowed, but the web server log does not show any corresponding request. The domain controller logs show no abnormal activity. The company has a policy to immediately contain any confirmed threats. What should the analyst do first based on this information?

⚠ Common exam trap

SSCP often tests the order of incident response steps—candidates jump to containment (block IP, reboot) because the scenario feels urgent, but the policy says 'confirmed threats,' and the evidence is not yet confirmed, so verification must come first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the web server's integrity by checking for filesystem changes or anomalous processes

The analyst should first verify the web server's integrity by checking for filesystem changes or anomalous processes, because the IDS alert plus the firewall 'allow' but missing web server log entry suggests a possible discrepancy—either the request was dropped before reaching the app, or the web server was compromised and its logging tampered with. Confirming whether exploitation actually occurred is the correct first step before containment, since the policy requires containing 'confirmed' threats. This aligns with the incident response 'identification/validation' phase before eradication and containment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reboot the web server to clear any potential memory-resident malware

    Why it's wrong here

    Rebooting destroys volatile memory evidence and disrupts a production web server before any threat is confirmed. The missing web server log entry suggests the IDS alert may be a false positive, so containment is unwarranted. Rebooting is a recovery action, appropriate only after an incident is verified and scoped.

  • ✗

    Block the external IP at the firewall

    Why it's wrong here

    Blocking the IP acts on unconfirmed evidence: the firewall allowed the connection, yet the web server logged no matching request, so the exploit may never have reached the host. Containment should follow confirmation. Blocking would be right once the SIEM and web server logs corroborate an actual compromise.

  • ✓

    Verify the web server's integrity by checking for filesystem changes or anomalous processes

    Why this is correct

    The firewall allowed the connection yet the web server logged no matching request, so the exploit may have succeeded silently. Checking filesystem changes and anomalous processes establishes whether compromise actually occurred before invoking the containment policy, avoiding premature isolation based on unconfirmed evidence.

  • ✗

    Escalate the alert to the incident response team

    Why it's wrong here

    Escalation is premature: the web server log shows no matching request, so the IDS alert may be a false positive and no threat is confirmed. The policy requires containment only for confirmed threats, and the analyst should first correlate further evidence. Escalation suits a verified incident needing specialist response.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.