Courseiva
easyMultiple ChoiceObjective-mapped

SSCP Practice Question: After a security incident, the CISO asks for a…

After a security incident, the CISO asks for a report detailing which assets were affected, the attack vector, and the financial impact. Which of the following best describes this report?

⚠ Common exam trap

ISC2 often tests the distinction between proactive planning documents (incident response plan, BIA) and reactive post-incident reports (lessons learned), leading candidates to confuse the BIA's financial impact analysis with the incident-specific financial impact in the lessons learned report.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Lessons learned report

A lessons learned report is a post-incident document that captures what happened during a security incident, including affected assets, the attack vector, and financial impact. It is used to improve future incident response processes and is distinct from operational plans or risk assessments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Lessons learned report

    Why this is correct

    A lessons learned report captures post-incident details and improvements.

  • Incident response plan

    Why it's wrong here

    An incident response plan outlines procedures, not a report of a specific incident.

  • Risk register

    Why it's wrong here

    A risk register is a list of identified risks, not a post-incident analysis.

  • Business impact analysis (BIA)

    Why it's wrong here

    BIA is conducted before an incident to determine criticality.

About these practice questions

One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.