Courseiva
mediumMultiple Choice

SSCP Practice Question: After a security incident, the CSIRT is…

After a security incident, the CSIRT is conducting lessons learned. Which output is most directly used to update the risk management process?

⚠ Common exam trap

Test-takers frequently confuse operational outputs (corrective actions, updated IR plans) with the formal risk management artifact (risk register) that directly influences risk acceptance, mitigation, or transfer decisions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk register updates.

The risk management process is directly updated by incorporating new risk information derived from incident analysis. Risk register updates (option B) capture newly identified risks, changes in risk likelihood or impact, and the effectiveness of existing controls, which are the primary outputs that feed back into risk treatment decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Updated incident response plan.

    Why it's wrong here

    The incident response plan governs how future incidents are handled, not the likelihood or impact ratings in the risk register. It tempts because lessons learned routinely feed plan revisions, but the risk management process is updated through reassessed risk entries, not response procedures.

  • ✓

    Risk register updates.

    Why this is correct

    Risk register updates capture the incident's identified vulnerabilities, likelihood and impact changes, feeding directly into the risk management process. This satisfies the stem's requirement for the most direct output, since the register is the formal artefact through which lessons learned alter documented risk treatment decisions.

  • ✗

    Corrective actions.

    Why it's wrong here

    Corrective actions address the specific incident's root cause, not the likelihood or impact values recorded in the risk register. It tempts because remediation feels risk-related, yet updating the risk management process requires reassessing identified risks and their ratings, which the lessons-learned risk review produces.

  • ✗

    Forensic report.

    Why it's wrong here

    A forensic report documents evidence and timeline for legal or investigative purposes, not risk likelihood or impact values. It tempts because it emerges from the same lessons-learned activity, but the risk management process is updated by reassessing identified risks, not by evidentiary documentation.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.