SSCP Incident Response and Recovery Practice Question
After a security incident, the incident response team holds a lessons learned meeting. What is the PRIMARY outcome of this meeting?
⚠ Common exam trap
Watch out — candidates often confuse the lessons learned meeting with the immediate operational steps of incident response, such as evidence handling or public relations, rather than recognizing its core purpose of process improvement and continuous learning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify improvements to the incident response process
The primary outcome of a lessons learned meeting is to identify improvements to the incident response process. This meeting focuses on analyzing what worked well and what did not, leading to actionable changes in policies, procedures, and tools to enhance future incident handling. It is a key component of the continuous improvement cycle mandated by frameworks like NIST SP 800-61.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Permanently delete all evidence related to the incident
Why it's wrong here
Lessons learned produces recommendations and updates to plans, procedures and controls; deleting evidence destroys the audit trail needed for legal, regulatory and forensic follow-up. Retention is often mandated. The meeting is tempting as a tidy-up step after closure, but evidence preservation is exactly what incident handling requires, not destruction.
- ✗
Inform the media about the incident details
Why it's wrong here
Lessons learned produces internal process improvements, not external communications; media notification is handled by public relations or communications staff. It is tempting because incident details do eventually reach the public, and would be correct for a press briefing or disclosure meeting rather than a review.
- ✓
Identify improvements to the incident response process
Why this is correct
The lessons learned meeting reviews what occurred, what worked and what failed, then produces actionable recommendations to strengthen the incident response plan, tools and procedures. Its primary outcome is documented process improvement, not blame or immediate remediation of the affected systems.
- ✗
Assign blame for the incident
Why it's wrong here
The meeting identifies control gaps and improves future response; assigning blame discourages honest reporting and yields no corrective action. It is tempting because accountability feels like a natural post-incident step, and would be correct for a disciplinary or HR investigation, not a lessons learned review.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.