SSCP Incident Response and Recovery Practice Question
After a security incident, the response team holds a lessons learned meeting. Which TWO are primary objectives of this meeting? (Select two.)
⚠ Common exam trap
Watch out — candidates often confuse operational recovery tasks (like restoring systems or deleting evidence) with the strategic, process-improvement objectives of the lessons learned meeting, which are solely focused on analyzing the response and updating documentation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify what went well and what could be improved
Option A is correct because a lessons learned (post-incident) meeting is fundamentally a review activity whose primary purpose is to evaluate the response effort, capturing both effective actions ('what went well') and gaps or weaknesses ('what could be improved') so the organization can learn from the incident. Option B is correct because the actionable output of that review is to feed findings back into the incident response plan, playbooks, and runbooks — updating procedures, detection rules, and escalation paths so future incidents are handled more effectively. Option C is incorrect because evidence must be preserved for forensic analysis, legal, and regulatory purposes, not deleted; evidence handling follows chain-of-custody requirements. Option D is incorrect because lessons learned meetings are blameless post-mortems focused on process and systemic improvement, not on assigning individual fault, which would suppress honest reporting. Option E is incorrect because restoring affected systems to production is part of the recovery/eradication phase of incident handling, not an objective of the post-incident lessons learned meeting, which occurs after recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identify what went well and what could be improved
Why this is correct
Reviewing what went well and what could be improved captures strengths and gaps in detection, response and coordination, which is a primary purpose of the post-incident lessons learned meeting. It feeds directly into refining processes rather than assigning blame.
- ✓
Update the incident response plan and runbooks
Why this is correct
Lessons learned outputs must be fed back into the incident response plan and runbooks so future responses reflect the gaps just identified. This closes the loop between the post-incident review and preparation, satisfying the stem's requirement for a primary objective of the meeting.
- ✗
Delete all evidence to free up storage
Why it's wrong here
Evidence must be retained for legal, regulatory and forensic purposes; deleting it destroys the material the review analyses and may breach obligations. It is tempting when storage costs or data-minimisation policies are a concern, and would apply to securely disposing of data once retention periods expire.
- ✗
Assign blame for the incident
Why it's wrong here
Lessons learned examines what happened and how to improve controls; assigning blame discourages the honest reporting the meeting depends on and produces no control change. It is tempting because accountability feels like a natural outcome of an incident review, and would be relevant in a disciplinary or HR process, not here.
- ✗
Restore affected systems to production
Why it's wrong here
Restoring systems belongs to the recovery and eradication phases, which occur before the review; the lessons learned meeting happens afterwards and produces recommendations. It is tempting because restoration is a visible incident-response activity, and would be the correct focus during the containment and recovery stage.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. After a security incident, the incident response team holds a lessons learned meeting. What is the PRIMARY outcome of this meeting?
medium- A.Permanently delete all evidence related to the incident
- B.Inform the media about the incident details
- ✓ C.Identify improvements to the incident response process
- D.Assign blame for the incident
Why C: The primary outcome of a lessons learned meeting is to identify improvements to the incident response process. This meeting focuses on analyzing what worked well and what did not, leading to actionable changes in policies, procedures, and tools to enhance future incident handling. It is a key component of the continuous improvement cycle mandated by frameworks like NIST SP 800-61.
Variation 2. What is the PRIMARY purpose of a lessons learned meeting after an incident?
easy- A.To assign blame for the incident
- B.To satisfy regulatory compliance requirements
- C.To calculate the financial cost of the incident
- ✓ D.To identify improvements in the incident response process
Why D: The primary purpose of a lessons learned meeting is to analyze the incident response process to identify what worked well and what did not, enabling the team to update procedures, playbooks, and tools to improve future responses. This aligns with the continuous improvement cycle mandated by frameworks like NIST SP 800-61, which emphasizes post-incident activity to refine detection and remediation capabilities.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.