Courseiva

SSCP Incident Response and Recovery Practice Question

An analyst detects suspicious outbound traffic from a server to a known command-and-control IP address. According to NIST SP 800-61, which phase of the incident response lifecycle does this activity fall under?

⚠ Common exam trap

ISC2 SSCP often tests the distinction between 'Detection and Analysis' and 'Containment, Eradication, and Recovery' by presenting a detection event and expecting candidates to recognize that containment actions are separate and occur later in the lifecycle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detection and Analysis

The detection of suspicious outbound traffic to a known command-and-control IP address is a clear indicator of a potential security incident. According to NIST SP 800-61, this activity falls under the 'Detection and Analysis' phase, which involves identifying and validating that an incident has occurred through monitoring, alerting, and analysis of security events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Post-Incident Activity

    Why it's wrong here

    Post-Incident Activity covers lessons learned, evidence retention and reporting after containment, eradication and recovery are complete. Detection is still in progress here. It is tempting because the analyst is reviewing evidence, but that review happens after the incident is resolved, not while traffic is ongoing.

  • ✗

    Preparation

    Why it's wrong here

    Preparation covers establishing capability, tools and training before incidents occur; detecting live command-and-control traffic is the Detection and Analysis phase. It is tempting because preparation includes monitoring infrastructure, but the act of identifying an active indicator is detection, not readiness.

  • ✗

    Containment, Eradication, and Recovery

    Why it's wrong here

    Containment, Eradication and Recovery covers limiting damage, removing the threat and restoring systems once an incident is confirmed. Detection precedes it. It is tempting because the traffic suggests compromise, but the analyst has only identified the indicator, not yet contained or eradicated anything.

  • ✓

    Detection and Analysis

    Why this is correct

    Detecting suspicious outbound traffic to a known command-and-control IP is the identification of a potential security event, which NIST SP 800-61 places squarely within Detection and Analysis. This phase covers monitoring, triage and validating whether activity constitutes a genuine incident before containment begins.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.