SSCP Incident Response and Recovery Practice Question
An analyst detects suspicious outbound traffic from a server to a known command-and-control IP address. According to NIST SP 800-61, which phase of the incident response lifecycle does this activity fall under?
⚠ Common exam trap
ISC2 SSCP often tests the distinction between 'Detection and Analysis' and 'Containment, Eradication, and Recovery' by presenting a detection event and expecting candidates to recognize that containment actions are separate and occur later in the lifecycle.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detection and Analysis
The detection of suspicious outbound traffic to a known command-and-control IP address is a clear indicator of a potential security incident. According to NIST SP 800-61, this activity falls under the 'Detection and Analysis' phase, which involves identifying and validating that an incident has occurred through monitoring, alerting, and analysis of security events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Post-Incident Activity
Why it's wrong here
Post-Incident Activity covers lessons learned, evidence retention and reporting after containment, eradication and recovery are complete. Detection is still in progress here. It is tempting because the analyst is reviewing evidence, but that review happens after the incident is resolved, not while traffic is ongoing.
- ✗
Preparation
Why it's wrong here
Preparation covers establishing capability, tools and training before incidents occur; detecting live command-and-control traffic is the Detection and Analysis phase. It is tempting because preparation includes monitoring infrastructure, but the act of identifying an active indicator is detection, not readiness.
- ✗
Containment, Eradication, and Recovery
Why it's wrong here
Containment, Eradication and Recovery covers limiting damage, removing the threat and restoring systems once an incident is confirmed. Detection precedes it. It is tempting because the traffic suggests compromise, but the analyst has only identified the indicator, not yet contained or eradicated anything.
- ✓
Detection and Analysis
Why this is correct
Detecting suspicious outbound traffic to a known command-and-control IP is the identification of a potential security event, which NIST SP 800-61 places squarely within Detection and Analysis. This phase covers monitoring, triage and validating whether activity constitutes a genuine incident before containment begins.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.