Courseiva

SSCP Incident Response and Recovery Practice Question

An incident responder is analyzing a network packet capture to determine the scope of a data exfiltration incident. The responder notices a large volume of outbound traffic to an unfamiliar IP address over port 443. Which of the following should the responder do FIRST to determine if the traffic is malicious?

⚠ Common exam trap

The trap here is jumping to containment or external intelligence lookups before analyzing the actual traffic, which is the most direct way to confirm malicious activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inspect the packet payload and metadata for signs of command-and-control or data exfiltration.

To determine if the outbound traffic is malicious, the responder must first inspect the packet payload and metadata. This direct analysis can reveal signs of exfiltration, such as large data transfers, unusual protocols, or communication patterns indicative of command-and-control. It provides concrete evidence before taking any containment or intelligence-gathering steps that might be premature.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Block the IP address at the firewall to stop the exfiltration.

    Why it's wrong here

    Blocking the IP address may stop the immediate exfiltration, but it could also tip off the attacker and cause them to change tactics, making it harder to determine the full scope. The first step should be to analyze the traffic to confirm maliciousness and gather intelligence, not to take containment actions that might destroy evidence or alert the adversary.

  • ✗

    Check the IP address against a threat intelligence feed to see if it is known malicious.

    Why it's wrong here

    Checking threat intelligence is a valuable step, but it should not be the first action. Threat feeds may not have the IP listed if it is new or part of a targeted attack. The responder should first analyze the traffic to understand its nature, then use threat intelligence to corroborate findings. Relying solely on feeds could miss novel threats and does not analyze the actual traffic.

  • ✓

    Inspect the packet payload and metadata for signs of command-and-control or data exfiltration.

    Why this is correct

    The first step in determining if the traffic is malicious is to analyze the packets themselves. This includes examining payloads for known malware signatures, checking for unusual protocols or patterns, and looking at metadata such as packet sizes, timing, and frequency. This analysis can reveal if the traffic is encrypted command-and-control, data exfiltration, or benign. It provides the evidence needed to justify further actions.

  • ✗

    Perform reverse DNS lookup and WHOIS on the IP address to gather ownership information.

    Why it's wrong here

    Reverse DNS and WHOIS can provide useful context about the IP address, such as the owning organization, but they do not confirm whether the traffic is malicious. Attackers often use compromised or cloud-hosted IPs, so this information alone is insufficient. The responder should first inspect the traffic content and behavior to determine if it indicates exfiltration.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.