Courseiva

SSCP Incident Response and Recovery Practice Question

An organization has suffered a ransomware attack that encrypted files on several file servers. The incident response team is planning recovery. Which TWO actions should be performed to verify that the restored systems are clean before returning them to production? (Select TWO)

⚠ Common exam trap

A common mix-up: candidates assume restoring from a clean backup (Option A) is sufficient to guarantee a clean system, but the SSCP exam emphasizes that backups must be verified as malware-free and that additional validation steps (scanning and monitoring) are required before returning systems to production.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a full antivirus and anti-malware scan on the restored systems

Option C is correct because running a full antivirus and anti-malware scan on the restored systems is a direct verification step that checks the restored data and OS for any residual malware, ransomware payloads, or infected files before the systems are trusted again. Option E is correct because monitoring the restored systems for reinfection or anomalous behavior over a period of time provides ongoing validation that no dormant persistence mechanisms, scheduled tasks, or command-and-control callbacks survived the recovery process. Option A is not a verification action; restoring from the most recent backup is a recovery step, and that backup itself may contain the ransomware or an earlier compromise. Option B does not verify system cleanliness; changing user passwords is a containment/credential-hygiene measure and does nothing to detect malware on the restored hosts. Option D is also not a verification step; applying OS security patches remediates known vulnerabilities but does not confirm that the restored systems are free of the ransomware or other malware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restore the systems from the most recent backup

    Why it's wrong here

    Restoring is part of recovery, not verification.

  • ✗

    Change all user passwords associated with the systems

    Why it's wrong here

    Password reset is an eradication step, not a verification step.

  • ✓

    Run a full antivirus and anti-malware scan on the restored systems

    Why this is correct

    Scanning restored systems with current antivirus and anti-malware signatures detects any residual malware, backdoors or dormant payloads the ransomware may have left behind. This directly satisfies the stem's requirement to verify systems are clean before returning them to production.

  • ✗

    Apply all security patches to the operating system

    Why it's wrong here

    Patching is important but does not verify cleanliness; it prevents future exploits.

  • ✓

    Monitor the systems for any signs of reinfection or anomalous behavior for a period of time

    Why this is correct

    Continuous monitoring after restoration detects reinfection, beaconing or anomalous behaviour that a single scan may miss, confirming the systems remain clean over time. This satisfies the stem's verification requirement by providing ongoing assurance before and after production reinstatement.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.