SSCP Incident Response and Recovery Practice Question
An organization is developing its incident response plan. According to NIST SP 800-61, which phase should include establishing a communication plan, acquiring necessary tools, and conducting exercises?
⚠ Common exam trap
A common misconception is that Detection and Analysis includes proactive preparation activities, but NIST SP 800-61 clearly separates the proactive Preparation phase from the reactive Detection phase, which only begins after an incident is suspected.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preparation
According to NIST SP 800-61, the Preparation phase is where the organization establishes a communication plan, acquires necessary tools (e.g., forensic workstations, imaging software, network monitoring tools), and conducts exercises (e.g., tabletop exercises or full-scale simulations) to ensure readiness. This phase lays the foundation for all subsequent incident response activities by ensuring resources and procedures are in place before an incident occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Preparation
Why this is correct
Preparation covers building incident response capability before incidents occur, including developing the communication plan, procuring tools and resources, and running exercises to validate readiness. NIST SP 800-61 places all three activities in this phase, preceding detection, containment, and post-incident work.
- ✗
Post-Incident Activity
Why it's wrong here
Preparation is the phase where NIST SP 800-61 places communication planning, tool acquisition and exercises; Post-Incident Activity instead reviews lessons learned after an incident closes. It tempts because exercises and tooling feel like ongoing improvement work, and that phase does capture findings that refine future preparation.
- ✗
Detection and Analysis
Why it's wrong here
Detection and Analysis covers monitoring, triage and validating whether an event is an incident; communication plans, tool acquisition and exercises are prepared beforehand. This phase would be correct if the question asked where alerts are correlated and incidents are confirmed and scoped.
- ✗
Containment, Eradication, and Recovery
Why it's wrong here
Containment, Eradication and Recovery executes the response once an incident is confirmed, limiting spread and restoring systems; preparation activities such as communication planning, tooling and exercises occur earlier. This phase would be correct if the stem described isolating affected hosts or rebuilding compromised systems.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.