Courseiva

SSCP · domain

Incident Response and Recovery

This domain covers the SSCP incident response lifecycle: preparation, detection and analysis, containment, eradication, recovery, and post-incident lessons learned. Questions test your judgment on ordering actions correctly, selecting containment scope, using evidence-handling and forensic practices, and aligning response with business continuity and disaster recovery priorities.

83 questions17 easy45 medium21 hard

Focused practice

Practice Incident Response and Recovery questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Incident Response and Recovery

Be able to sequence incident response phases correctly and pick the right containment action first. The single most important thing: contain the threat before eradicating or recovering, while preserving evidence and following the IR plan.

Ordering the IR lifecycle phases and selecting preparation components like an IR plan and trained response team

Choosing containment scope (isolate host, segment network, disable account) to stop lateral movement

Applying evidence handling and chain of custody so forensic artifacts remain admissible

Distinguishing incident response from business continuity and disaster recovery roles and triggers

Watch out for

Common Incident Response and Recovery exam traps

  • ▸Jumping straight to eradication or recovery before containing the threat, letting the adversary spread further
  • ▸Confusing business continuity (keep operations running) with disaster recovery (restore IT systems) when choosing the right plan
  • ▸Treating lessons learned as blame assignment instead of process improvement, missing the primary purpose

Question index

All Incident Response and Recovery questions (83)

Click any question to see the full explanation, or start a practice session above.

1

An incident responder needs to create a forensic image of a suspect hard drive. What is the correct procedure to ensure evidence integrity?

Medium
2

A financial services firm's incident response plan defines a Recovery Time Objective (RTO) of 2 hours for its online trading platform. During a tabletop exercise, the team discovers that the current disaster recovery runbook requires manual steps that take approximately 6 hours to complete. The Chief Information Security Officer (CISO) asks for a recommendation to align the recovery capability with the RTO without increasing the budget significantly. Which of the following is the MOST appropriate recommendation?

Hard
3

After a ransomware incident, the incident response team is conducting recovery. Which THREE steps are essential to ensure a secure restoration and prevent reinfection? (Choose three.)

Medium
4

A security analyst is reviewing a disaster recovery plan and notes that the organization has a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 2 hours for a critical database. Which of the following backup strategies BEST meets these objectives?

Hard
5

A company is developing a DR plan for a critical database. The maximum acceptable downtime is 2 hours, and the maximum data loss is 1 hour. What are the RTO and RPO?

Medium
6

During the detection and analysis phase, an analyst receives a user report of unusual system behavior. The analyst reviews logs and finds several failed login attempts followed by a successful login from an unusual IP address. What is the next step?

Medium
7

A forensic examiner is preparing to acquire a disk image from a compromised server. The server is still running and contains critical evidence in volatile memory. According to NIST SP 800-86, which of the following should the examiner do FIRST?

Hard
8

A forensic examiner is preparing to acquire a forensic image of a running Linux server that is suspected of being compromised. The server has active network connections and encrypted volumes. Which of the following should the examiner do FIRST according to the order of volatility?

Hard
9

A security team is conducting a lessons learned meeting after a major security incident. Which TWO of the following are PRIMARY objectives of this meeting? (Choose two.)

Medium
10

After a ransomware incident, an organization decides to restore data from backups. The RPO (Recovery Point Objective) is 4 hours. What does this RPO indicate?

Medium
11

A company's disaster recovery plan specifies an RTO of 4 hours for its customer relationship management (CRM) system. Which of the following DR site types is MOST appropriate to meet this RTO?

Hard
12

After a security incident at a retail company, the incident response team conducts a post-incident review. The team identifies that the attacker gained initial access through an unpatched web server. Which of the following is the PRIMARY purpose of the lessons learned meeting in this scenario?

Easy
13

A security analyst is responding to a confirmed malware infection on a Windows workstation. The workstation is still powered on and connected to the corporate network. The analyst needs to collect volatile data that could be lost if the system is shut down or the malware is allowed to continue running. Which TWO of the following data sources should the analyst prioritize for collection? (Choose two.)

Medium
14

An organization is conducting a disaster recovery test for its critical database. The RTO is 4 hours, and the RPO is 15 minutes. During the test, the team restores the database from a backup taken 2 hours before the test. The restore completes in 3 hours. Which statement accurately reflects the test outcome?

Hard
15

A security analyst is documenting an incident that involved unauthorized access to a file server. The analyst needs to record the timeline of events, actions taken, and evidence collected. Which of the following is the PRIMARY purpose of maintaining proper documentation during incident response?

Easy
16

A healthcare provider's incident response team is handling a suspected ransomware incident on a clinical workstation. The team lead wants to determine whether the incident should be escalated to a full response or handled as a false positive. According to NIST SP 800-61, which activity is part of the detection and analysis phase?

Hard
17

An incident responder is collecting evidence from a compromised Linux server. The responder uses the 'dd' command to create an image of the hard drive. Which of the following is the PRIMARY reason for using a write blocker during this process?

Medium
18

A forensic investigator is collecting evidence from a compromised Windows server. According to the order of volatility, which THREE pieces of evidence should be collected FIRST? (Select THREE)

Hard
19

During a post-incident review, the incident response team identifies several areas for improvement. According to NIST SP 800-61, which THREE activities are typically part of the post-incident activity phase?

Hard
20

Which of the following is the primary purpose of a chain of custody form in digital forensics?

Easy
21

During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) was 14 days. Which improvement would most directly reduce MTTD?

Hard
22

After a security incident, an organization's legal team requests documentation that shows who had possession of a hard drive at every point from seizure to analysis. Which document should the incident responder provide?

Easy
23

During which phase of the NIST SP 800-61 incident response lifecycle are lessons learned meetings conducted and metrics such as MTTD and MTTR tracked?

Easy
24

A company is conducting a disaster recovery test. Which TWO types of tests involve minimal risk to production operations?

Medium
25

An organization is developing its incident response plan. According to NIST SP 800-61, which phase should include establishing a communication plan, acquiring necessary tools, and conducting exercises?

Easy
26

What is the primary purpose of establishing a chain of custody for digital evidence?

Easy
27

Which type of disaster recovery test involves running the DR systems alongside the production systems to validate functionality without impacting live operations?

Medium
28

During the eradication phase of a malware incident, a security analyst removes malicious files and cleans registry persistence. What is the MOST critical additional step to prevent reinfection through the same vector?

Hard
29

A security analyst is responding to a malware incident on a Windows server. Which TWO actions should be taken to properly collect volatile evidence?

Medium
30

After a security incident, the incident response team holds a lessons learned meeting. What is the PRIMARY outcome of this meeting?

Medium
31

Which DR testing type involves running recovery systems in parallel with production systems to verify functionality without impacting live operations?

Easy
32

An incident responder is collecting evidence from a compromised server. Which of the following is the correct order for collecting volatile data?

Medium
33

An analyst detects suspicious outbound traffic from a workstation to a known command-and-control IP. Which IoC blocking method is MOST appropriate as an immediate containment measure?

Medium
34

An incident responder is analyzing a network packet capture to determine the scope of a data exfiltration incident. The responder notices a large volume of outbound traffic to an unfamiliar IP address over port 443. Which of the following should the responder do FIRST to determine if the traffic is malicious?

Hard
35

During a malware containment operation, the incident response team decides to isolate an infected endpoint using network access controls. However, the malware is spreading via removable media. Which additional containment measure should the team implement?

Hard
36

Which of the following is the PRIMARY purpose of establishing a chain of custody when handling digital evidence?

Medium
37

An organization's incident response team has just completed the recovery phase of a major security incident. The team lead is now planning the post-incident activity. According to NIST SP 800-61, which of the following should be the PRIMARY focus of the lessons learned meeting?

Medium
38

Which metric is used to measure the average time it takes to detect an incident?

Easy
39

An incident responder is preparing to acquire volatile data from a compromised Linux server that is still powered on. The server hosts a critical database and cannot be shut down yet. According to order of volatility, which data source should the responder collect FIRST?

Hard
40

An incident responder is collecting volatile evidence from a compromised Linux server. Which TWO of the following should be collected first? (Select two.)

Medium
41

After a security incident, the response team holds a lessons learned meeting. Which TWO are primary objectives of this meeting? (Select two.)

Medium
42

An organization is restoring a critical database from a backup after a ransomware attack. Which of the following steps should be performed BEFORE restoring the data to ensure the restoration is successful and secure?

Hard
43

An incident responder is investigating a compromised Linux server and needs to collect volatile data. The responder has root access and wants to ensure that the data collected is admissible in a court of law. Which of the following commands should be used FIRST to capture the contents of physical memory?

Hard
44

During incident response, a team needs to isolate an infected workstation that is part of a critical manufacturing network. Which containment method is MOST appropriate to minimize disruption while preventing the spread of malware?

Medium
45

A security analyst is reviewing the organization's disaster recovery plan and notices that the Recovery Time Objective (RTO) for a critical application is 2 hours, but the current recovery process takes 8 hours. Which of the following should the analyst recommend FIRST?

Medium
46

A security team is conducting a lessons learned meeting after a major security incident. The team identifies that the incident response plan was not followed because team members were unsure of their roles. Which of the following should be the PRIMARY outcome of this meeting to address the issue?

Medium
47

A financial services firm has just contained a ransomware incident on a file server. The incident response plan requires a formal post-incident activity phase. The CISO wants to know what the team should do FIRST to improve future response. Which action best aligns with NIST SP 800-61 post-incident activity?

Medium
48

A financial services firm's incident response team has just contained a malware outbreak on a file server. The server contains regulated customer data. The team lead instructs the responder to capture the current state of the system before any remediation. According to NIST SP 800-61, which action should the responder take FIRST to preserve the most volatile evidence?

Medium
49

During a post-incident review of a data breach, the incident response team is evaluating the chain of custody for forensic evidence. Which THREE practices demonstrate proper evidence handling? (Choose three.)

Hard
50

What is the PRIMARY purpose of a lessons learned meeting after an incident?

Easy
51

A security analyst receives an alert from the SIEM about a possible malware infection on a workstation. The analyst confirms the infection and begins containment. Which of the following actions BEST aligns with the containment phase of the NIST SP 800-61 incident response lifecycle?

Medium
52

During a malware outbreak, a security analyst needs to contain the spread. The affected systems are on the same VLAN as critical servers. Which of the following containment actions should be performed FIRST to minimize impact?

Hard
53

A security incident response team is reviewing their disaster recovery plan. They need to ensure that their backup strategy supports recovery from a ransomware attack that encrypts critical files. Which TWO of the following are essential characteristics of an effective backup strategy for this scenario? (Choose two.)

Medium
54

During which phase of the NIST SP 800-61 incident response lifecycle are incident response plan updates and lessons learned typically documented?

Easy
55

An organization has experienced a ransomware attack. After containing the incident, the response team plans to restore systems from backups. Which step is most critical before restoring production systems?

Medium
56

An organization's disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for its critical database. Which of the following DR site configurations BEST meets these requirements?

Medium
57

During the containment phase of incident response, a security analyst identifies malware on a critical server. Which TWO actions should be taken FIRST to contain the threat and preserve evidence? (Choose two.)

Easy
58

A security analyst receives a user report about a workstation exhibiting unusual behavior, such as unexpected pop-ups and slow performance. The analyst first checks the antivirus logs and finds no alerts. What is the NEXT step in the detection and analysis phase?

Medium
59

During a full interruption test of the disaster recovery plan, which of the following is the PRIMARY risk?

Medium
60

A security analyst detects a workstation communicating with a known command-and-control server. The workstation is running critical applications. What should be the analyst's first step according to the NIST incident response lifecycle?

Medium
61

A security analyst receives an alert from the EDR system indicating that a workstation has been communicating with a known malicious IP address. The analyst confirms the alert and notes that the user is still logged in. Which immediate containment action should the analyst take FIRST?

Medium
62

An organization's disaster recovery plan specifies an RPO of 4 hours and an RTO of 24 hours for a critical database. Which of the following best describes these metrics?

Medium
63

A security analyst is investigating a phishing incident that led to credential theft. Which TWO actions are appropriate during the containment phase? (Select TWO)

Medium
64

A security analyst is reviewing alerts and sees that a user's workstation has begun encrypting files with a new extension, and a ransom note has appeared on the desktop. The analyst confirms this is an active ransomware infection. According to NIST SP 800-61, which action should the analyst take FIRST during the containment phase?

Medium
65

An organization has suffered a ransomware attack that encrypted files on several file servers. The incident response team is planning recovery. Which TWO actions should be performed to verify that the restored systems are clean before returning them to production? (Select TWO)

Medium
66

A healthcare organization's incident response team has just contained a ransomware outbreak that encrypted several file servers. Before restoring from backups, the incident response manager wants to ensure that the team can determine exactly how the attacker initially gained access and what data was exfiltrated. The organization does not have a dedicated forensic imaging solution, but the servers are still powered on and running. Which of the following actions BEST supports the investigation while preserving evidence?

Medium
67

During a forensic investigation, an examiner creates a bit-for-bit copy of a hard drive using a write blocker. What is the purpose of using a write blocker?

Medium
68

An analyst detects suspicious outbound traffic from a server to a known command-and-control IP address. According to NIST SP 800-61, which phase of the incident response lifecycle does this activity fall under?

Medium
69

Which TWO metrics are commonly tracked to measure the effectiveness of the incident response process? (Select TWO)

Easy
70

During the preparation phase of incident response, which TWO components are essential for an effective incident response plan? (Select TWO)

Medium
71

During the preparation phase of the incident response lifecycle, which of the following is the MOST important component to establish?

Easy
72

A security analyst is reviewing the organization's incident response plan and wants to ensure it includes the necessary elements for the preparation phase according to NIST SP 800-61. Which of the following should be included in the preparation phase? (Choose two.)

Medium
73

An incident response team is preparing to collect evidence from a compromised Linux web server. The team lead wants to ensure that the evidence will be admissible in a potential legal proceeding. Which TWO actions should the team take to maintain the integrity of the evidence? (Choose two.)

Medium
74

A security analyst is reviewing the incident response plan and wants to ensure the containment strategy is effective for a recent malware outbreak. The analyst must choose containment measures that align with NIST SP 800-61. Which TWO actions are appropriate containment strategies? (Choose two.)

Medium
75

After a major security incident, an organization's incident response team conducts a lessons learned meeting. The team identifies that the communication plan was unclear, leading to delays in notifying stakeholders. Which of the following should be the PRIMARY outcome of this meeting?

Easy
76

An incident responder needs to create a forensic image of a suspect hard drive. Which of the following steps is ESSENTIAL to ensure the integrity of the evidence?

Medium
77

Which type of disaster recovery test involves running the DR systems alongside production systems to verify functionality without impacting operations?

Easy
78

A security analyst receives a chain of custody form for a hard drive that was seized from a suspected insider threat. The form shows that the drive was handled by three individuals over two days. Which of the following is the PRIMARY reason for maintaining a chain of custody?

Hard
79

A security team detects lateral movement within the network. Which containment strategy should be applied first to limit the spread of the threat?

Medium
80

A multinational corporation has a disaster recovery plan with a Recovery Time Objective (RTO) of 2 hours for its customer-facing e-commerce platform. During a regional power outage, the primary data center goes offline. The DR team activates the hot site, but the database replication lag causes the e-commerce platform to come online after 5 hours. Which of the following should the incident response team do FIRST after restoring services?

Hard
81

After a major security incident, an organization conducts a lessons learned meeting. Which of the following is the PRIMARY purpose of this meeting?

Easy
82

During a ransomware incident, the incident response team needs to recover encrypted servers. Which THREE steps are essential for successful recovery? (Select THREE)

Hard
83

A security team is collecting evidence from a compromised server. They need to create a forensic image. Which of the following is the CORRECT procedure to ensure data integrity?

Medium

Frequently asked questions

What does the Incident Response and Recovery domain cover on the SSCP exam?
Be able to sequence incident response phases correctly and pick the right containment action first. The single most important thing: contain the threat before eradicating or recovering, while preserving evidence and following the IR plan.
How many questions are in this domain?
This page lists all 83 Incident Response and Recovery questions in the SSCP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Incident Response and Recovery questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-sscp ISC2-SSCP sscp incident response Practice Questions