Courseiva

CCNA Incident Response and Recovery Questions

8 of 83 questions · Page 2/2 · Incident Response and Recovery · Answers revealed

76
MCQmedium

An incident responder needs to create a forensic image of a suspect hard drive. Which of the following steps is ESSENTIAL to ensure the integrity of the evidence?

A.Run an antivirus scan on the drive before imaging
B.Use a write blocker to prevent modification of the original drive
C.Boot the suspect system to verify it is functional
D.Perform the imaging over the network to save time
AnswerB

A hardware write blocker intercepts write commands at the interface level, allowing reads while preventing any modification to the suspect drive. This preserves the original evidence's integrity, ensuring the forensic image is an admissible, verifiable copy.

Why this answer

Using a write blocker is essential because it ensures that no data can be written to the suspect hard drive during the imaging process, preserving the original evidence in a forensically sound state. Without a write blocker, any operating system or imaging tool could inadvertently modify metadata (e.g., access timestamps) or the file system, which would compromise the integrity and admissibility of the evidence in legal proceedings.

Exam trap

A common trap in SSCP is the misconception that booting the system or running software-based checks is acceptable. However, any interaction with the original drive that could alter its state—even a read-only mount without a write blocker—can change metadata and break the chain of custody.

How to eliminate wrong answers

Option A is wrong because running an antivirus scan on the drive before imaging could modify the drive's contents (e.g., by quarantining or deleting files), which violates forensic integrity principles. Option C is wrong because booting the suspect system can alter the system state, including writing to the drive (e.g., log files, temporary files), and may trigger anti-forensic mechanisms. Option D is wrong because performing imaging over the network introduces risks of data corruption, packet loss, or interception, and does not inherently prevent writes to the original drive; a write blocker is still required for forensic soundness.

77
MCQeasy

Which type of disaster recovery test involves running the DR systems alongside production systems to verify functionality without impacting operations?

A.Tabletop exercise
B.Full interruption test
C.Parallel test
D.Simulation test
AnswerC

A parallel test runs DR systems concurrently with production, processing transactions or workloads in isolation, so functionality is verified without disrupting live operations. This matches the stem's constraint of validating DR capability while leaving production systems unaffected.

Why this answer

A parallel test runs the disaster recovery (DR) systems in a live, non-disruptive manner alongside the production environment. This allows the organization to validate that the DR systems can process transactions and handle workloads correctly without affecting the primary production operations, making it the correct choice for verifying functionality without impact.

Exam trap

The trap here is that candidates often confuse a parallel test with a simulation test, thinking both are 'non-disruptive,' but a simulation test does not run DR systems alongside production and typically uses synthetic data, whereas a parallel test uses real production data and systems in a concurrent, non-interfering manner.

How to eliminate wrong answers

Option A is wrong because a tabletop exercise is a discussion-based walkthrough of roles and procedures, not an actual technical test of DR systems running alongside production. Option B is wrong because a full interruption test (also called a full-scale or hot start test) involves shutting down production systems and failing over to the DR site, which directly impacts operations. Option D is wrong because a simulation test mimics a disaster scenario in a controlled environment but does not run DR systems concurrently with production systems; it often uses isolated test beds.

78
MCQhard

A security analyst receives a chain of custody form for a hard drive that was seized from a suspected insider threat. The form shows that the drive was handled by three individuals over two days. Which of the following is the PRIMARY reason for maintaining a chain of custody?

A.To prove that the evidence has not been tampered with and is admissible in legal proceedings
B.To determine the cost of the forensic investigation
C.To ensure the hard drive is stored in a secure location
D.To track the productivity of forensic analysts
AnswerA

The chain of custody documents every person who handled the drive and when, proving the evidence remained unaltered since seizure. This continuity is what allows the drive to be admitted in legal proceedings against the insider threat suspect.

Why this answer

The chain of custody is a documented chronological record of evidence handling, which is essential to demonstrate that the hard drive has not been altered, damaged, or substituted since seizure. Without this unbroken record, the evidence could be challenged as inadmissible in court under rules like the Federal Rules of Evidence (FRE) 901, which require authentication. This is the primary reason because legal admissibility hinges on proving integrity and continuity of custody.

Exam trap

(ISC)² often tests the distinction between the legal necessity of chain of custody (admissibility) versus operational tasks like storage or cost tracking, leading candidates to confuse a supporting activity (secure storage) with the primary purpose.

How to eliminate wrong answers

Option B is wrong because determining the cost of the forensic investigation is an administrative or budgeting concern, not the primary legal purpose of chain of custody. Option C is wrong because while secure storage is a component of proper evidence handling, the chain of custody specifically documents who had access and when, not just the storage location itself. Option D is wrong because tracking analyst productivity is a management metric unrelated to the forensic integrity and legal admissibility requirements that chain of custody is designed to satisfy.

79
MCQmedium

A security team detects lateral movement within the network. Which containment strategy should be applied first to limit the spread of the threat?

A.Disable user accounts associated with compromised systems.
B.Isolate the affected systems by disconnecting them from the network.
C.Block the attacker's IP addresses at the perimeter firewall.
D.Reimage all compromised systems immediately.
AnswerB

Disconnecting affected systems from the network immediately severs the attacker's command-and-control and lateral movement channels, satisfying the requirement to limit spread first. Isolation precedes eradication or credential resets because every minute of connectivity lets the adversary pivot to additional hosts.

Why this answer

Isolating affected systems by disconnecting them from the network is the immediate priority because it physically or logically severs the attacker's ability to propagate laterally via SMB, RDP, or other network protocols. This containment step stops the spread without destroying forensic evidence, which would be lost if systems were reimaged or powered off prematurely.

Exam trap

ISC2 often tests the misconception that blocking external IPs or disabling accounts is sufficient for containment, when in fact internal lateral movement requires immediate network-level isolation of the compromised host.

How to eliminate wrong answers

Option A is wrong because disabling user accounts does not stop an attacker who has already established remote access via a service account, kernel-level backdoor, or cached credentials; the compromised system remains on the network and can still be used for lateral movement. Option C is wrong because blocking IP addresses at the perimeter firewall is ineffective against internal lateral movement, which occurs on the LAN and does not traverse the perimeter; the attacker can also easily change IP addresses or use internal routing to bypass the block. Option D is wrong because reimaging destroys volatile evidence (e.g., memory dumps, active network connections) and takes too long, allowing the attacker to continue spreading while the system is being rebuilt; containment must precede eradication.

80
MCQhard

A multinational corporation has a disaster recovery plan with a Recovery Time Objective (RTO) of 2 hours for its customer-facing e-commerce platform. During a regional power outage, the primary data center goes offline. The DR team activates the hot site, but the database replication lag causes the e-commerce platform to come online after 5 hours. Which of the following should the incident response team do FIRST after restoring services?

A.Immediately fail back to the primary data center without testing.
B.Terminate the DR team lead for failing to meet the RTO.
C.Update the DR plan to reflect the actual recovery time achieved.
D.Conduct a root cause analysis of the replication lag and RTO miss.
AnswerD

After restoring services, the team should investigate why the hot site failed to meet the 2-hour RTO, focusing on database replication lag. A root cause analysis identifies whether the lag was due to bandwidth, configuration, or capacity issues, enabling corrective actions. This aligns with post-incident activity and ensures the DR capability is improved for future outages.

Why this answer

After restoring services, the incident response team should perform a root cause analysis to understand why the hot site did not meet the 2-hour RTO. The replication lag is a technical issue that must be diagnosed and corrected to improve DR readiness. Punitive actions, plan normalization, or untested failback do not address the underlying cause and could worsen future outcomes.

Exam trap

The trap here is focusing on restoring services or updating documentation, when the critical next step is to analyze why the RTO was missed and fix the root cause.

81
MCQeasy

After a major security incident, an organization conducts a lessons learned meeting. Which of the following is the PRIMARY purpose of this meeting?

A.To identify improvements to the incident response process.
B.To calculate the financial cost of the incident.
C.To inform the public about the incident details.
D.To determine which team members should be disciplined.
AnswerA

The lessons learned meeting is held to review the incident and identify what went well and what could be improved. The primary outcome is to update policies, procedures, and training based on the findings. This helps the organization respond more effectively to future incidents. It is not about assigning blame or punishing individuals.

Why this answer

The lessons learned meeting is a post-incident review aimed at improving the incident response process. It brings together the response team to discuss what happened, what worked, and what didn't, with the goal of updating procedures, training, and tools. It is not about punishment, cost calculation, or public disclosure, although those may be separate follow-up activities.

Exam trap

The trap here is thinking the meeting is for assigning blame or calculating costs, but its core purpose is process improvement.

82
Multi-Selecthard

During a ransomware incident, the incident response team needs to recover encrypted servers. Which THREE steps are essential for successful recovery? (Select THREE)

Select 3 answers
A.Restore data from the most recent clean backup
B.Pay the ransom to obtain the decryption key
C.Patch the vulnerability that allowed the ransomware to enter
D.Delete all user accounts and recreate them
E.Scan restored systems to ensure eradication of malware
AnswersA, C, E

Ransomware encrypts data in place, so recovery depends on restoring from a backup taken before infection. Selecting the most recent clean copy minimises data loss while ensuring the restored files are free of the encryption payload, directly satisfying the recovery objective.

Why this answer

Option A is correct because restoring from the most recent clean backup is the primary and most reliable way to recover encrypted data without trusting the attacker or paying the ransom. Option C is correct because patching the vulnerability that allowed the ransomware to enter prevents immediate re-infection once systems are restored and brought back online. Option E is correct because scanning restored systems verifies that malware has been eradicated and that no residual persistence mechanisms or reinfection vectors remain before returning them to production.

Option B is not appropriate because paying the ransom does not guarantee a working decryption key, funds criminal activity, and may violate organizational or legal policy. Option D is not an essential recovery step because deleting and recreating all user accounts does not address the encrypted data or the malware itself and could cause unnecessary operational disruption.

Exam trap

The SSCP exam often tests the misconception that paying the ransom is a valid recovery step, but it emphasizes that payment should never be recommended due to lack of guarantee and ethical concerns.

83
MCQmedium

A security team is collecting evidence from a compromised server. They need to create a forensic image. Which of the following is the CORRECT procedure to ensure data integrity?

A.Use a write blocker to create a bit-for-bit copy, then compute MD5 hash of the original and the copy to verify they match
B.Take a photo of the screen and document file timestamps manually
C.Create a compressed image file using software without a write blocker
D.Boot the system and run a backup utility to copy files to an external drive
AnswerA

A write blocker prevents any modification to the source drive during imaging, preserving evidential integrity. Hashing both the original and the bit-for-bit copy with MD5 confirms they are identical, satisfying the requirement to verify integrity.

Why this answer

Forensic imaging requires a write blocker to prevent any modification to the original evidence, and a bit-for-bit copy preserves all data, including slack space and deleted files. Computing an MD5 hash of both the original and the copy verifies integrity by ensuring the hashes match, confirming no data alteration occurred during acquisition.

Exam trap

The trap here is that candidates may think a simple backup or file copy is sufficient for forensic evidence, but the SSCP exam emphasizes that only a write-blocked bit-for-bit copy with hash verification ensures data integrity and admissibility.

How to eliminate wrong answers

Option B is wrong because taking a photo and manually documenting timestamps does not create a forensic image; it only captures superficial information and fails to preserve the full data for analysis. Option C is wrong because creating a compressed image without a write blocker risks altering the original drive's data due to write operations, compromising evidence integrity. Option D is wrong because booting the system and running a backup utility modifies the system state (e.g., writes to swap, logs, or file access times) and does not produce a bit-for-bit copy, violating forensic best practices.

← PreviousPage 2 of 2 · 83 questions total

Ready to test yourself?

Try a timed practice session using only Incident Response and Recovery questions.