Courseiva

SSCP Incident Response and Recovery Practice Question

During a post-incident review, the incident response team identifies several areas for improvement. According to NIST SP 800-61, which THREE activities are typically part of the post-incident activity phase?

⚠ Common exam trap

It's easy for candidates to confuse operational recovery actions (like patching or hardware replacement) with the analytical and improvement-focused activities that define the post-incident phase per NIST SP 800-61.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the incident response plan based on findings

Option B is correct because NIST SP 800-61's post-incident activity phase explicitly includes using the lessons learned and review findings to update the incident response plan, policies, and procedures so future responses improve. Option D is correct because holding a lessons learned meeting (post-incident review) with all involved parties is a core recommended activity in this phase, used to identify what happened, what was done well, and what needs improvement. Option E is correct because NIST SP 800-61 calls for using incident data to develop and track metrics, such as mean time to detect (MTTD) and mean time to recover/repair (MTTR), to measure and improve the incident response capability over time. Option A is not part of the post-incident activity phase; patching is a remediation/eradication action performed during incident handling, not a blanket post-incident review activity. Option C is likewise incorrect because immediately replacing all affected hardware is a recovery/remediation decision made during the handling phase based on the specific incident, not a standard post-incident review activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Patch all systems in the organization as a precaution

    Why it's wrong here

    Organisation-wide precautionary patching is vulnerability management, not a NIST SP 800-61 post-incident activity, which covers lessons learned, evidence retention and using collected data to improve future response. It is tempting because patching prevents recurrence, and would be correct if the question asked how to remediate the exploited vulnerability during eradication.

  • ✓

    Update the incident response plan based on findings

    Why this is correct

    NIST SP 800-61 places revising the incident response plan within post-incident activity, so lessons identified during review feed back into procedures, contact lists, and controls. This closes the improvement loop and better prepares the team for subsequent incidents.

  • ✗

    Replace all affected hardware immediately

    Why it's wrong here

    Hardware replacement is a containment and recovery action performed during incident handling, not a post-incident activity, which NIST SP 800-61 defines as lessons learned, evidence retention and reporting. It is tempting because remediation feels like closure, and would be correct if the question asked about eradicating persistent compromise during the recovery phase.

  • ✓

    Conduct a lessons learned meeting

    Why this is correct

    The lessons learned meeting is a core post-incident activity in NIST SP 800-61, convening responders and stakeholders to examine what occurred, what worked, and what failed. Findings from this discussion drive updates to the plan and future response effectiveness.

  • ✓

    Track metrics such as MTTD and MTTR

    Why this is correct

    Tracking metrics such as mean time to detect and mean time to repair belongs to the post-incident activity phase, where NIST SP 800-61 directs teams to use incident data to improve future response. Measuring these figures satisfies the stem's requirement to identify improvement areas, since trends expose weaknesses in detection and containment.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.