Courseiva

SSCP Incident Response and Recovery Practice Question

During the detection and analysis phase, an analyst receives a user report of unusual system behavior. The analyst reviews logs and finds several failed login attempts followed by a successful login from an unusual IP address. What is the next step?

⚠ Common exam trap

Test-takers frequently confuse the detection and analysis phase with the containment phase in the SSCP incident response lifecycle, leading them to choose immediate disconnection (Option A) instead of first classifying the incident and determining the need for escalation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Classify the incident and determine if escalation is needed.

During the detection and analysis phase of incident response, the primary goal is to assess the validity and scope of a potential security event before taking action. The analyst has observed indicators of a possible brute-force attack (failed logins followed by a successful login from an unusual IP), which requires classification to determine if it meets the criteria for a security incident. Escalation may be needed to involve a higher-tier incident response team or to initiate formal containment procedures, as per NIST SP 800-61 guidelines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately disconnect the user's workstation from the network.

    Why it's wrong here

    Disconnecting the workstation isolates one endpoint while the compromised account remains active, so the attacker retains access through other channels. It is tempting because endpoint isolation is a fast containment action, and it is correct once the compromised credential has been disabled or reset.

  • ✗

    Rebuild the user's workstation from a known-good image.

    Why it's wrong here

    Rebuilding the workstation destroys volatile evidence such as memory-resident malware and active sessions before containment and forensic analysis are complete. It is tempting because reimaging reliably removes persistence, making it the right step once the incident is confirmed, scoped and evidence has been preserved.

  • ✓

    Classify the incident and determine if escalation is needed.

    Why this is correct

    Failed logins followed by a success from an unusual IP indicate probable compromise, so the analyst must classify the incident and decide whether escalation is warranted. Classification determines severity and the appropriate response path within detection and analysis.

  • ✗

    Ignore the event as it may be a false positive.

    Why it's wrong here

    Dismissing the event discards evidence of a probable credential compromise; the failed-then-successful login pattern from an unusual IP warrants escalation and containment, not closure. False-positive triage applies after validation, and this indicator is too specific to wave through without investigation.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.