Courseiva
Incident Response and RecoverymediumMultiple ChoiceObjective-mapped

SSCP Incident Response and Recovery Practice Question

During the eradication phase of incident response, which of the following actions is MOST critical to ensure the threat is completely removed from a compromised system?

⚠ Common exam trap

A common mistake in the SSCP exam is confusing the eradication phase with the recovery phase. Candidates may select patching or reimaging because those actions seem thorough, but the key during eradication is removing all artifacts of the compromise, including persistence mechanisms, before recovering the system to production.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Removing malicious files and cleaning registry persistence

During the eradication phase, the primary goal is to ensure that no remnants of the attacker's presence remain on the system. Option C directly addresses this by removing malicious files and cleaning registry persistence, which eliminates backdoors, scheduled tasks, and other persistence mechanisms that could allow the threat to survive a reboot or evade detection. Without this step, even after patching or credential resets, the attacker could regain access through hidden persistence points.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Reimaging the system from a verified clean image

    Why it's wrong here

    Reimaging is an effective eradication method, but if a clean image is available, it's a valid step; however, cleaning persistence is more critical in a non-reimage scenario. The question asks for the MOST critical, and cleaning persistence is fundamental.

  • Resetting compromised user credentials

    Why it's wrong here

    Resetting credentials is important but does not remove malware already on the system.

  • Removing malicious files and cleaning registry persistence

    Why this is correct

    Attackers often establish persistence; failing to remove it can lead to recompromise.

  • Patching the exploited vulnerability

    Why it's wrong here

    Patching prevents re-exploitation but does not remove existing malware.

About these practice questions

Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.