SSCP Incident Response and Recovery Practice Question
During the eradication phase of incident response, which of the following actions is MOST critical to ensure the threat is completely removed from a compromised system?
⚠ Common exam trap
A common mistake in the SSCP exam is confusing the eradication phase with the recovery phase. Candidates may select patching or reimaging because those actions seem thorough, but the key during eradication is removing all artifacts of the compromise, including persistence mechanisms, before recovering the system to production.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Removing malicious files and cleaning registry persistence
During the eradication phase, the primary goal is to ensure that no remnants of the attacker's presence remain on the system. Option C directly addresses this by removing malicious files and cleaning registry persistence, which eliminates backdoors, scheduled tasks, and other persistence mechanisms that could allow the threat to survive a reboot or evade detection. Without this step, even after patching or credential resets, the attacker could regain access through hidden persistence points.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reimaging the system from a verified clean image
Why it's wrong here
Reimaging is an effective eradication method, but if a clean image is available, it's a valid step; however, cleaning persistence is more critical in a non-reimage scenario. The question asks for the MOST critical, and cleaning persistence is fundamental.
- ✗
Resetting compromised user credentials
Why it's wrong here
Resetting credentials is important but does not remove malware already on the system.
- ✓
Removing malicious files and cleaning registry persistence
Why this is correct
Attackers often establish persistence; failing to remove it can lead to recompromise.
- ✗
Patching the exploited vulnerability
Why it's wrong here
Patching prevents re-exploitation but does not remove existing malware.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.