Courseiva

CCNA Sscp Incident Response Questions

75 of 83 questions · Page 1/2 · Sscp Incident Response topic · Answers revealed

1
MCQmedium

An incident responder needs to create a forensic image of a suspect hard drive. What is the correct procedure to ensure evidence integrity?

A.Use a write blocker, create a bit-for-bit image, and compute SHA-256 hash before and after imaging.
B.Boot the suspect system and use imaging software to copy data.
C.Remove the drive and place it in anti-static bag, then ship to lab.
D.Connect the drive directly to forensic workstation, copy all files, and compute MD5 hash of copy.
AnswerA

A write blocker prevents any modification to the source drive, bit-for-bit imaging captures an exact replica including slack space, and SHA-256 hashes computed before and after verify the image matches the original, satisfying the evidence-integrity requirement.

Why this answer

Forensic imaging requires a write blocker to prevent any modification to the original evidence, a bit-for-bit (sector-level) copy to capture all data including slack space and deleted files, and cryptographic hashing (SHA-256) both before and after imaging to verify that the image is an exact, unaltered duplicate of the source. This process ensures the integrity and admissibility of digital evidence in legal proceedings.

Exam trap

The trap here is that candidates may think booting the system or simply copying files is sufficient, but the SSCP exam emphasizes that any write activity to the original evidence breaks the chain of custody and invalidates the forensic integrity.

How to eliminate wrong answers

Option B is wrong because booting the suspect system alters the system state (e.g., writes temporary files, updates logs, changes timestamps), which modifies evidence and violates forensic best practices. Option C is wrong because simply placing the drive in an anti-static bag and shipping it does not create a forensic image; imaging must be performed to preserve the data, and the procedure omits write-blocking and hashing. Option D is wrong because connecting the drive directly without a write blocker risks accidental writes to the source, and copying files (rather than creating a bit-for-bit image) loses metadata, slack space, and deleted data; MD5 is also less collision-resistant than SHA-256 for modern forensic standards.

2
MCQhard

A financial services firm's incident response plan defines a Recovery Time Objective (RTO) of 2 hours for its online trading platform. During a tabletop exercise, the team discovers that the current disaster recovery runbook requires manual steps that take approximately 6 hours to complete. The Chief Information Security Officer (CISO) asks for a recommendation to align the recovery capability with the RTO without increasing the budget significantly. Which of the following is the MOST appropriate recommendation?

A.Outsource the entire recovery process to a managed security service provider (MSSP) with a 2-hour SLA.
B.Increase the RTO to 6 hours to match the current manual recovery process.
C.Automate the manual steps using existing orchestration tools and scripts to reduce recovery time.
D.Implement a hot site with real-time replication, which will guarantee a 2-hour recovery.
AnswerC

Automating manual steps with existing orchestration tools can significantly reduce recovery time without major new spending. Many organizations already have configuration management or scripting platforms that can be leveraged to streamline failover and recovery. This approach directly addresses the gap between the 6-hour manual process and the 2-hour RTO. It also reduces human error and improves consistency, making it the most appropriate recommendation given the budget constraint.

Why this answer

Automating manual recovery steps using existing orchestration tools is the most cost-effective way to reduce recovery time and meet the 2-hour RTO. It leverages current investments, minimizes new spending, and directly targets the delay. Increasing the RTO ignores business needs, while hot site or MSSP options likely exceed the budget and may not fully resolve the manual process bottleneck.

Exam trap

The trap here is assuming that achieving a lower RTO always requires expensive new infrastructure, when automation of existing manual steps can often close the gap within budget.

3
Multi-Selectmedium

After a ransomware incident, the incident response team is conducting recovery. Which THREE steps are essential to ensure a secure restoration and prevent reinfection? (Choose three.)

Select 3 answers
A.Restore from the most recent backup available, regardless of its integrity.
B.Reconnect the system to the network immediately after restoration to test functionality.
C.Perform a full system scan with updated antivirus on the restored system.
D.Remove persistence mechanisms from the registry and startup folders.
E.Patch the vulnerability that was exploited in the initial compromise.
AnswersC, D, E

Scanning the restored system with current antivirus signatures detects any residual malware or dormant payloads that survived restoration, satisfying the requirement to prevent reinfection. Because ransomware often leaves droppers or secondary implants, this verification step confirms the restored host is genuinely clean before returning it to production.

Why this answer

Option C is correct because after restoring data or a system image, a full scan with up-to-date antivirus signatures is needed to detect any residual malware that may have been present in the backup or reintroduced during restoration, preventing reinfection. Option D is correct because ransomware and other malware often establish persistence via Run/RunOnce registry keys, services, scheduled tasks, and Startup folders; these must be identified and removed so the threat cannot re-execute after reboot. Option E is correct because the initial compromise vector—such as an unpatched SMB, RDP, or VPN vulnerability—must be remediated; otherwise the same exploit can be used again to reinfect the restored system.

Option A is not appropriate because restoring from a backup without verifying its integrity risks reintroducing corrupted or already-infected data. Option B is not appropriate because reconnecting to the network immediately after restoration, before scanning, patching, and removing persistence, exposes the system to reinfection and lateral movement.

Exam trap

SSCP often tests the misconception that the most recent backup is always the safest choice, but the trap here is that integrity and cleanliness of the backup are more important than recency, and candidates may overlook the need to remove persistence mechanisms before reconnecting to the network.

4
MCQhard

A security analyst is reviewing a disaster recovery plan and notes that the organization has a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 2 hours for a critical database. Which of the following backup strategies BEST meets these objectives?

A.Continuous data protection (CDP) with asynchronous replication to a hot site.
B.Hourly incremental backups to a local NAS with nightly replication to a warm site.
C.Daily full backups with weekly tape rotation stored offsite.
D.Weekly full backups with daily differential backups stored in the cloud.
AnswerA

CDP captures every change and can provide an RPO of near zero, easily meeting the 15-minute requirement. Asynchronous replication to a hot site allows for rapid recovery, often within minutes, satisfying the 2-hour RTO. This combination ensures minimal data loss and quick restoration, aligning with the critical database's needs.

Why this answer

The RPO of 15 minutes requires that no more than 15 minutes of data can be lost, necessitating continuous or near-continuous backup. The RTO of 2 hours demands rapid recovery, which a hot site with asynchronous replication can provide. Continuous data protection combined with a hot site meets both objectives by minimizing data loss and downtime.

Exam trap

The trap here is assuming that hourly backups meet a 15-minute RPO or that a warm site can recover within 2 hours.

5
MCQmedium

A company is developing a DR plan for a critical database. The maximum acceptable downtime is 2 hours, and the maximum data loss is 1 hour. What are the RTO and RPO?

A.RTO = 2 hours, RPO = 1 hour
B.RTO = 1 hour, RPO = 1 hour
C.RTO = 1 hour, RPO = 2 hours
D.RTO = 2 hours, RPO = 2 hours
AnswerA

RTO defines the maximum tolerable downtime, so 2 hours maps directly to RTO. RPO defines the maximum tolerable data loss measured in time, so 1 hour maps to RPO. The option matches both stated constraints exactly.

Why this answer

The Recovery Time Objective (RTO) is the maximum acceptable downtime, which is 2 hours. The Recovery Point Objective (RPO) is the maximum acceptable data loss, which is 1 hour. Therefore, option A correctly identifies RTO = 2 hours and RPO = 1 hour.

Exam trap

The trap here is confusing RTO (time to recover) with RPO (data loss tolerance), leading candidates to swap the two values or assume they must be equal.

How to eliminate wrong answers

Option B is wrong because it swaps the RTO and RPO values, incorrectly setting RTO to 1 hour (the maximum data loss) and RPO to 1 hour (the maximum downtime). Option C is wrong because it inverts the definitions, setting RTO to 1 hour (data loss) and RPO to 2 hours (downtime). Option D is wrong because it sets both RTO and RPO to 2 hours, ignoring the specified 1-hour maximum data loss constraint.

6
MCQmedium

During the detection and analysis phase, an analyst receives a user report of unusual system behavior. The analyst reviews logs and finds several failed login attempts followed by a successful login from an unusual IP address. What is the next step?

A.Immediately disconnect the user's workstation from the network.
B.Rebuild the user's workstation from a known-good image.
C.Classify the incident and determine if escalation is needed.
D.Ignore the event as it may be a false positive.
AnswerC

Failed logins followed by a success from an unusual IP indicate probable compromise, so the analyst must classify the incident and decide whether escalation is warranted. Classification determines severity and the appropriate response path within detection and analysis.

Why this answer

During the detection and analysis phase of incident response, the primary goal is to assess the validity and scope of a potential security event before taking action. The analyst has observed indicators of a possible brute-force attack (failed logins followed by a successful login from an unusual IP), which requires classification to determine if it meets the criteria for a security incident. Escalation may be needed to involve a higher-tier incident response team or to initiate formal containment procedures, as per NIST SP 800-61 guidelines.

Exam trap

The trap here is that candidates often confuse the detection and analysis phase with the containment phase in the SSCP incident response lifecycle, leading them to choose immediate disconnection (Option A) instead of first classifying the incident and determining the need for escalation.

How to eliminate wrong answers

Option A is wrong because immediately disconnecting the user's workstation from the network is a premature containment action that should only occur after the incident has been confirmed and classified; doing so could disrupt business operations and destroy volatile evidence (e.g., active network connections, memory contents). Option B is wrong because rebuilding the workstation from a known-good image is a recovery step that occurs after containment, eradication, and evidence preservation; skipping analysis could result in losing forensic data needed to identify the root cause and prevent recurrence. Option D is wrong because ignoring the event as a false positive is negligent; the combination of multiple failed logins followed by a successful login from an unusual IP address is a classic indicator of a successful password-guessing attack and warrants investigation, not dismissal.

7
MCQhard

A forensic examiner is preparing to acquire a disk image from a compromised server. The server is still running and contains critical evidence in volatile memory. According to NIST SP 800-86, which of the following should the examiner do FIRST?

A.Capture the contents of RAM using a memory acquisition tool.
B.Document the system's physical configuration and cable connections.
C.Create a bit-for-bit image of the hard drive.
D.Shut down the server to preserve the disk state.
AnswerA

According to NIST SP 800-86 and the order of volatility, volatile data such as RAM contents should be collected first because it is lost when the system is powered off. Capturing RAM preserves critical evidence like running processes, network connections, and encryption keys. This step must precede disk imaging to ensure that the most perishable evidence is not lost.

Why this answer

The order of volatility in digital forensics dictates that the most perishable evidence, such as RAM and running processes, must be collected first. NIST SP 800-86 emphasizes capturing volatile memory before disk imaging or shutting down the system. This ensures that critical evidence like encryption keys, network connections, and malware artifacts are preserved for analysis.

Exam trap

The trap here is assuming that disk imaging is the first step, but volatile memory is more perishable and must be captured first.

8
MCQhard

A forensic examiner is preparing to acquire a forensic image of a running Linux server that is suspected of being compromised. The server has active network connections and encrypted volumes. Which of the following should the examiner do FIRST according to the order of volatility?

A.Record the current network connections using netstat or ss.
B.Capture the swap partition to preserve encrypted volume keys.
C.Capture the contents of physical memory (RAM) using a tool such as LiME or AVML.
D.Create a bit-for-bit image of the hard drive using dd or a similar tool.
AnswerC

According to the order of volatility, memory (RAM) is more volatile than disk storage and network connections. Capturing RAM first preserves critical evidence such as running processes, network connections, encryption keys, and malware that may only exist in memory. If the system is shut down or the memory is overwritten, this evidence is lost forever. Tools like LiME or AVML allow for memory acquisition on Linux systems while minimizing impact on the running system.

Why this answer

The order of volatility dictates that the most volatile data should be collected first. RAM is more volatile than disk storage and contains critical evidence such as running processes, network connections, and encryption keys. Capturing RAM first with tools like LiME or AVML ensures that this ephemeral data is preserved before it is lost or altered.

Disk imaging, network connection recording, and swap capture are important but should follow memory acquisition to maintain the integrity of the most volatile evidence.

Exam trap

The trap here is assuming that disk imaging or recording network connections should come first, but the order of volatility requires capturing RAM before any disk-based or less volatile sources.

9
Multi-Selectmedium

A security team is conducting a lessons learned meeting after a major security incident. Which TWO of the following are PRIMARY objectives of this meeting? (Choose two.)

Select 2 answers
A.Identify the root cause of the incident to prevent recurrence.
B.Determine the financial cost of the incident for insurance claims.
C.Evaluate the effectiveness of the incident response process and identify improvements.
D.Assign blame to the individuals responsible for the incident.
E.Update the disaster recovery plan with new backup procedures.
AnswersA, C

One primary objective of a lessons learned meeting is to determine the root cause of the incident. By understanding what allowed the incident to occur, the team can implement corrective actions to prevent similar incidents in the future. This analysis is a core part of the post-incident activity phase in NIST SP 800-61.

Why this answer

The primary objectives of a lessons learned meeting are to identify the root cause of the incident and to evaluate the effectiveness of the incident response process. These objectives help the organization prevent future incidents and improve its response capabilities. Blame assignment, financial cost determination, and specific plan updates are not primary goals of this meeting.

Exam trap

The trap here is thinking that assigning blame or determining financial costs are key objectives, when the focus should be on learning and improvement.

10
MCQmedium

After a ransomware incident, an organization decides to restore data from backups. The RPO (Recovery Point Objective) is 4 hours. What does this RPO indicate?

A.Backups must be taken at least every 4 hours to ensure data loss does not exceed 4 hours
B.The organization can tolerate 4 hours of downtime
C.The system must be restored within 4 hours of the incident
D.The recovery process will take a maximum of 4 hours
AnswerA

RPO defines the maximum tolerable data loss measured in time, so a four-hour RPO means backups must run at least every four hours; otherwise a failure could destroy more than four hours of transactions, breaching the objective.

Why this answer

The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time. An RPO of 4 hours means the organization can tolerate losing up to 4 hours of data, so backups must be taken at least every 4 hours to ensure that in the worst case, no more than 4 hours of data is lost. This directly dictates the backup frequency, not the recovery time or downtime.

Exam trap

The trap here is confusing RPO (data loss tolerance) with RTO (downtime tolerance), leading candidates to select options that describe recovery time or downtime instead of backup frequency.

How to eliminate wrong answers

Option B is wrong because it describes the Recovery Time Objective (RTO), which is the maximum acceptable downtime, not the RPO. Option C is wrong because it also describes the RTO (time to restore service), not the RPO which is about data loss tolerance. Option D is wrong because it describes the actual recovery time, which is a metric of the restoration process, not the RPO's definition of acceptable data loss.

11
MCQhard

A company's disaster recovery plan specifies an RTO of 4 hours for its customer relationship management (CRM) system. Which of the following DR site types is MOST appropriate to meet this RTO?

A.Warm site
B.Mobile site
C.Hot site
D.Cold site
AnswerC

A hot site maintains continuously synchronised hardware, data and applications, enabling near-immediate failover well inside the four-hour RTO. Unlike warm or cold sites, which require restoration from backups or hardware provisioning, it satisfies the stem's demanding recovery time constraint for the business-critical CRM system.

Why this answer

A hot site is fully configured with hardware, software, and live data replication, enabling recovery within minutes to a few hours. Since the RTO is 4 hours, a hot site can meet this requirement by allowing immediate failover without the need for extensive setup or data restoration.

Exam trap

The trap here is that candidates often confuse a warm site (which has hardware but not live data) as sufficient for a 4-hour RTO, underestimating the time needed to restore and validate backups, which can easily exceed 4 hours for a CRM system with large databases.

How to eliminate wrong answers

Option A is wrong because a warm site has pre-installed hardware but may lack up-to-date data and require several hours to days to restore from backups, making it unsuitable for a 4-hour RTO. Option B is wrong because a mobile site is a portable unit that must be transported and configured on-site, typically taking days to become operational, far exceeding the 4-hour RTO. Option D is wrong because a cold site provides only physical infrastructure (power, cooling, space) with no IT equipment or data, requiring weeks to procure and install systems, which cannot meet a 4-hour RTO.

12
MCQeasy

After a security incident at a retail company, the incident response team conducts a post-incident review. The team identifies that the attacker gained initial access through an unpatched web server. Which of the following is the PRIMARY purpose of the lessons learned meeting in this scenario?

A.To determine the exact financial cost of the incident for insurance claims.
B.To assign blame to the team responsible for the unpatched server.
C.To identify improvements to prevent similar incidents and enhance response capabilities.
D.To immediately reimage all servers in the environment.
AnswerC

The primary purpose of a lessons learned meeting is to review the incident and identify changes to processes, tools, and training that will improve future prevention and response. In this retail scenario, the unpatched web server highlights a need to strengthen patch management and vulnerability scanning, which the meeting should capture as actionable improvements.

Why this answer

The lessons learned meeting is a post-incident activity focused on improving future prevention, detection, and response. It should produce actionable recommendations, such as strengthening patch management, rather than assigning blame or calculating costs. In this scenario, the unpatched web server points to a process gap that the meeting should address to reduce recurrence risk.

Exam trap

The trap here is equating the lessons learned meeting with blame assignment or cost accounting, when its core purpose is to drive process and control improvements.

13
Multi-Selectmedium

A security analyst is responding to a confirmed malware infection on a Windows workstation. The workstation is still powered on and connected to the corporate network. The analyst needs to collect volatile data that could be lost if the system is shut down or the malware is allowed to continue running. Which TWO of the following data sources should the analyst prioritize for collection? (Choose two.)

Select 2 answers
A.Event logs stored in the C:\Windows\System32\winevt\Logs directory.
B.Active network connections and associated process IDs.
C.The master file table (MFT) on the NTFS volume.
D.The Windows Registry hive files stored on the hard drive.
E.Contents of the system's RAM, including running processes and network connections.
AnswersB, E

Active network connections and their associated process IDs are volatile and can reveal command-and-control (C2) communications or data exfiltration. This information is lost when the system is shut down or the connection is terminated. Collecting it early helps identify the malware's external infrastructure and affected processes. Tools like netstat and Get-NetTCPConnection can capture this data quickly.

Why this answer

The two most volatile data sources are RAM contents and active network connections with process IDs. Both are lost when the system is powered off or the malware terminates its connections. Registry hives, MFT, and event logs are stored on disk and persist, so they can be collected later.

Prioritizing volatile data aligns with the order of volatility in incident response.

Exam trap

The trap here is confusing important disk-based artifacts, such as registry hives or event logs, with volatile data that disappears when the system is powered off.

14
MCQhard

An organization is conducting a disaster recovery test for its critical database. The RTO is 4 hours, and the RPO is 15 minutes. During the test, the team restores the database from a backup taken 2 hours before the test. The restore completes in 3 hours. Which statement accurately reflects the test outcome?

A.The test failed because the restore took longer than 15 minutes.
B.The test passed because the backup was available and restorable.
C.The test passed because the RTO was met.
D.The test failed because the RPO was exceeded.
AnswerD

The RPO is 15 minutes, meaning the organization can tolerate losing at most 15 minutes of data. The backup used was 2 hours old, so up to 2 hours of data would be lost, exceeding the RPO. Even though the restore time was within the RTO, the data loss exceeds the RPO, so the test failed from a data loss perspective. This makes the statement correct.

Why this answer

The RPO defines the maximum tolerable data loss, measured in time. A 2-hour-old backup means up to 2 hours of data could be lost, which exceeds the 15-minute RPO. The RTO, which is the maximum tolerable downtime, was met because the restore took 3 hours out of 4 allowed.

However, since the RPO was violated, the test failed overall. The correct statement identifies the RPO exceedance as the failure reason.

Exam trap

The trap here is focusing only on the RTO and ignoring the RPO, or confusing the two metrics, when both must be satisfied for a successful disaster recovery test.

15
MCQeasy

A security analyst is documenting an incident that involved unauthorized access to a file server. The analyst needs to record the timeline of events, actions taken, and evidence collected. Which of the following is the PRIMARY purpose of maintaining proper documentation during incident response?

A.To satisfy the requirement that all incidents must be reported to law enforcement within 24 hours.
B.To provide a detailed record that supports legal proceedings, regulatory compliance, and post-incident review.
C.To allow the public relations team to craft a press release about the incident.
D.To ensure that the incident response team can bill the organization for overtime hours.
AnswerB

Proper documentation during incident response serves multiple critical purposes: it creates an admissible record for legal action, demonstrates compliance with regulations and standards, and provides data for lessons learned and process improvement. Without accurate documentation, the organization may be unable to pursue legal remedies, face compliance penalties, or fail to understand the root cause. This is a fundamental requirement in NIST SP 800-61 and other incident response frameworks.

Why this answer

Incident response documentation is essential for creating a reliable record that can be used in legal proceedings, to demonstrate regulatory compliance, and to conduct meaningful post-incident reviews. It captures the timeline, actions taken, and evidence collected, ensuring accountability and enabling lessons learned. Without it, organizations risk losing critical information needed for prosecution, compliance audits, and improving future response efforts.

Other purposes like billing, blanket law enforcement reporting, or PR are secondary and not the primary drivers.

Exam trap

The trap here is confusing secondary benefits like public relations or billing with the primary purpose of documentation, which is to maintain an accurate and admissible record for legal, compliance, and improvement purposes.

16
MCQhard

A healthcare provider's incident response team is handling a suspected ransomware incident on a clinical workstation. The team lead wants to determine whether the incident should be escalated to a full response or handled as a false positive. According to NIST SP 800-61, which activity is part of the detection and analysis phase?

A.Validating the incident by correlating alerts with known indicators and impact.
B.Implementing a network access control list to block the ransomware's command-and-control domain.
C.Conducting a lessons learned meeting with clinical staff.
D.Eradicating the malware by reimaging the workstation.
AnswerA

Validation is a core detection and analysis activity: responders correlate alerts, indicators, and impact to confirm whether an event is a real incident. This step prevents wasted resources on false positives and determines the appropriate response. In the ransomware scenario, validating the alert against known ransomware indicators and assessing clinical impact directly supports the decision to escalate or dismiss.

Why this answer

Detection and analysis in NIST SP 800-61 involves validating alerts, correlating indicators, scoping the incident, and determining impact. Validation is the critical step that separates real incidents from false positives and informs escalation decisions. Eradication, containment, and post-incident review occur in later phases, so they are not part of detection and analysis.

Exam trap

The trap here is confusing containment or eradication actions with detection and analysis, because responders often want to act immediately rather than first validating whether the incident is real.

17
MCQmedium

An incident responder is collecting evidence from a compromised Linux server. The responder uses the 'dd' command to create an image of the hard drive. Which of the following is the PRIMARY reason for using a write blocker during this process?

A.To prevent the operating system from mounting the drive and altering timestamps.
B.To ensure the imaging process does not modify the original evidence.
C.To increase the speed of the imaging process by bypassing file system checks.
D.To allow the responder to write notes directly to the evidence drive for documentation.
AnswerB

The primary purpose of a write blocker is to prevent any write commands from reaching the evidence drive during imaging. This ensures that the original evidence remains unaltered, preserving its integrity for forensic analysis and legal proceedings. Without a write blocker, the imaging tool or OS could inadvertently write to the drive, contaminating the evidence.

Why this answer

A write blocker is a hardware or software tool that allows read-only access to a storage device, preventing any write operations. Its primary purpose is to ensure that the original evidence is not modified during forensic imaging. This preservation of integrity is crucial for the evidence to be admissible in court and for accurate analysis.

Exam trap

The trap here is thinking that a write blocker is mainly for preventing timestamp changes or for speed, rather than for blocking all writes to preserve evidence.

18
Multi-Selecthard

A forensic investigator is collecting evidence from a compromised Windows server. According to the order of volatility, which THREE pieces of evidence should be collected FIRST? (Select THREE)

Select 3 answers
A.System event logs
B.Hard drive image
C.Network connections and open ports
D.Contents of RAM (memory dump)
E.List of running processes
AnswersC, D, E

Network connections and open ports reside in memory and change or disappear within seconds, placing them near the top of the order of volatility. Collecting them first satisfies the stem's requirement to gather the most perishable evidence before it is lost.

Why this answer

According to the order of volatility, the most perishable data must be captured first because it disappears when the system is powered off or changes rapidly. Option C (Network connections and open ports) is correct because active TCP/UDP sessions, listening sockets, and ARP/routing state exist only in memory and vanish immediately on shutdown, so tools like netstat, ss, or Get-NetTCPConnection must run first. Option D (Contents of RAM (memory dump)) is correct because physical memory holds encryption keys, injected code, and uncommitted data that is irretrievably lost once power is removed, making it the highest-priority acquisition.

Option E (List of running processes) is correct because the process table, PIDs, parent-child relationships, and loaded modules are volatile kernel structures that change second by second and cannot be recovered from a later disk image. Option A (System event logs) is not among the first tier because, although logs are valuable, they are typically persisted to disk (.evtx files) and survive until overwritten, so they are collected after memory-resident artifacts. Option B (Hard drive image) is not among the first tier because disk contents are the least volatile and remain intact while live memory and network state are captured beforehand.

Exam trap

ISC2 SSCP often tests the misconception that event logs are volatile because they are 'system state' data, but logs are written to disk and persist; the trap is confusing 'important' with 'volatile'.

19
Multi-Selecthard

During a post-incident review, the incident response team identifies several areas for improvement. According to NIST SP 800-61, which THREE activities are typically part of the post-incident activity phase?

Select 3 answers
A.Patch all systems in the organization as a precaution
B.Update the incident response plan based on findings
C.Replace all affected hardware immediately
D.Conduct a lessons learned meeting
E.Track metrics such as MTTD and MTTR
AnswersB, D, E

NIST SP 800-61 places revising the incident response plan within post-incident activity, so lessons identified during review feed back into procedures, contact lists, and controls. This closes the improvement loop and better prepares the team for subsequent incidents.

Why this answer

Option B is correct because NIST SP 800-61's post-incident activity phase explicitly includes using the lessons learned and review findings to update the incident response plan, policies, and procedures so future responses improve. Option D is correct because holding a lessons learned meeting (post-incident review) with all involved parties is a core recommended activity in this phase, used to identify what happened, what was done well, and what needs improvement. Option E is correct because NIST SP 800-61 calls for using incident data to develop and track metrics, such as mean time to detect (MTTD) and mean time to recover/repair (MTTR), to measure and improve the incident response capability over time.

Option A is not part of the post-incident activity phase; patching is a remediation/eradication action performed during incident handling, not a blanket post-incident review activity. Option C is likewise incorrect because immediately replacing all affected hardware is a recovery/remediation decision made during the handling phase based on the specific incident, not a standard post-incident review activity.

Exam trap

The trap here is confusing operational recovery actions (like patching or hardware replacement) with the analytical and improvement-focused activities that define the post-incident phase per NIST SP 800-61.

20
MCQeasy

Which of the following is the primary purpose of a chain of custody form in digital forensics?

A.To track the possession and handling of evidence from collection to presentation
B.To document the steps taken to contain an incident
C.To record the hash values of forensic images
D.To provide a list of approved forensic tools
AnswerA

The chain of custody form records every transfer, custodian, and handling action for evidence, creating an unbroken audit trail from seizure through analysis to courtroom presentation. This documentation lets the court verify that nothing was altered, supporting evidence admissibility.

Why this answer

A chain of custody form is used to document the chronological sequence of custody, control, transfer, analysis, and disposition of evidence. Its primary purpose is to track who had possession of the evidence and what was done with it from the moment of collection through to presentation in court. This ensures the evidence is admissible and has not been tampered with.

Exam trap

SSCP often tests the confusion between chain of custody and other forensic documentation like incident response forms or hash logs, causing candidates to choose an answer that describes a related but different artifact.

How to eliminate wrong answers

Option B is wrong because documenting containment steps is part of incident response procedures, not the chain of custody form, which focuses on evidence handling. Option C is wrong because recording hash values is a separate integrity verification step; while hashes may be noted on a chain of custody form, the form's primary purpose is tracking possession, not recording hashes. Option D is wrong because a list of approved forensic tools is maintained in tool validation documentation, not in the chain of custody form.

21
MCQhard

During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) was 14 days. Which improvement would most directly reduce MTTD?

A.Implementing stricter access control policies
B.Conducting more frequent tabletop exercises
C.Deploying additional endpoint detection and response (EDR) sensors with automated alerting
D.Increasing the frequency of full system backups
AnswerC

EDR sensors with automated alerting detect malicious endpoint behaviour in near real time, collapsing the 14-day detection gap. Faster telemetry and alert generation directly shorten the time between compromise and discovery, which is precisely what MTTD measures.

Why this answer

Deploying additional EDR sensors with automated alerting directly reduces the time between an incident's occurrence and its detection by providing continuous monitoring and immediate notification of suspicious activities. This shortens the MTTD because automated alerts eliminate the delay inherent in manual log review or periodic checks, enabling the incident response team to react within minutes rather than days.

Exam trap

The trap here is that candidates often confuse detection speed (MTTD) with prevention or recovery metrics, mistakenly thinking that improving backups (Option D) or access controls (Option A) will help detect incidents faster, when in fact they address different phases of the incident response lifecycle.

How to eliminate wrong answers

Option A is wrong because stricter access control policies primarily reduce the likelihood of an incident (prevention) or limit the blast radius, but they do not improve detection speed; MTTD is a detection metric, not a prevention or containment metric. Option B is wrong because tabletop exercises improve team preparedness and response procedures, but they do not directly affect the speed of detecting real incidents; they focus on reaction and coordination after detection, not on reducing detection latency. Option D is wrong because increasing the frequency of full system backups improves data recovery capabilities and reduces recovery time objectives (RTO), but backups do not provide real-time visibility into ongoing malicious activity and thus have no direct impact on MTTD.

22
MCQeasy

After a security incident, an organization's legal team requests documentation that shows who had possession of a hard drive at every point from seizure to analysis. Which document should the incident responder provide?

A.Vulnerability assessment report
B.Incident response plan
C.Forensic imaging log
D.Chain of custody form
AnswerD

A chain of custody form records the chronological history of evidence, including who collected it, when, and every transfer of possession. It ensures evidence integrity and admissibility in legal proceedings. The legal team's request for documentation of possession at every point directly matches the purpose of a chain of custody form, making it the correct answer.

Why this answer

A chain of custody form is the formal record that documents the seizure, transfer, and analysis of evidence. It includes dates, times, names, and signatures of everyone who handled the evidence. This ensures that evidence has not been tampered with and is admissible in court.

The legal team's request for possession history is precisely what a chain of custody form provides, so it is the correct document.

Exam trap

The trap here is assuming that any forensic documentation, like an imaging log, satisfies a chain of custody request, when only a chain of custody form tracks every transfer of possession.

23
MCQeasy

During which phase of the NIST SP 800-61 incident response lifecycle are lessons learned meetings conducted and metrics such as MTTD and MTTR tracked?

A.Containment, Eradication, and Recovery
B.Preparation
C.Detection and Analysis
D.Post-Incident Activity
AnswerD

Post-Incident Activity is the NIST SP 800-61 phase where the incident is reviewed after containment and recovery. Lessons learned meetings occur here, and metrics including MTTD and MTTR are tracked to improve future response. This directly satisfies the stem's requirement for the phase covering retrospective analysis and performance measurement.

Why this answer

The Post-Incident Activity phase (D) is where lessons learned meetings are conducted and metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) are tracked. This phase focuses on reviewing the incident response process, identifying improvements, and documenting findings to enhance future response efforts, as defined in NIST SP 800-61 Revision 2.

Exam trap

ISC2 often tests the misconception that metrics like MTTD and MTTR are tracked during Detection and Analysis or Containment phases, but they are actually reviewed and analyzed only after the incident is resolved in the Post-Incident Activity phase.

How to eliminate wrong answers

Option A is wrong because Containment, Eradication, and Recovery focuses on stopping the incident, removing threats, and restoring operations, not on post-incident analysis or metric tracking. Option B is wrong because Preparation involves establishing policies, tools, and training before an incident occurs, not conducting lessons learned or tracking MTTD/MTTR after an incident. Option C is wrong because Detection and Analysis is the phase where incidents are identified and analyzed, but it does not include the retrospective review or metric collection that occurs in the Post-Incident Activity phase.

24
Multi-Selectmedium

A company is conducting a disaster recovery test. Which TWO types of tests involve minimal risk to production operations?

Select 2 answers
A.Tabletop exercise
B.Simulation test
C.Parallel test
D.Walkthrough
E.Full interruption test
AnswersA, D

A tabletop exercise poses minimal risk because participants discuss disaster recovery roles and procedures verbally, without touching production systems or activating failover. This satisfies the stem's constraint of testing readiness while avoiding any operational impact, unlike full interruption or parallel tests that consume resources or disrupt live services.

Why this answer

A tabletop exercise (A) is correct because it is a discussion-based test in which stakeholders talk through disaster recovery roles, procedures, and decision points without touching or reconfiguring any production systems, so it carries essentially no operational risk. A walkthrough (D) is also correct because participants verbally trace each step of the DR plan against documentation and expected actions, again without executing failover or activating alternate sites, keeping production untouched. By contrast, a simulation test (B) can involve activating recovery mechanisms or alternate processing in a controlled but still potentially disruptive manner, and a parallel test (C) runs the recovery site alongside production, which introduces cost, data-synchronization, and configuration risks.

A full interruption test (E) is the riskiest option because it actually shuts down or takes production offline to fail over completely, which is unacceptable when minimal risk is required.

Exam trap

A common misconception is that 'simulation' or 'parallel' tests are low-risk because they are 'controlled,' but the key distinction is that tabletop and walkthrough involve zero execution of technical recovery steps, while any test that touches production systems carries inherent risk.

25
MCQeasy

An organization is developing its incident response plan. According to NIST SP 800-61, which phase should include establishing a communication plan, acquiring necessary tools, and conducting exercises?

A.Preparation
B.Post-Incident Activity
C.Detection and Analysis
D.Containment, Eradication, and Recovery
AnswerA

Preparation covers building incident response capability before incidents occur, including developing the communication plan, procuring tools and resources, and running exercises to validate readiness. NIST SP 800-61 places all three activities in this phase, preceding detection, containment, and post-incident work.

Why this answer

According to NIST SP 800-61, the Preparation phase is where the organization establishes a communication plan, acquires necessary tools (e.g., forensic workstations, imaging software, network monitoring tools), and conducts exercises (e.g., tabletop exercises or full-scale simulations) to ensure readiness. This phase lays the foundation for all subsequent incident response activities by ensuring resources and procedures are in place before an incident occurs.

Exam trap

A common misconception is that Detection and Analysis includes proactive preparation activities, but NIST SP 800-61 clearly separates the proactive Preparation phase from the reactive Detection phase, which only begins after an incident is suspected.

How to eliminate wrong answers

Option B is wrong because the Post-Incident Activity phase focuses on lessons learned, evidence retention, and report generation after containment and recovery, not on proactive preparation like tool acquisition or exercises. Option C is wrong because Detection and Analysis involves identifying and validating incidents through log analysis, alerts, and threat intelligence, not establishing communication plans or acquiring tools. Option D is wrong because Containment, Eradication, and Recovery are reactive phases that execute actions to stop the incident, remove threats, and restore systems, relying on the tools and plans already set up in Preparation.

26
MCQeasy

What is the primary purpose of establishing a chain of custody for digital evidence?

A.To reduce the size of evidence for storage
B.To encrypt evidence for secure transmission
C.To maintain evidence integrity and track handling
D.To prioritize which evidence to analyze first
AnswerC

Chain of custody documents who collected, accessed and transferred each artefact, with timestamps and signatures. This unbroken audit trail preserves evidence integrity and admissibility, proving the data was not altered or substituted between seizure and presentation, which satisfies the requirement to track handling throughout the investigation.

Why this answer

The primary purpose of establishing a chain of custody for digital evidence is to maintain evidence integrity and track every person who handled the evidence from collection through presentation in court. This process ensures that the evidence has not been tampered with, altered, or corrupted, which is critical for admissibility under legal standards such as the Federal Rules of Evidence (FRE) Rule 901. By documenting each transfer with timestamps, signatures, and hash values (e.g., MD5 or SHA-256), the chain of custody provides a verifiable audit trail that supports the evidence's authenticity and reliability.

Exam trap

The trap here is that candidates confuse chain of custody with data preservation techniques like encryption or compression, but the exam specifically tests that its core purpose is to ensure integrity and provide an unbroken audit trail of handling, not to secure or reduce the data.

How to eliminate wrong answers

Option A is wrong because reducing the size of evidence for storage is not a purpose of chain of custody; that is typically achieved through compression algorithms like ZIP or deduplication, and it has no bearing on legal admissibility. Option B is wrong because encrypting evidence for secure transmission is a separate security measure (e.g., using AES-256 or TLS), not a function of chain of custody, which focuses on documenting handling rather than protecting confidentiality. Option D is wrong because prioritizing which evidence to analyze first is a triage decision made during incident response based on impact or volatility (e.g., memory over disk), not a goal of chain of custody, which applies equally to all evidence items.

27
MCQmedium

Which type of disaster recovery test involves running the DR systems alongside the production systems to validate functionality without impacting live operations?

A.Simulation test
B.Full interruption test
C.Tabletop exercise
D.Parallel test
AnswerD

A parallel test runs DR systems concurrently with production, letting recovery capabilities be validated under realistic load without disrupting live operations. Unlike full interruption, it confirms functionality while production continues serving users, satisfying the non-impact constraint.

Why this answer

A parallel test runs the disaster recovery systems concurrently with the production systems to verify that the DR environment can handle the workload without disrupting live operations. This approach validates data replication, application functionality, and failover readiness while keeping production untouched, making it the correct choice for non-disruptive validation.

Exam trap

The trap here is that candidates often confuse 'parallel test' with 'simulation test' because both sound non-disruptive, but a simulation test is purely theoretical while a parallel test actually runs DR systems with live data.

How to eliminate wrong answers

Option A is wrong because a simulation test involves a controlled, often tabletop-style walkthrough of disaster scenarios without actually activating DR systems or processing live data. Option B is wrong because a full interruption test (also called a full-scale test) requires shutting down production systems to fail over to the DR site, which directly impacts live operations. Option C is wrong because a tabletop exercise is a discussion-based review of roles and procedures, not a technical validation of DR system functionality.

28
MCQhard

During the eradication phase of a malware incident, a security analyst removes malicious files and cleans registry persistence. What is the MOST critical additional step to prevent reinfection through the same vector?

A.Patching the vulnerability that was exploited
B.Running a full antivirus scan
C.Resetting all user passwords
D.Reimaging the system with a clean OS
AnswerA

Patching the exploited vulnerability closes the original entry vector, so the attacker cannot reinfect the host through the same flaw. Removing files and registry persistence alone leaves that vector open, allowing immediate recompromise during or after eradication.

Why this answer

Patching the exploited vulnerability (Option A) is the most critical additional step because it removes the root cause of the infection. Without patching, the same attack vector (e.g., an unpatched SMB vulnerability like EternalBlue) remains open, allowing the malware to reinfect the system immediately after cleanup. Eradication is incomplete if the underlying flaw is not addressed, as the attacker can simply re-exploit the same weakness.

Exam trap

ISC2 often tests the misconception that cleaning or reimaging alone is sufficient, but the trap here is that candidates overlook the need to address the root cause (the vulnerability) to prevent reinfection through the same vector.

How to eliminate wrong answers

Option B is wrong because running a full antivirus scan is a detection and cleanup step, not a preventive measure against reinfection through the same vector; it may miss zero-day or polymorphic malware. Option C is wrong because resetting user passwords addresses credential theft or lateral movement, but does not close the exploited vulnerability (e.g., a remote code execution flaw in a network service). Option D is wrong because reimaging the system with a clean OS removes the malware but does not patch the original vulnerability; the system will be reinfected if reconnected to the same unpatched network.

29
Multi-Selectmedium

A security analyst is responding to a malware incident on a Windows server. Which TWO actions should be taken to properly collect volatile evidence?

Select 2 answers
A.Reboot the system to clear malware from memory
B.Delete suspicious files to prevent further infection
C.Perform a full disk image using a write blocker
D.Capture a memory dump using WinPmem
E.Record active network connections
AnswersD, E

WinPmem captures physical memory, preserving running processes, injected code and encryption keys that vanish on shutdown or reboot. This satisfies the volatile-evidence requirement, since RAM is lost first and must be acquired before any disk imaging or power-off.

Why this answer

Option D is correct because capturing a memory dump with WinPmem preserves the contents of RAM, which is the most volatile evidence and is lost the moment the system is powered off or rebooted. Option E is correct because recording active network connections (e.g., via netstat or similar tools) documents volatile state such as established sessions, listening ports, and remote endpoints that would otherwise disappear. Options A and B are wrong because rebooting or deleting files destroys volatile evidence and alters the system state, violating order-of-volatility principles.

Option C is incorrect here because a full disk image with a write blocker captures non-volatile storage, not volatile evidence such as memory or live network connections.

Exam trap

The trap here is that candidates often confuse 'volatile evidence' with 'non-volatile evidence' and choose disk imaging (Option C) instead of memory capture, or mistakenly think rebooting (Option A) is a safe containment step.

30
MCQmedium

After a security incident, the incident response team holds a lessons learned meeting. What is the PRIMARY outcome of this meeting?

A.Permanently delete all evidence related to the incident
B.Inform the media about the incident details
C.Identify improvements to the incident response process
D.Assign blame for the incident
AnswerC

The lessons learned meeting reviews what occurred, what worked and what failed, then produces actionable recommendations to strengthen the incident response plan, tools and procedures. Its primary outcome is documented process improvement, not blame or immediate remediation of the affected systems.

Why this answer

The primary outcome of a lessons learned meeting is to identify improvements to the incident response process. This meeting focuses on analyzing what worked well and what did not, leading to actionable changes in policies, procedures, and tools to enhance future incident handling. It is a key component of the continuous improvement cycle mandated by frameworks like NIST SP 800-61.

Exam trap

The trap here is that candidates may confuse the lessons learned meeting with the immediate operational steps of incident response, such as evidence handling or public relations, rather than recognizing its core purpose of process improvement and continuous learning.

How to eliminate wrong answers

Option A is wrong because permanently deleting all evidence related to the incident violates legal hold requirements, chain of custody, and potential forensic analysis needs; evidence must be preserved according to retention policies and regulatory mandates. Option B is wrong because informing the media about incident details is not a primary outcome of a lessons learned meeting; such communication is handled by a designated public relations or legal team to avoid compromising investigations or violating disclosure laws. Option D is wrong because assigning blame is counterproductive and contrary to the purpose of a lessons learned meeting, which is to focus on process improvement rather than individual fault; a blame-free culture encourages honest reporting and effective remediation.

31
MCQeasy

Which DR testing type involves running recovery systems in parallel with production systems to verify functionality without impacting live operations?

A.Full interruption test
B.Simulation test
C.Parallel test
D.Tabletop exercise
AnswerC

A parallel test runs recovery systems alongside production, processing the same transactions in parallel, so functionality is verified without disrupting live operations. This directly satisfies the stem's constraint of validating recovery capability while leaving production systems untouched.

Why this answer

A parallel test is the correct DR testing type because it involves running the recovery systems concurrently with the production systems. This allows the organization to verify that the backup systems function correctly and can handle the workload without any impact on live operations, as the production environment remains untouched.

Exam trap

ISC2 often tests the distinction between a parallel test and a simulation test, where candidates mistakenly think a simulation involves actual system execution, but in reality, a simulation test is a theoretical exercise without any live system activation.

How to eliminate wrong answers

Option A is wrong because a full interruption test (also known as a full-scale or hot start test) requires shutting down the primary production systems and failing over entirely to the recovery site, which directly impacts live operations and is not a parallel run. Option B is wrong because a simulation test involves a walk-through or role-playing scenario where team members discuss their responses to a disaster without actually activating any recovery systems or processing live data. Option D is wrong because a tabletop exercise is a discussion-based session where participants review plans and procedures in a meeting room, with no actual execution of recovery systems or parallel processing.

32
MCQmedium

An incident responder is collecting evidence from a compromised server. Which of the following is the correct order for collecting volatile data?

A.Network connections, memory dump, disk image
B.Disk image, network connections, memory dump
C.Memory dump, network connections, disk image
D.Disk image, memory dump, network connections
AnswerA

Memory is more volatile than network connections, so it should be first.

Why this answer

Volatile data must be collected in order of decreasing volatility. Network connections (active sessions, ARP cache, routing tables) are more volatile than RAM and can change or disappear within seconds, so they are captured first. Memory (RAM) is collected next because it is lost on power loss but persists slightly longer than network state.

The disk image is collected last because it is persistent storage and the least volatile. This order preserves ephemeral evidence such as active sessions, running processes, and encryption keys before it disappears.

Exam trap

ISC2 often tests the misconception that disk imaging should be done first because it is the most stable evidence source, but the trap is that volatile data such as network state and memory is lost forever if not captured immediately. Note that network connections are more volatile than RAM and must be collected before the memory dump.

How to eliminate wrong answers

Option A is wrong because collecting network connections before memory dump risks losing volatile memory contents (e.g., processes, kernel objects) that may contain evidence of active malware or encryption keys. Option B is wrong because starting with a disk image is the least volatile and would cause loss of all volatile data (memory and network state) before they are captured. Option D is wrong because collecting disk image before memory dump violates the order of volatility; memory must be captured first as it is lost immediately upon shutdown or power loss.

33
MCQmedium

An analyst detects suspicious outbound traffic from a workstation to a known command-and-control IP. Which IoC blocking method is MOST appropriate as an immediate containment measure?

A.Delete the malicious files from the system
B.Remove the malware from the workstation using EDR
C.Block the IP address at the perimeter firewall
D.Disable the user's account
AnswerC

Blocking the command-and-control IP at the perimeter firewall immediately severs the workstation's outbound channel, halting data exfiltration and further instruction. This satisfies the containment constraint by stopping active communication fast, before deeper host remediation begins.

Why this answer

Blocking the IP address at the perimeter firewall is the most appropriate immediate containment measure because it directly cuts the outbound communication channel to the known command-and-control (C2) server. This stops data exfiltration and prevents the attacker from issuing further commands, buying time for deeper analysis. Firewall ACLs or blackhole routes can be applied in seconds without altering the endpoint, which is critical when the malware may have persistence mechanisms or anti-forensic capabilities.

Exam trap

The trap is that candidates may focus on endpoint remediation (e.g., deleting files or removing malware) rather than immediate containment through network-level blocking, which is the priority in incident response.

How to eliminate wrong answers

Option A is wrong because deleting malicious files from the system does not stop active C2 traffic; the malware may be running in memory or have already established a persistent connection, and file deletion alone does not terminate existing network sessions. Option B is wrong because removing malware using EDR is a remediation step, not an immediate containment measure; EDR removal can take time, may trigger malware defenses, and does not instantly block the outbound C2 traffic already in progress. Option D is wrong because disabling the user's account does not affect the malware's network communication; the malware runs as a process independent of user authentication and can continue sending data over the network even with the account disabled.

34
MCQhard

An incident responder is analyzing a network packet capture to determine the scope of a data exfiltration incident. The responder notices a large volume of outbound traffic to an unfamiliar IP address over port 443. Which of the following should the responder do FIRST to determine if the traffic is malicious?

A.Block the IP address at the firewall to stop the exfiltration.
B.Check the IP address against a threat intelligence feed to see if it is known malicious.
C.Inspect the packet payload and metadata for signs of command-and-control or data exfiltration.
D.Perform reverse DNS lookup and WHOIS on the IP address to gather ownership information.
AnswerC

The first step in determining if the traffic is malicious is to analyze the packets themselves. This includes examining payloads for known malware signatures, checking for unusual protocols or patterns, and looking at metadata such as packet sizes, timing, and frequency. This analysis can reveal if the traffic is encrypted command-and-control, data exfiltration, or benign. It provides the evidence needed to justify further actions.

Why this answer

To determine if the outbound traffic is malicious, the responder must first inspect the packet payload and metadata. This direct analysis can reveal signs of exfiltration, such as large data transfers, unusual protocols, or communication patterns indicative of command-and-control. It provides concrete evidence before taking any containment or intelligence-gathering steps that might be premature.

Exam trap

The trap here is jumping to containment or external intelligence lookups before analyzing the actual traffic, which is the most direct way to confirm malicious activity.

35
MCQhard

During a malware containment operation, the incident response team decides to isolate an infected endpoint using network access controls. However, the malware is spreading via removable media. Which additional containment measure should the team implement?

A.Block the malware's command-and-control IP at the firewall
B.Disable the user's account and force a password reset
C.Reimage the infected system immediately
D.Group policy to disable USB ports or restrict autorun
AnswerD

Network isolation blocks lateral spread over the LAN but does nothing against USB-borne propagation, since removable media bypasses network access controls entirely. Disabling USB ports or restricting autorun via Group Policy closes that physical channel, satisfying the stem's requirement to contain malware spreading through removable media.

Why this answer

The malware is spreading via removable media, so disabling USB ports or restricting autorun via Group Policy directly cuts off the propagation vector. Network access controls (NAC) isolate the endpoint from the network, but they do not prevent the malware from copying itself to USB drives or executing via autorun.inf. Group Policy can disable the storage device class (e.g., via 'Removable Storage Access' policies) or disable autorun entirely (via 'Turn off Autoplay' policy), stopping the spread at the physical media level.

Exam trap

The exam often tests the distinction between containment and remediation, and the trap here is that candidates confuse blocking C2 traffic (Option A) with stopping local propagation, failing to recognize that removable media spread is independent of network connectivity.

How to eliminate wrong answers

Option A is wrong because blocking the C2 IP at the firewall only disrupts command-and-control communication, not the local spread via removable media; the malware can still propagate via USB drives without needing network connectivity. Option B is wrong because disabling the user's account and forcing a password reset addresses credential compromise or unauthorized access, but does not stop the malware from copying itself to removable media or autorunning on other systems. Option C is wrong because reimaging the infected system immediately is a remediation step, not a containment step; containment must first stop the spread, and reimaging should only occur after containment is achieved to avoid reinfection or data loss.

36
MCQmedium

Which of the following is the PRIMARY purpose of establishing a chain of custody when handling digital evidence?

A.To determine the priority of the incident
B.To ensure that evidence is stored in a secure location
C.To prove that evidence has not been altered or tampered with from collection to presentation
D.To identify which forensic tools were used during analysis
AnswerC

A documented chain of custody records every transfer, handler and storage condition from seizure to courtroom, creating an auditable trail that demonstrates the evidence's integrity remained intact. This directly satisfies the stem's demand for the primary purpose: proving the data was neither altered nor tampered with between collection and presentation.

Why this answer

The primary purpose of chain of custody is to create a documented, unbroken record of every person who handled the evidence, from collection through presentation in court. This documentation is critical to demonstrate that the digital evidence has not been altered, tampered with, or corrupted, thereby preserving its integrity and admissibility. Without a proper chain of custody, the opposing party can successfully challenge the evidence as unreliable or compromised.

Exam trap

The trap here is that candidates often confuse the purpose of chain of custody with the purpose of secure storage (Option B), but the exam specifically tests that the primary goal is proving evidence integrity through an unbroken record of custody, not just physical security.

How to eliminate wrong answers

Option A is wrong because establishing chain of custody has nothing to do with determining incident priority; priority is based on impact, criticality, and business risk, not evidence handling. Option B is wrong because while secure storage is an important part of evidence preservation, it is only one component of the chain of custody process, not the primary purpose; the core goal is proving integrity through documentation of every transfer and access event. Option D is wrong because identifying forensic tools used during analysis is a matter of methodology documentation, not chain of custody; chain of custody focuses on who had possession and when, not which software was employed.

37
MCQmedium

An organization's incident response team has just completed the recovery phase of a major security incident. The team lead is now planning the post-incident activity. According to NIST SP 800-61, which of the following should be the PRIMARY focus of the lessons learned meeting?

A.Identifying improvements to the incident response plan and procedures based on what worked and what did not.
B.Updating the organization's disaster recovery plan to reflect the new threat landscape.
C.Calculating the total financial cost of the incident to report to stakeholders.
D.Determining which team members should be disciplined for mistakes made during the response.
AnswerA

The lessons learned meeting is intended to review the incident and the response to identify strengths and weaknesses, leading to improvements in the incident response plan, procedures, and training. This helps the organization better prepare for future incidents. The primary focus is on process improvement, not on assigning blame or calculating costs. NIST SP 800-61 emphasizes that the meeting should produce actionable recommendations.

Why this answer

The primary focus of a lessons learned meeting after an incident is to review the response efforts and identify improvements to the incident response plan, procedures, and training. This aligns with NIST SP 800-61, which emphasizes that the meeting should produce actionable recommendations to enhance future response. It is not about discipline, financial reporting, or solely updating disaster recovery plans.

The goal is continuous improvement of the incident response capability.

Exam trap

The trap here is confusing the lessons learned meeting with a disciplinary or financial review, when its core purpose is to improve incident response processes through constructive analysis.

38
MCQeasy

Which metric is used to measure the average time it takes to detect an incident?

A.Recovery Point Objective (RPO)
B.Mean Time to Resolve (MTTR)
C.Mean Time to Detect (MTTD)
D.Recovery Time Objective (RTO)
AnswerC

Mean Time to Detect measures the average elapsed time between an incident's actual occurrence and its detection by monitoring or staff. This directly satisfies the stem's requirement for the metric quantifying detection speed, distinguishing it from response or resolution metrics.

Why this answer

Mean Time to Detect (MTTD) is the correct metric because it specifically measures the average time elapsed between the occurrence of an incident and its detection by monitoring systems or security personnel. This metric is critical in incident response as it directly impacts the window of opportunity for attackers to cause damage before containment begins.

Exam trap

The trap here is that candidates often confuse Mean Time to Detect (MTTD) with Mean Time to Resolve (MTTR) because both acronyms start with 'MTT' and relate to incident timelines, but MTTD focuses solely on detection while MTTR covers the entire resolution process after detection.

How to eliminate wrong answers

Option A is wrong because Recovery Point Objective (RPO) measures the maximum acceptable amount of data loss measured in time, not detection time; it is used in backup and disaster recovery planning. Option B is wrong because Mean Time to Resolve (MTTR) measures the average time taken to fully resolve an incident after detection, not the detection phase itself. Option D is wrong because Recovery Time Objective (RTO) measures the maximum acceptable downtime after a disaster, not the time to detect an incident.

39
MCQhard

An incident responder is preparing to acquire volatile data from a compromised Linux server that is still powered on. The server hosts a critical database and cannot be shut down yet. According to order of volatility, which data source should the responder collect FIRST?

A.Output of the netstat -antp command showing active network connections
B.Contents of the /var/log/auth.log file
C.Temporary files in the /tmp directory
D.Contents of physical memory (RAM) using a tool such as LiME
AnswerD

Order of volatility dictates that memory (RAM) is more volatile than network state, disk logs, or temporary files. RAM holds running processes, open network connections, encryption keys, and malware artifacts that disappear on shutdown or reboot. Capturing RAM first preserves the most perishable evidence. Tools like LiME allow memory acquisition on Linux, making this the correct first step.

Why this answer

The order of volatility prioritizes data that is most likely to be lost first. RAM is highly volatile and contains running processes, network connections, encryption keys, and malware that may not exist on disk. Network state and disk logs are less volatile and can be collected afterward.

Capturing memory with a tool like LiME before other sources ensures the most perishable evidence is preserved for forensic analysis.

Exam trap

The trap here is assuming that network connections or logs are the most volatile because they change frequently, when actually RAM contents are lost first upon shutdown or reboot.

40
Multi-Selectmedium

An incident responder is collecting volatile evidence from a compromised Linux server. Which TWO of the following should be collected first? (Select two.)

Select 2 answers
A.Disk image of the system drive
B.System log files from /var/log
C.Hardware configuration inventory
D.List of active network connections using netstat
E.Contents of RAM using LiME
AnswersD, E

Listing active network connections with netstat captures ephemeral socket state that vanishes on reboot or service restart, preserving attacker command-and-control and lateral-movement evidence. This satisfies the stem's volatility constraint: network connections are among the first artefacts lost, so they must be collected before memory-resident data degrades further.

Why this answer

Option E (Contents of RAM using LiME) is correct because RAM is the most volatile evidence on a running Linux system and is lost on shutdown or reboot; LiME (Linux Memory Extractor) is a kernel module that captures physical memory to a file for later forensic analysis, preserving running processes, encryption keys, and network state. Option D (List of active network connections using netstat) is correct because active connections, listening sockets, and associated PIDs are highly volatile and change within seconds, so capturing them early preserves evidence of command-and-control channels and lateral movement; netstat (or its modern replacement ss) reads this state directly from the kernel. Option A (Disk image of the system drive) is not first because disk contents are persistent and can be acquired later without loss, and imaging a live disk is slower and less volatile than memory or network state.

Option B (System log files from /var/log) is not first because logs are stored on disk and persist across reboots, so they are less volatile than RAM or active connections. Option C (Hardware configuration inventory) is not first because hardware configuration is static and remains available after the incident, making it the least volatile category of evidence.

Exam trap

In the SSCP exam, the order of volatility is a key concept for incident response. The trap is that candidates mistakenly prioritize disk-based artifacts (logs, images) over truly volatile data like RAM and network connections, which are lost on power-off.

41
Multi-Selectmedium

After a security incident, the response team holds a lessons learned meeting. Which TWO are primary objectives of this meeting? (Select two.)

Select 2 answers
A.Identify what went well and what could be improved
B.Update the incident response plan and runbooks
C.Delete all evidence to free up storage
D.Assign blame for the incident
E.Restore affected systems to production
AnswersA, B

Reviewing what went well and what could be improved captures strengths and gaps in detection, response and coordination, which is a primary purpose of the post-incident lessons learned meeting. It feeds directly into refining processes rather than assigning blame.

Why this answer

Option A is correct because a lessons learned (post-incident) meeting is fundamentally a review activity whose primary purpose is to evaluate the response effort, capturing both effective actions ('what went well') and gaps or weaknesses ('what could be improved') so the organization can learn from the incident. Option B is correct because the actionable output of that review is to feed findings back into the incident response plan, playbooks, and runbooks — updating procedures, detection rules, and escalation paths so future incidents are handled more effectively. Option C is incorrect because evidence must be preserved for forensic analysis, legal, and regulatory purposes, not deleted; evidence handling follows chain-of-custody requirements.

Option D is incorrect because lessons learned meetings are blameless post-mortems focused on process and systemic improvement, not on assigning individual fault, which would suppress honest reporting. Option E is incorrect because restoring affected systems to production is part of the recovery/eradication phase of incident handling, not an objective of the post-incident lessons learned meeting, which occurs after recovery.

Exam trap

The trap here is that candidates may confuse operational recovery tasks (like restoring systems or deleting evidence) with the strategic, process-improvement objectives of the lessons learned meeting, which are solely focused on analyzing the response and updating documentation.

42
MCQhard

An organization is restoring a critical database from a backup after a ransomware attack. Which of the following steps should be performed BEFORE restoring the data to ensure the restoration is successful and secure?

A.Notify users that the system will be available in one hour
B.Disconnect the backup server from the network
C.Immediately restore the most recent backup to minimize data loss
D.Verify the integrity of the backup and patch the exploited vulnerability
AnswerD

Validating backup integrity confirms the data is uncorrupted and restorable, while patching the exploited vulnerability prevents immediate re-infection during restoration. Both must precede the restore to satisfy the stem's requirement that restoration be successful and secure.

Why this answer

Verifying backup integrity (e.g., using checksums or restore tests) ensures the backup is not corrupted or incomplete, which is critical after a ransomware attack where backups may also be targeted. Patching the exploited vulnerability (e.g., applying a security update or disabling the vulnerable service) prevents re-infection during or after the restore, ensuring the recovery is secure. Without these steps, restoring a compromised or incomplete backup could lead to data loss or immediate re-encryption by the same ransomware.

Exam trap

The trap here is that candidates assume restoring the most recent backup is always the priority, but the SSCP exam emphasizes that verifying backup integrity and securing the environment against re-infection are mandatory prerequisites for a successful and secure recovery.

How to eliminate wrong answers

Option A is wrong because notifying users of a one-hour availability before verifying the backup or patching the vulnerability is premature and unrealistic; restoration time depends on backup size and integrity checks, and users should only be notified after a successful restore and testing. Option B is wrong because disconnecting the backup server from the network is a good practice during recovery to prevent ransomware spread, but it is not the step that ensures restoration success and security—it is a containment measure that should be done before or during the restore, not the critical prerequisite for a successful restore. Option C is wrong because immediately restoring the most recent backup without verifying its integrity risks restoring a corrupted or encrypted backup (common in ransomware attacks where backups are also encrypted), and without patching the vulnerability, the system will be immediately re-infected.

43
MCQhard

An incident responder is investigating a compromised Linux server and needs to collect volatile data. The responder has root access and wants to ensure that the data collected is admissible in a court of law. Which of the following commands should be used FIRST to capture the contents of physical memory?

A.LiME (Linux Memory Extractor) to dump memory to a file
B.gcore to dump the memory of all running processes
C.The 'free' command to display memory usage statistics
D.dd if=/dev/mem of=/evidence/memory.dd
AnswerA

LiME is a loadable kernel module designed for volatile memory acquisition on Linux. It allows the responder to dump physical memory to a file or over the network without altering the system state significantly. It is widely accepted in forensics because it preserves the integrity of the memory image and is less likely to crash the system, making the evidence more defensible in court.

Why this answer

LiME is specifically designed for Linux memory forensics, allowing a responder to capture physical memory in a forensically sound manner. It loads as a kernel module and writes the memory image to a file or network destination, preserving the integrity of the evidence. This method is accepted in legal proceedings because it does not alter the system state unnecessarily and captures a comprehensive image.

Exam trap

The trap here is assuming that traditional tools like dd on /dev/mem or process-level dumps are sufficient for full physical memory acquisition, when they are not forensically reliable on modern systems.

44
MCQmedium

During incident response, a team needs to isolate an infected workstation that is part of a critical manufacturing network. Which containment method is MOST appropriate to minimize disruption while preventing the spread of malware?

A.Place the workstation into a quarantine VLAN via switch configuration
B.Apply a host-based firewall rule to block all inbound traffic
C.Physically unplug the network cable
D.Disable the user's Active Directory account
AnswerA

A quarantine VLAN isolates the workstation at the switch port while leaving the manufacturing network's routing and production traffic intact. This contains malware spread with minimal disruption, unlike disabling the switch port or powering off, which would halt critical operations.

Why this answer

Placing the workstation into a quarantine VLAN via switch configuration is most appropriate because it logically isolates the infected host from the rest of the network at Layer 2, preventing lateral spread of malware while allowing the manufacturing network to continue operating. This method uses 802.1Q VLAN tagging and access control lists (ACLs) on the switch to restrict traffic without physically disconnecting the device, which could disrupt time-sensitive manufacturing processes. It also preserves the ability to remotely manage or forensically image the workstation if needed.

Exam trap

The trap here is that candidates often choose 'physically unplug the network cable' because it seems like the most definitive containment, but they overlook the requirement to minimize disruption in a critical manufacturing network where sudden disconnection can halt production or cause safety hazards.

How to eliminate wrong answers

Option B is wrong because applying a host-based firewall rule to block all inbound traffic does not prevent the infected workstation from initiating outbound connections to spread malware to other systems, and it relies on the compromised host's own software, which may be disabled or bypassed by the malware. Option C is wrong because physically unplugging the network cable completely removes the workstation from the network, which can cause immediate disruption to critical manufacturing processes that depend on that workstation for real-time control or monitoring. Option D is wrong because disabling the user's Active Directory account only prevents authentication and access to domain resources, but does not stop the workstation from communicating with other devices on the same subnet or from spreading malware via non-authenticated protocols like ARP or NetBIOS.

45
MCQmedium

A security analyst is reviewing the organization's disaster recovery plan and notices that the Recovery Time Objective (RTO) for a critical application is 2 hours, but the current recovery process takes 8 hours. Which of the following should the analyst recommend FIRST?

A.Accept the risk and document the deviation.
B.Increase the RTO to 8 hours to match the current capability.
C.Purchase a new disaster recovery site.
D.Implement additional automation to reduce recovery time.
AnswerD

The RTO is not being met, so the first step is to improve the recovery process to meet the objective. Automation can significantly reduce manual steps and speed up recovery. Other options like increasing the RTO or accepting the risk might be considered later, but the initial recommendation should be to close the gap by enhancing the process. This aligns with continuous improvement in disaster recovery planning.

Why this answer

When the actual recovery time exceeds the RTO, the priority is to improve the recovery process to meet the business requirement. Automation can reduce manual effort and errors, speeding up recovery. Adjusting the RTO or accepting risk should only be considered after attempting to meet the objective.

Purchasing new infrastructure is a last resort and may not address process inefficiencies.

Exam trap

The trap here is thinking that changing the RTO is the solution, but the RTO is a business requirement that should be met.

46
MCQmedium

A security team is conducting a lessons learned meeting after a major security incident. The team identifies that the incident response plan was not followed because team members were unsure of their roles. Which of the following should be the PRIMARY outcome of this meeting to address the issue?

A.Outsource all incident response activities to a third-party provider.
B.Purchase a new SIEM solution to improve detection capabilities.
C.Immediately terminate the employees who failed to follow the plan.
D.Update the incident response plan with clearer role definitions and provide additional training.
AnswerD

The lessons learned meeting should result in actionable improvements. If roles were unclear, updating the plan to define responsibilities and training personnel accordingly directly addresses the root cause. This ensures future responses are more effective and aligns with the post-incident activity phase of NIST SP 800-61, which emphasizes revising policies and procedures based on findings.

Why this answer

The primary outcome of a lessons learned meeting is to identify improvements and implement changes to prevent recurrence. Since the issue was unclear roles, updating the incident response plan with clear role definitions and providing training directly addresses the deficiency. This aligns with best practices for continuous improvement in incident response.

Exam trap

The trap here is focusing on punitive actions or technology purchases instead of the root cause, which is a process and people issue that requires clear role definition and training.

47
MCQmedium

A financial services firm has just contained a ransomware incident on a file server. The incident response plan requires a formal post-incident activity phase. The CISO wants to know what the team should do FIRST to improve future response. Which action best aligns with NIST SP 800-61 post-incident activity?

A.Update the incident response plan with new detection signatures based on the ransomware variant.
B.Immediately reimage the server and restore data from the most recent backup.
C.Conduct a lessons learned meeting with all involved parties to review the incident timeline and response actions.
D.Notify the board of directors and external regulators about the incident.
AnswerC

NIST SP 800-61 identifies lessons learned as a key post-incident activity. A meeting with stakeholders reviews what happened, what worked, and what needs improvement. This directly addresses the CISO's goal of improving future response by capturing insights while details are fresh. It should occur before final recovery changes obscure the timeline, making it the correct first action.

Why this answer

NIST SP 800-61 defines post-incident activity as including lessons learned to improve future response. Holding a lessons learned meeting with involved parties captures what happened, what was effective, and what needs improvement. This should occur before recovery actions or plan updates, because the team's memory is freshest and evidence is still available.

The other actions are either recovery steps or communication tasks that do not directly fulfill the improvement goal.

Exam trap

The trap here is assuming that technical fixes like reimaging or signature updates constitute post-incident improvement, when NIST SP 800-61 prioritizes a lessons learned review first.

48
MCQmedium

A financial services firm's incident response team has just contained a malware outbreak on a file server. The server contains regulated customer data. The team lead instructs the responder to capture the current state of the system before any remediation. According to NIST SP 800-61, which action should the responder take FIRST to preserve the most volatile evidence?

A.Dump the contents of RAM and capture active network connections.
B.Export the server's event logs to a remote syslog server.
C.Capture a forensic image of the server's hard drive using a write blocker.
D.Document the server's physical location and hardware configuration.
AnswerA

RAM contents, running processes, and active network connections are the most volatile evidence and are lost when the system is powered off or rebooted. NIST SP 800-61 recommends collecting these first during the containment phase. Capturing memory and network state preserves indicators such as injected code, encryption keys, and command-and-control sessions before any remediation disrupts them.

Why this answer

The order of volatility dictates that the most transient evidence be collected first. RAM contents, running processes, and active network connections disappear when a system is powered down or rebooted, so they must be captured before disk imaging, log export, or physical documentation. This aligns with NIST SP 800-61 guidance to preserve volatile data during containment.

Exam trap

The trap here is assuming that disk imaging always comes first because it is the most familiar forensic step, when in fact volatile memory and network state must be captured before any shutdown or reboot.

49
Multi-Selecthard

During a post-incident review of a data breach, the incident response team is evaluating the chain of custody for forensic evidence. Which THREE practices demonstrate proper evidence handling? (Choose three.)

Select 3 answers
A.The original hard drive was used directly for analysis to avoid delays.
B.A write blocker was used when creating a forensic image of the disk.
C.MD5 hashes were computed only after the analysis was complete.
D.The forensic image was verified by comparing its hash to the hash of the original disk.
E.Each person who handled the evidence documented their name, date, time, and purpose.
AnswersB, D, E

Using a hardware or software write blocker prevents any modification to the source disk during imaging, preserving its integrity as evidence. This directly satisfies the chain-of-custody requirement that forensic copies be bit-for-bit accurate and unaltered, ensuring the image remains admissible and defensible during the post-incident review.

Why this answer

Option B is correct because a hardware or software write blocker prevents any modification to the original disk during imaging, preserving its integrity and admissibility as evidence. Option D is correct because comparing the hash (e.g., MD5 or SHA-256) of the forensic image to the hash of the original disk proves the image is a bit-for-bit duplicate and has not been altered. Option E is correct because maintaining an unbroken chain of custody requires every handler to record their name, date, time, and purpose of access, ensuring accountability and traceability.

Option A is wrong because analyzing the original drive directly risks altering metadata and destroying evidence; instead, a forensic image should be analyzed. Option C is wrong because hashes must be computed immediately upon acquisition (before analysis) to establish a baseline for integrity verification, not only afterward.

Exam trap

A common trap in this question is the misconception that hashing can be done at any point during the investigation, but integrity verification must occur before analysis begins to establish a baseline, not after the fact.

50
MCQeasy

What is the PRIMARY purpose of a lessons learned meeting after an incident?

A.To assign blame for the incident
B.To satisfy regulatory compliance requirements
C.To calculate the financial cost of the incident
D.To identify improvements in the incident response process
AnswerD

Lessons learned exists to feed findings back into the incident response plan, refining procedures, tools and communication based on what actually happened. It satisfies the stem's primary-purpose constraint by targeting process improvement rather than blame, evidence preservation or immediate containment.

Why this answer

The primary purpose of a lessons learned meeting is to analyze the incident response process to identify what worked well and what did not, enabling the team to update procedures, playbooks, and tools to improve future responses. This aligns with the continuous improvement cycle mandated by frameworks like NIST SP 800-61, which emphasizes post-incident activity to refine detection and remediation capabilities.

Exam trap

The trap here is that candidates confuse the primary goal of process improvement with secondary outcomes like cost calculation or compliance, but the SSCP exam emphasizes that the core purpose is to enhance the incident response plan's effectiveness, not to assign blame or tally expenses.

How to eliminate wrong answers

Option A is wrong because lessons learned meetings are explicitly non-punitive and focus on process improvement, not assigning blame, which would discourage open reporting and hinder future incident handling. Option B is wrong while regulatory compliance may require documentation of post-incident reviews, the primary purpose is not compliance but operational improvement; compliance is a secondary benefit. Option C is wrong because calculating financial cost is typically part of a separate damage assessment or forensic accounting, not the core objective of a lessons learned meeting, which centers on process effectiveness.

51
MCQmedium

A security analyst receives an alert from the SIEM about a possible malware infection on a workstation. The analyst confirms the infection and begins containment. Which of the following actions BEST aligns with the containment phase of the NIST SP 800-61 incident response lifecycle?

A.Isolate the workstation from the network by disabling its switch port.
B.Immediately reimage the workstation to remove the malware.
C.Run a full antivirus scan on the workstation.
D.Document the incident in the ticketing system.
AnswerA

Isolating the workstation from the network prevents the malware from spreading to other systems, which is a primary goal of containment. Disabling the switch port effectively cuts off network communication while preserving the system state for later forensic analysis. This action directly limits the scope and impact of the incident, aligning with NIST SP 800-61 containment strategies.

Why this answer

Containment aims to limit the damage and prevent further spread of the incident. Isolating the infected workstation from the network achieves this by cutting off communication, which can stop lateral movement and command-and-control traffic. Other actions like reimaging or scanning are part of later phases such as eradication or recovery, and documentation, while necessary, does not contain the threat.

Exam trap

The trap here is confusing eradication actions like reimaging with containment, which is about stopping the spread.

52
MCQhard

During a malware outbreak, a security analyst needs to contain the spread. The affected systems are on the same VLAN as critical servers. Which of the following containment actions should be performed FIRST to minimize impact?

A.Disable user accounts associated with the infected systems
B.Isolate the affected systems by applying VLAN quarantine or ACLs
C.Reboot the affected systems to clear malware from memory
D.Restore the affected systems from backup
AnswerB

VLAN quarantine or ACLs sever network reachability between the infected hosts and the critical servers sharing that VLAN, halting lateral spread without powering systems off and destroying volatile evidence. This directly satisfies the stem's requirement to minimise impact on the co-located critical servers first.

Why this answer

Isolating the affected systems by applying VLAN quarantine or ACLs is the correct first action because it immediately stops the malware from spreading laterally across the same VLAN to critical servers, while preserving forensic evidence. This network-level containment is faster and less disruptive than account or system-level changes, and it prevents the outbreak from propagating before any remediation begins.

Exam trap

The SSCP exam emphasizes that containment must occur at the network layer first, not at the host or user layer. The trap here is that candidates mistakenly choose to reboot or disable accounts, thinking they are stopping the infection, when in fact they are ignoring the immediate lateral spread risk.

How to eliminate wrong answers

Option A is wrong because disabling user accounts does not stop network-level propagation of malware; the infected systems can still communicate and spread the malware via network protocols even if the user account is disabled. Option C is wrong because rebooting may clear malware from memory but does not prevent reinfection from persistent components or lateral movement, and it can destroy volatile forensic evidence. Option D is wrong because restoring from backup is a recovery step, not a containment step; it should only be performed after the threat is contained and the root cause is understood, to avoid reintroducing the infection.

53
Multi-Selectmedium

A security incident response team is reviewing their disaster recovery plan. They need to ensure that their backup strategy supports recovery from a ransomware attack that encrypts critical files. Which TWO of the following are essential characteristics of an effective backup strategy for this scenario? (Choose two.)

Select 2 answers
A.Backups are stored offline or in an immutable format.
B.Backup restoration procedures are tested regularly.
C.Backups are encrypted with a key stored on the same server.
D.Backups are retained for at least seven years.
E.Backups are performed daily to the same network share.
AnswersA, B

Offline or immutable backups prevent ransomware from encrypting the backup data, ensuring that a clean copy is available for restoration. This is critical because ransomware often targets connected backups. Storing backups offline or using write-once-read-many (WORM) storage ensures that even if the network is compromised, the backups remain intact and can be used to recover.

Why this answer

An effective backup strategy against ransomware must ensure that backups cannot be encrypted by the attacker and that they can be successfully restored. Offline or immutable backups provide protection from encryption, and regular testing verifies that restoration will work when needed. Other factors like retention period or encryption key management are important but not as directly critical for this specific threat.

Exam trap

The trap here is focusing on backup frequency or retention rather than on protecting backups from being encrypted.

54
MCQeasy

During which phase of the NIST SP 800-61 incident response lifecycle are incident response plan updates and lessons learned typically documented?

A.Preparation
B.Containment, Eradication, and Recovery
C.Detection and Analysis
D.Post-Incident Activity
AnswerD

Post-Incident Activity is where the NIST SP 800-61 lifecycle captures lessons learned and revises the incident response plan. This phase explicitly covers reviewing what happened and feeding improvements back into the plan, satisfying the stem's requirement.

Why this answer

The Post-Incident Activity phase of NIST SP 800-61 is specifically designed for conducting lessons learned meetings, documenting improvements, and updating the incident response plan based on findings from the incident. This phase ensures that the organization captures feedback to refine procedures, tools, and training for future incidents.

Exam trap

The trap here is that candidates confuse the Post-Incident Activity phase with the Preparation phase, mistakenly thinking that plan updates occur before incidents, but NIST SP 800-61 explicitly places lessons learned and plan updates after the incident is resolved.

How to eliminate wrong answers

Option A is wrong because the Preparation phase focuses on establishing policies, tools, and training before an incident occurs, not on documenting updates after an incident. Option B is wrong because Containment, Eradication, and Recovery phases are operational steps to stop the incident, remove threats, and restore systems, not for retrospective documentation. Option C is wrong because Detection and Analysis involves identifying and analyzing potential incidents, not capturing lessons learned or updating plans.

55
MCQmedium

An organization has experienced a ransomware attack. After containing the incident, the response team plans to restore systems from backups. Which step is most critical before restoring production systems?

A.Verify the integrity of backup data by restoring to an isolated test environment.
B.Notify law enforcement immediately.
C.Patch the exploited vulnerability and ensure the backup is free of malware.
D.Disconnect all systems from the network.
AnswerC

Correct. Eradication and patching prevent recurrence.

Why this answer

Restoring from backups while the original vulnerability remains unpatched would allow the ransomware to reinfect the systems immediately. Additionally, if the backup itself contains malware (e.g., the ransomware encrypted the backup repository), restoring it would reintroduce the infection. Patching the exploited vulnerability and verifying the backup is clean ensures a safe restoration point, breaking the attack chain.

Exam trap

The trap here is that candidates often choose Option A (verify backup integrity) because it sounds thorough, but they miss that the most critical step is to eliminate the root cause of the infection to prevent immediate reinfection after restoration.

How to eliminate wrong answers

Option A is wrong because verifying backup integrity in an isolated test environment is a good practice but not the most critical step before restoration; the primary risk is reinfection from the same vulnerability or a compromised backup, not data corruption. Option B is wrong because notifying law enforcement is a post-incident legal and compliance step that does not directly prevent reinfection or data loss during restoration; it should occur after containment and evidence preservation, not before restoring systems. Option D is wrong because disconnecting all systems from the network is a containment step that should have been performed earlier in the incident response process; by the time the team plans to restore from backups, containment is already assumed to be complete, and re-disconnecting would hinder the restoration process.

56
MCQmedium

An organization's disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for its critical database. Which of the following DR site configurations BEST meets these requirements?

A.Cold site with weekly backup tapes shipped offsite
B.Cloud-based cold site with daily backups
C.Hot site with synchronous replication
D.Warm site with hourly log shipping to a standby database
AnswerD

Hourly log shipping to a standby database delivers an RPO of roughly one hour, and a warm site can be brought online within the four-hour RTO. Hot sites exceed the requirement at unnecessary cost, while cold sites cannot meet either target.

Why this answer

A warm site with hourly log shipping to a standby database can achieve an RPO of 1 hour (by losing at most one hour of transactions) and an RTO of 4 hours (by applying the logs and bringing the standby online within that window). The standby database is kept nearly current with minimal lag, meeting both recovery objectives without the cost of full synchronous replication.

Exam trap

The trap here is that candidates often choose a hot site (Option C) because it provides the best protection, but the question asks for the configuration that BEST meets the specified RTO/RPO, not the most robust or expensive option, making the warm site the most cost-effective and appropriate choice.

How to eliminate wrong answers

Option A is wrong because a cold site requires hardware setup and restoration from weekly backup tapes, which cannot meet a 4-hour RTO (setup alone often takes days) and the weekly backups exceed the 1-hour RPO (potential data loss of up to a week). Option B is wrong because a cloud-based cold site still requires provisioning resources and restoring from daily backups, which cannot achieve a 4-hour RTO (provisioning and restoration take longer) and the daily backups exceed the 1-hour RPO (potential data loss of up to 24 hours). Option C is wrong because a hot site with synchronous replication provides near-zero RPO and very low RTO (minutes), which over-delivers on the requirements and is unnecessarily expensive; the question asks for the configuration that BEST meets the stated RTO/RPO, not exceeds them with higher cost.

57
Multi-Selecteasy

During the containment phase of incident response, a security analyst identifies malware on a critical server. Which TWO actions should be taken FIRST to contain the threat and preserve evidence? (Choose two.)

Select 2 answers
A.Capture a forensic image of the hard drive.
B.Reboot the server to clear the malware from memory.
C.Disconnect the network cable from the server.
D.Run a full antivirus scan on the server.
E.Capture the contents of RAM using a tool like WinPmem.
AnswersC, E

Disconnecting the network cable immediately severs the malware's command-and-control channel and lateral movement paths, satisfying the containment requirement. Unlike powering down, it preserves volatile memory and running processes, so forensic evidence such as RAM artefacts survives for later analysis. This makes it the fastest physical isolation method for a critical server.

Why this answer

Option C is correct because physically disconnecting the network cable from the server immediately isolates the host, preventing lateral movement, command-and-control callbacks, and data exfiltration while the incident is being contained. Option E is correct because capturing RAM with a tool like WinPmem preserves volatile evidence such as running processes, network connections, injected code, and encryption keys that would be lost on shutdown or reboot, and it should be done before any power state change. Option A is not among the first actions because a full forensic disk image is time-consuming and is typically acquired after volatile memory is preserved and the host is isolated.

Option B is wrong because rebooting destroys volatile memory evidence and may allow malware to re-infect the system or trigger destructive payloads. Option D is wrong because running a full antivirus scan alters system state, can quarantine or delete files, and does not isolate the server from the network, thereby contaminating evidence and leaving the threat active.

Exam trap

SSCP often tests the order of volatility and the containment-vs-eradication distinction; candidates who choose reboot or antivirus scan first confuse eradication/remediation with containment and destroy evidence.

58
MCQmedium

A security analyst receives a user report about a workstation exhibiting unusual behavior, such as unexpected pop-ups and slow performance. The analyst first checks the antivirus logs and finds no alerts. What is the NEXT step in the detection and analysis phase?

A.Escalate the incident to senior management
B.Isolate the workstation from the network immediately
C.Perform a forensic memory capture
D.Classify the severity of the potential incident
AnswerD

With antivirus logs clear, the analyst must still triage the report; classifying severity determines whether it becomes a formal incident and drives escalation and resourcing, which is the next detection-and-analysis action before containment or eradication.

Why this answer

In the detection and analysis phase of incident response, after initial validation and checking antivirus logs, the analyst must classify the severity of the potential incident to determine the appropriate response level and prioritization. Classification guides whether the incident warrants escalation, isolation, or deeper forensic investigation. This step aligns with NIST SP 800-61 and SSCP incident handling principles.

Exam trap

The trap is jumping to containment (isolating the workstation) or escalation because those feel urgent; the exam tests whether you follow the correct sequence where severity classification precedes containment and escalation in the detection and analysis phase.

How to eliminate wrong answers

Option A is wrong because escalating to senior management is premature before the incident has been classified and validated; escalation follows severity determination. Option B is wrong because isolating the workstation is a containment action that belongs to the containment phase, not the detection and analysis phase, and should occur after severity classification. Option C is wrong because performing a forensic memory capture is a detailed investigative step that comes after the incident has been classified and prioritized, not as the immediate next step.

59
MCQmedium

During a full interruption test of the disaster recovery plan, which of the following is the PRIMARY risk?

A.Vendor unavailability during the test
B.Employee confusion about their roles
C.Extended downtime or data loss if the plan fails
D.Cost overruns due to overtime pay
AnswerC

A full interruption test actually shuts down production systems and invokes recovery, so if the plan proves flawed, the organisation suffers real extended downtime or data loss. This is the primary risk that distinguishes it from tabletop or simulation testing.

Why this answer

A full interruption test simulates a complete disaster by actually shutting down the primary site and failing over to the recovery site. The primary risk is that if the recovery plan fails, the organization may experience extended downtime or data loss because the production environment is already down and cannot be quickly restored. This directly impacts business continuity and is the most severe consequence.

Exam trap

SSCP often tests the distinction between the primary risk of a full interruption test (extended downtime/data loss) and secondary risks like cost or employee confusion, which are less critical.

How to eliminate wrong answers

Option A is wrong because vendor unavailability is a secondary concern; while it could hinder the test, it does not directly cause downtime or data loss. Option B is wrong because employee confusion about roles is a people/process risk that can be mitigated with training and documentation, but it is not the primary risk of a full interruption test. Option D is wrong because cost overruns due to overtime pay are a financial concern, not the primary operational risk of extended downtime or data loss.

60
MCQmedium

A security analyst detects a workstation communicating with a known command-and-control server. The workstation is running critical applications. What should be the analyst's first step according to the NIST incident response lifecycle?

A.Power off the workstation immediately to stop the communication.
B.Isolate the workstation from the network while preserving volatile data.
C.Run a full antivirus scan on the workstation.
D.Notify management and wait for instructions.
AnswerB

Isolation stops the workstation communicating with the command-and-control server, containing the compromise, while preserving volatile data such as memory and active connections for later forensic analysis. This aligns with the NIST lifecycle's containment objective before eradication.

Why this answer

According to the NIST incident response lifecycle, the first priority is containment. Isolating the workstation from the network stops communication with the command-and-control server while preserving volatile data (e.g., memory, running processes, network connections) for forensic analysis. Powering off would destroy this critical evidence, and running a scan or waiting for instructions delays containment and risks further compromise.

Exam trap

A common misconception in incident response is that immediate power-off is the safest containment action, but the trap is that it destroys volatile evidence required for forensic analysis, as emphasized in the NIST incident response lifecycle and SSCP exam objectives.

How to eliminate wrong answers

Option A is wrong because powering off the workstation destroys volatile data (e.g., RAM contents, active network connections, process lists) that are essential for forensic analysis and identifying the scope of the compromise. Option C is wrong because running a full antivirus scan on a live, compromised system can alter evidence, trigger destructive malware behaviors, and does not immediately stop the command-and-control communication. Option D is wrong because notifying management and waiting for instructions violates the NIST principle of immediate containment; delaying action allows the attacker to continue exfiltration or lateral movement.

61
MCQmedium

A security analyst receives an alert from the EDR system indicating that a workstation has been communicating with a known malicious IP address. The analyst confirms the alert and notes that the user is still logged in. Which immediate containment action should the analyst take FIRST?

A.Isolate the workstation using the EDR agent's network isolation capability
B.Create a full forensic image of the hard drive
C.Disable the user's Active Directory account
D.Block the malicious IP address at the firewall
AnswerA

EDR network isolation severs the workstation's connections while preserving the agent's management channel and volatile evidence, halting command-and-control traffic and potential lateral movement. This contains the confirmed compromise immediately, before the still-logged-in user or malware can cause further damage.

Why this answer

Network isolation via the EDR agent is the fastest, least disruptive containment action that stops the active command-and-control channel while preserving volatile memory and forensic artifacts on the host. It cuts the malicious traffic immediately without tipping off the attacker through account lockouts or firewall changes that might be noticed. This aligns with the containment phase of incident response, where speed and evidence preservation are both prioritized.

Exam trap

The trap is confusing 'containment' with 'eradication' or 'evidence collection' — candidates often pick forensic imaging or firewall blocking because those sound thorough, but the question asks for the FIRST immediate containment action.

How to eliminate wrong answers

Option B is wrong because creating a full forensic image is a preservation/collection step that takes significant time and does nothing to stop the ongoing malicious communication — containment must precede deep forensics. Option C is wrong because disabling the AD account does not stop the malware already running on the workstation from continuing to beacon out, and it may alert the attacker or disrupt the user's other sessions before evidence is gathered. Option D is wrong because blocking a single IP at the firewall is a network-perimeter action that only addresses one indicator; the malware could use DGA domains, other C2 IPs, or encrypted channels, and it leaves the compromised host free to move laterally.

62
MCQmedium

An organization's disaster recovery plan specifies an RPO of 4 hours and an RTO of 24 hours for a critical database. Which of the following best describes these metrics?

A.RPO means up to 4 hours of data loss; RTO means the database must be recovered within 24 hours.
B.RPO means recovery point objective; RTO means recovery time objective.
C.RPO means the database can be down for up to 4 hours; RTO means up to 24 hours of data loss.
D.RPO means the database must be recovered within 4 hours; RTO means up to 24 hours of data loss.
AnswerA

RPO defines the maximum tolerable data loss measured in time, so four hours means the recovery point may lose up to four hours of transactions. RTO defines the maximum acceptable downtime, so the database must be operational again within 24 hours of disruption.

Why this answer

RPO (Recovery Point Objective) defines the maximum acceptable data loss measured in time, meaning up to 4 hours of transactions could be lost. RTO (Recovery Time Objective) defines the maximum acceptable downtime, meaning the database must be fully operational within 24 hours after a disaster.

Exam trap

The trap here is confusing RPO with downtime and RTO with data loss, leading candidates to swap the definitions or misassign the time values.

How to eliminate wrong answers

Option B is wrong because it merely expands the acronyms without explaining the practical meaning of the metrics (e.g., it doesn't state that RPO is about data loss and RTO is about downtime). Option C is wrong because it reverses the definitions: RPO is about data loss, not downtime, and RTO is about downtime, not data loss. Option D is wrong because it swaps the values: RPO is 4 hours of data loss, not recovery time, and RTO is 24 hours of downtime, not data loss.

63
Multi-Selectmedium

A security analyst is investigating a phishing incident that led to credential theft. Which TWO actions are appropriate during the containment phase? (Select TWO)

Select 2 answers
A.Reset the compromised user's password
B.Update the incident response plan
C.Conduct a lessons learned meeting
D.Restore the user's machine from backup
E.Block the phishing domain at the email gateway
AnswersA, E

Resetting the password immediately invalidates the stolen credentials, cutting off the attacker's authenticated access before they can pivot or exfiltrate further. This directly satisfies the containment phase's goal of limiting damage while the phishing incident is still active.

Why this answer

Option A is correct because resetting the compromised user's password immediately invalidates the stolen credentials, preventing the attacker from continuing to use the phished account during containment. Option E is correct because blocking the phishing domain at the email gateway stops further phishing emails from that domain reaching other users, limiting the spread of the incident. Option B is not a containment action; updating the incident response plan is a post-incident improvement activity.

Option C is also post-incident, as lessons learned meetings occur after eradication and recovery to improve future response. Option D is a recovery action, since restoring from backup is used to return systems to normal operation after the threat is contained and removed.

Exam trap

In the SSCP exam, candidates often confuse the containment phase with recovery or other phases. A common mistake is selecting actions like restoring from backup (recovery) or conducting lessons learned (post-incident), instead of immediate containment steps such as password resets or blocking malicious infrastructure.

64
MCQmedium

A security analyst is reviewing alerts and sees that a user's workstation has begun encrypting files with a new extension, and a ransom note has appeared on the desktop. The analyst confirms this is an active ransomware infection. According to NIST SP 800-61, which action should the analyst take FIRST during the containment phase?

A.Immediately disconnect the workstation from the network by unplugging the Ethernet cable or disabling Wi-Fi.
B.Shut down the workstation immediately to stop the encryption process.
C.Pay the ransom to obtain the decryption key and restore files quickly.
D.Run a full antivirus scan on the workstation to remove the ransomware.
AnswerA

Isolating the infected workstation from the network is the immediate priority in the containment phase to prevent the ransomware from spreading to shared drives and other systems. Disconnecting the network stops lateral movement and further encryption of network resources, while preserving the local state for later forensic analysis. This aligns with NIST SP 800-61 guidance to limit the scope and magnitude of the incident before proceeding with eradication and recovery.

Why this answer

During an active ransomware incident, the first containment action is to isolate the infected system from the network to prevent lateral spread and further encryption of shared resources. This aligns with NIST SP 800-61, which emphasizes limiting the scope of the incident before eradication and recovery. Disconnecting the network preserves volatile evidence while stopping the malware's communication and propagation.

Other actions like scanning, shutting down, or paying the ransom do not address immediate containment and may hinder forensic efforts.

Exam trap

The trap here is assuming that shutting down the machine or running antivirus is the fastest way to stop ransomware, when in fact network isolation must come first to prevent spread and preserve evidence.

65
Multi-Selectmedium

An organization has suffered a ransomware attack that encrypted files on several file servers. The incident response team is planning recovery. Which TWO actions should be performed to verify that the restored systems are clean before returning them to production? (Select TWO)

Select 2 answers
A.Restore the systems from the most recent backup
B.Change all user passwords associated with the systems
C.Run a full antivirus and anti-malware scan on the restored systems
D.Apply all security patches to the operating system
E.Monitor the systems for any signs of reinfection or anomalous behavior for a period of time
AnswersC, E

Scanning restored systems with current antivirus and anti-malware signatures detects any residual malware, backdoors or dormant payloads the ransomware may have left behind. This directly satisfies the stem's requirement to verify systems are clean before returning them to production.

Why this answer

Option C is correct because running a full antivirus and anti-malware scan on the restored systems is a direct verification step that checks the restored data and OS for any residual malware, ransomware payloads, or infected files before the systems are trusted again. Option E is correct because monitoring the restored systems for reinfection or anomalous behavior over a period of time provides ongoing validation that no dormant persistence mechanisms, scheduled tasks, or command-and-control callbacks survived the recovery process. Option A is not a verification action; restoring from the most recent backup is a recovery step, and that backup itself may contain the ransomware or an earlier compromise.

Option B does not verify system cleanliness; changing user passwords is a containment/credential-hygiene measure and does nothing to detect malware on the restored hosts. Option D is also not a verification step; applying OS security patches remediates known vulnerabilities but does not confirm that the restored systems are free of the ransomware or other malware.

Exam trap

The trap here is that candidates often assume restoring from a clean backup (Option A) is sufficient to guarantee a clean system, but the SSCP exam emphasizes that backups must be verified as malware-free and that additional validation steps (scanning and monitoring) are required before returning systems to production.

66
MCQmedium

A healthcare organization's incident response team has just contained a ransomware outbreak that encrypted several file servers. Before restoring from backups, the incident response manager wants to ensure that the team can determine exactly how the attacker initially gained access and what data was exfiltrated. The organization does not have a dedicated forensic imaging solution, but the servers are still powered on and running. Which of the following actions BEST supports the investigation while preserving evidence?

A.Run a full antivirus scan on each server and quarantine any detected malware, then review the scan reports.
B.Immediately power off the servers to prevent further encryption, then remove the hard drives for later analysis.
C.Capture a memory image and relevant logs from the running servers, then isolate them from the network before restoration.
D.Restore the servers from the most recent backup immediately, then review backup logs to identify the initial compromise.
AnswerC

Capturing volatile data like memory and logs while the systems are still running preserves critical evidence about the attacker's tools, credentials, and network connections. Isolating the servers prevents further damage without destroying evidence. This approach aligns with incident response best practices by balancing containment and forensic preservation, enabling the team to determine initial access and exfiltration methods before restoring from backups.

Why this answer

The best action is to capture volatile evidence such as memory and logs from the running servers before isolating them. This preserves critical artifacts that reveal the attacker's methods and data exfiltration while preventing further damage. Restoring from backup or powering off the servers would destroy evidence, and antivirus scanning could alter the compromised state, undermining the investigation's goals.

Exam trap

The trap here is assuming that containment always requires immediately powering off or restoring systems, which destroys volatile evidence needed to determine the root cause and scope of the incident.

67
MCQmedium

During a forensic investigation, an examiner creates a bit-for-bit copy of a hard drive using a write blocker. What is the purpose of using a write blocker?

A.To prevent modification of the original evidence
B.To encrypt the data during transfer
C.To speed up the imaging process
D.To verify the hash of the original drive
AnswerA

A write blocker intercepts write commands at the hardware or driver level, allowing the examiner to read the drive while blocking any modification. This preserves the original evidence's integrity so the bit-for-bit copy remains forensically sound and admissible.

Why this answer

A write blocker is a hardware or software device that intercepts and blocks any write commands from the forensic workstation to the source drive, ensuring that the original evidence remains unaltered during acquisition. This is critical for maintaining the integrity and admissibility of digital evidence in legal proceedings, as any modification could compromise the chain of custody and forensic soundness.

Exam trap

ISC2 often tests the misconception that write blockers are used for encryption or speed optimization, but the core purpose is strictly write prevention to preserve evidence integrity.

How to eliminate wrong answers

Option B is wrong because write blockers do not encrypt data; encryption is a separate process typically handled by forensic tools or software after acquisition, and a write blocker's sole function is to prevent writes. Option C is wrong because write blockers do not speed up imaging; in fact, they may introduce a slight overhead due to command filtering, and imaging speed is primarily determined by the drive interface and the imaging tool. Option D is wrong because verifying the hash of the original drive is a post-imaging step performed by the examiner using hashing algorithms like SHA-256 or MD5, not a function of the write blocker itself.

68
MCQmedium

An analyst detects suspicious outbound traffic from a server to a known command-and-control IP address. According to NIST SP 800-61, which phase of the incident response lifecycle does this activity fall under?

A.Post-Incident Activity
B.Preparation
C.Containment, Eradication, and Recovery
D.Detection and Analysis
AnswerD

Detecting suspicious outbound traffic to a known command-and-control IP is the identification of a potential security event, which NIST SP 800-61 places squarely within Detection and Analysis. This phase covers monitoring, triage and validating whether activity constitutes a genuine incident before containment begins.

Why this answer

The detection of suspicious outbound traffic to a known command-and-control IP address is a clear indicator of a potential security incident. According to NIST SP 800-61, this activity falls under the 'Detection and Analysis' phase, which involves identifying and validating that an incident has occurred through monitoring, alerting, and analysis of security events.

Exam trap

ISC2 SSCP often tests the distinction between 'Detection and Analysis' and 'Containment, Eradication, and Recovery' by presenting a detection event and expecting candidates to recognize that containment actions are separate and occur later in the lifecycle.

How to eliminate wrong answers

Option A is wrong because 'Post-Incident Activity' occurs after the incident has been contained and eradicated, focusing on lessons learned and reporting, not on initial detection. Option B is wrong because 'Preparation' involves establishing policies, tools, and training before an incident occurs, not detecting active malicious traffic. Option C is wrong because 'Containment, Eradication, and Recovery' are actions taken after detection to stop the spread, remove the threat, and restore systems, not the initial identification of suspicious traffic.

69
Multi-Selecteasy

Which TWO metrics are commonly tracked to measure the effectiveness of the incident response process? (Select TWO)

Select 2 answers
A.MTTD (Mean Time to Detect)
B.SLA (Service Level Agreement) compliance percentage
C.MTBF (Mean Time Between Failures)
D.MTTR (Mean Time to Respond)
E.Number of firewall rules
AnswersA, D

MTTD measures the elapsed time from incident occurrence to detection, quantifying how quickly monitoring and alerting identify threats. Tracking it exposes gaps in detection capability and is a core effectiveness metric alongside containment and recovery times.

Why this answer

MTTD (Mean Time to Detect) is correct because it directly measures how quickly an organization identifies an incident after it occurs, which is a core indicator of incident response effectiveness in the detection phase. MTTR (Mean Time to Respond) is correct because it measures how quickly the team responds to and contains or resolves an incident, reflecting the efficiency of the response process. Together, MTTD and MTTR are standard incident response metrics used to benchmark and improve detection and response capabilities.

SLA compliance percentage is not specific to incident response effectiveness, as SLAs cover many service areas beyond security incidents. MTBF (Mean Time Between Failures) measures reliability of systems or components, not incident response performance. The number of firewall rules is a configuration or hygiene metric and does not measure how well incidents are detected or handled.

Exam trap

ISC2 often tests the distinction between operational metrics (MTTD, MTTR) and reliability metrics (MTBF) or configuration counts, so candidates mistakenly select MTBF or firewall rules because they sound technical but are irrelevant to incident response effectiveness.

70
Multi-Selectmedium

During the preparation phase of incident response, which TWO components are essential for an effective incident response plan? (Select TWO)

Select 2 answers
A.A list of approved vendors for hardware replacement
B.A list of all employee passwords
C.A communication plan with contact information for key stakeholders
D.Network topology diagrams
E.Detailed recovery procedures for each critical system
AnswersC, E

A communication plan with stakeholder contact details satisfies the coordination constraint during preparation, ensuring the right people are reachable the moment an incident is declared. Without predefined escalation paths and contacts, response stalls while responders hunt for decision-makers, delaying containment and violating the plan's requirement for clear internal and external notification procedures.

Why this answer

Option C is correct because an incident response plan must include a communication plan with up-to-date contact information for key stakeholders (e.g., incident handlers, management, legal, PR, and law enforcement) so that notifications and escalations occur quickly and in the proper order during an incident. Option E is correct because detailed recovery procedures for each critical system provide the documented, tested steps (such as restoration order, RTO/RPO targets, and system-specific rebuild or failover instructions) needed to return operations to normal after containment and eradication. Option A is not essential to the plan itself, since vendor lists support logistics but are not a core IR plan component.

Option B is incorrect and a security risk, as storing all employee passwords violates least privilege and credential-management best practices. Option D, while useful for scoping and containment, is supporting documentation rather than one of the two essential components emphasized here.

Exam trap

The trap here is that candidates may confuse operational logistics (like vendor lists or network diagrams) with the core structural components of an incident response plan, which must prioritize communication and recovery to enable a coordinated and effective response.

71
MCQeasy

During the preparation phase of the incident response lifecycle, which of the following is the MOST important component to establish?

A.Communication plan
B.Incident response plan
C.Incident response team
D.Forensic analysis tools
AnswerB

The incident response plan defines roles, escalation paths, communication channels and procedures before an incident occurs, so responders act consistently rather than improvising. This satisfies the stem's requirement for the most important preparation-phase component, underpinning every later lifecycle phase.

Why this answer

The incident response plan is the foundational document that outlines the entire process, including roles, procedures, and escalation paths. Without a formal, approved plan, other components like the communication plan, team, or tools lack the necessary structure and authority to function effectively during an incident.

Exam trap

ISC2 SSCP often tests the misconception that the incident response team is the most important component, but without a formal plan, the team lacks defined roles, authority, and procedures to act effectively.

How to eliminate wrong answers

Option A is wrong because a communication plan is a subset of the incident response plan; it cannot be established effectively without the overarching plan defining who communicates what and when. Option C is wrong because the incident response team is a resource that is assembled and trained based on the plan's requirements, not the primary component to establish first. Option D is wrong because forensic analysis tools are tactical resources selected after the plan defines the investigation procedures and legal requirements, not the most important preparatory component.

72
Multi-Selectmedium

A security analyst is reviewing the organization's incident response plan and wants to ensure it includes the necessary elements for the preparation phase according to NIST SP 800-61. Which of the following should be included in the preparation phase? (Choose two.)

Select 2 answers
A.Eradicating malware from infected systems.
B.Recovering data from backups.
C.Developing an incident response policy that defines roles and responsibilities.
D.Establishing a communication plan with internal and external stakeholders.
E.Conducting a lessons learned meeting after an incident.
AnswersC, D

An incident response policy is a foundational element of the preparation phase. It establishes the authority, scope, and responsibilities for incident response, ensuring that all stakeholders understand their roles. NIST SP 800-61 specifically lists the creation of an incident response policy as a key preparation activity, as it provides the framework for the entire incident response lifecycle.

Why this answer

The preparation phase of the NIST SP 800-61 incident response lifecycle includes activities that establish the capability to respond to incidents. This includes creating an incident response policy that defines roles and responsibilities, and establishing a communication plan with stakeholders. These elements ensure the organization is ready to detect, analyze, and respond to incidents effectively.

Exam trap

The trap here is confusing activities from other phases, such as lessons learned, eradication, or recovery, with preparation phase elements.

73
Multi-Selectmedium

An incident response team is preparing to collect evidence from a compromised Linux web server. The team lead wants to ensure that the evidence will be admissible in a potential legal proceeding. Which TWO actions should the team take to maintain the integrity of the evidence? (Choose two.)

Select 2 answers
A.Document the chain of custody for each evidence item.
B.Analyze the original evidence directly to avoid any copy-related discrepancies.
C.Compute and record cryptographic hashes of the evidence before and after analysis.
D.Allow all team members to access the evidence freely for efficiency.
E.Store evidence on the compromised server to maintain original context.
AnswersA, C

A chain of custody documents who handled the evidence, when, and for what purpose, which is essential for admissibility. Without it, opposing counsel can challenge whether the evidence was tampered with or altered. In this scenario, documenting custody for each item collected from the Linux server establishes an unbroken record that supports the evidence's integrity in legal proceedings.

Why this answer

Maintaining evidence integrity requires documenting the chain of custody and using cryptographic hashes to verify that data has not changed. These practices ensure that evidence collected from the compromised Linux server can withstand legal scrutiny. Analyzing originals, storing evidence on the compromised system, or allowing unrestricted access all undermine integrity and admissibility.

Exam trap

The trap here is assuming that analyzing the original evidence is more accurate, when in fact it risks altering the evidence and breaking the chain of custody.

74
Multi-Selectmedium

A security analyst is reviewing the incident response plan and wants to ensure the containment strategy is effective for a recent malware outbreak. The analyst must choose containment measures that align with NIST SP 800-61. Which TWO actions are appropriate containment strategies? (Choose two.)

Select 2 answers
A.Restoring the infected systems from a known good backup
B.Immediately deleting all files created in the last 24 hours on the infected systems
C.Applying a temporary firewall rule to block command-and-control traffic
D.Conducting a lessons learned meeting with the incident response team
E.Disconnecting the infected systems from the network
AnswersC, E

Blocking command-and-control traffic via firewall rules is a containment technique that cuts off attacker communication without necessarily disconnecting all systems. NIST SP 800-61 supports using network controls to contain incidents. This approach can be more surgical than full isolation, allowing business operations to continue while preventing further malicious activity. It is a valid containment strategy.

Why this answer

Containment strategies in NIST SP 800-61 focus on limiting the scope and impact of an incident. Disconnecting infected systems and blocking command-and-control traffic both prevent further spread or attacker communication. Deleting files, restoring backups, and holding lessons learned meetings are eradication, recovery, or post-incident activities, not containment.

The two correct actions directly stop the incident from expanding while analysis continues.

Exam trap

The trap here is confusing eradication and recovery actions with containment, when containment specifically aims to stop the spread without necessarily removing the threat.

75
MCQeasy

After a major security incident, an organization's incident response team conducts a lessons learned meeting. The team identifies that the communication plan was unclear, leading to delays in notifying stakeholders. Which of the following should be the PRIMARY outcome of this meeting?

A.A set of actionable recommendations to update the incident response plan and improve future response efforts.
B.A decision to terminate the employees who failed to follow the communication plan.
C.An immediate upgrade of all security tools to prevent similar communication failures.
D.A formal report documenting the incident timeline and the names of individuals responsible for the delays.
AnswerA

The primary purpose of a lessons learned meeting is to identify what went well and what needs improvement, then produce actionable recommendations to enhance the incident response plan. This includes clarifying communication procedures, roles, and escalation paths. The outcome should be a documented set of changes that can be implemented and tested. This directly addresses the identified communication delays and helps prevent recurrence.

Why this answer

The primary outcome of a lessons learned meeting is a set of actionable recommendations to improve the incident response plan, including communication procedures. This ensures that identified weaknesses are addressed systematically. Documenting blame, terminating employees, or immediately upgrading tools do not directly resolve the process gaps and may not prevent future communication delays.

Exam trap

The trap here is focusing on punitive measures or tool purchases instead of process improvements, which are the true goal of a lessons learned meeting.

Page 1 of 2 · 83 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Sscp Incident Response questions.