Courseiva

SSCP · topic practice

Incident Response and Recovery practice questions

This domain covers the SSCP incident response lifecycle: preparation, detection and analysis, containment, eradication, recovery, and post-incident lessons learned. Questions test your judgment on ordering actions correctly, selecting containment scope, using evidence-handling and forensic practices, and aligning response with business continuity and disaster recovery priorities.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Incident Response and Recovery

What the exam tests

What to know about Incident Response and Recovery

Be able to sequence incident response phases correctly and pick the right containment action first. The single most important thing: contain the threat before eradicating or recovering, while preserving evidence and following the IR plan.

Ordering the IR lifecycle phases and selecting preparation components like an IR plan and trained response team

Choosing containment scope (isolate host, segment network, disable account) to stop lateral movement

Applying evidence handling and chain of custody so forensic artifacts remain admissible

Distinguishing incident response from business continuity and disaster recovery roles and triggers

Watch out for

Common Incident Response and Recovery exam traps

  • ▸Jumping straight to eradication or recovery before containing the threat, letting the adversary spread further
  • ▸Confusing business continuity (keep operations running) with disaster recovery (restore IT systems) when choosing the right plan
  • ▸Treating lessons learned as blame assignment instead of process improvement, missing the primary purpose

Practice set

Incident Response and Recovery questions

20 questions · select your answer, then reveal the explanation

An organization's security team detects a potential data breach. After confirming the incident, they classify it as P2 (high severity) and begin containment. Which action should be performed FIRST to preserve evidence for forensic analysis?

During a forensic investigation, an examiner needs to preserve volatile evidence. Which of the following lists the correct order of collection for volatile data?

Which of the following is the FIRST step in the volatile evidence collection order when responding to an incident on a live system?

During the eradication phase of incident response, which of the following actions is MOST critical to ensure the threat is completely removed from a compromised system?

An incident responder is tasked with collecting forensic evidence from a compromised Linux server. Which command would the responder use to capture the contents of volatile memory (RAM) for analysis?

After containing a ransomware incident, the incident response team identifies that the attacker gained initial access through a phishing email that installed a backdoor. Which of the following eradication steps is MOST critical to prevent re-infection?

During the detection and analysis phase, an analyst classifies an incident as P1 (critical) because it involves a breach of sensitive customer data. What is the IMMEDIATE next step the analyst should take?

During a forensic investigation, a responder must collect evidence from a live Windows system. Which of the following represents the correct order for collecting volatile data?

An incident responder is handling a malware outbreak. The malware has been identified as a fileless threat that persists via registry run keys. Which eradication step is most appropriate?

A company is selecting a disaster recovery site for its critical applications. Which THREE characteristics differentiate a warm site from a cold site? (Select three.)

An organization uses a hot disaster recovery (DR) site and has a Recovery Time Objective (RTO) of 4 hours. During a DR test, the team discovers that data replication from the primary site fails. Which TWO actions should the team take to meet the RTO while ensuring data integrity? (Choose two.)

A security operations center (SOC) analyst receives an alert that a user's laptop has been infected with ransomware. The analyst confirms the infection and isolates the laptop from the network. According to NIST SP 800-61, which of the following should the analyst do NEXT?

A security analyst is preparing an incident response plan for a financial institution that must comply with PCI DSS. The organization wants to ensure that its incident response activities are aligned with a recognized industry framework. Which of the following frameworks should the analyst use as the PRIMARY reference for structuring the incident response lifecycle?

An analyst is reviewing a network packet capture of an intrusion and needs to determine the source of an attack. The capture shows a TCP session with a source IP of 192.168.1.50, a destination IP of 10.0.0.5, and a destination port of 22. The analyst knows that 10.0.0.5 is an internal server. Which of the following should the analyst do FIRST to identify the true source of the attack?

A forensic examiner is preparing to acquire a forensic image of a running Windows server. The examiner wants to ensure that the evidence is admissible in court. Which of the following should the examiner do FIRST?

A security analyst is reviewing logs and discovers that a user account with administrative privileges was used to access a sensitive file server outside of normal business hours. The account belongs to an IT administrator who is on vacation. The analyst suspects credential compromise. According to NIST SP 800-61, which of the following actions should be taken FIRST?

A security team is conducting a post-incident review after a ransomware attack. They are analyzing the effectiveness of their incident response plan. Which TWO of the following activities are part of the post-incident activity phase according to NIST SP 800-61? (Choose two.)

A security analyst is creating a disaster recovery plan for a critical application. The application has a Recovery Time Objective (RTO) of 2 hours and a Recovery Point Objective (RPO) of 15 minutes. Which of the following backup strategies would BEST meet these requirements?

An incident responder is analyzing a compromised Linux server. The responder needs to determine which user accounts were recently created or modified. Which of the following commands should the responder use to review the account creation and modification timestamps?

During which phase of the NIST SP 800-61 incident response lifecycle are incident response plan updates and lessons learned typically documented?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Incident Response and Recovery sessions

Start a Incident Response and Recovery only practice session

Every question in these sessions is drawn from the Incident Response and Recovery domain — nothing else.

Related practice questions

Related SSCP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SSCP exam test about Incident Response and Recovery?
Be able to sequence incident response phases correctly and pick the right containment action first. The single most important thing: contain the threat before eradicating or recovering, while preserving evidence and following the IR plan.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Incident Response and Recovery questions in a focused session?
Yes — the session launcher on this page draws every question from the Incident Response and Recovery domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SSCP topics?
Use the topic links above to move to related areas, or go back to the SSCP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SSCP exam covers. They are not copied from any real exam or dump site.