hardMultiple Select
SSCP Practice Question: Which THREE of the following are key elements of…
Which THREE of the following are key elements of a security incident response plan?
⚠ Common exam trap
ISC2 often tests the misconception that 'restoring all systems from backup' is a standalone key element, when in fact it is a sub-step of the recovery phase and must be preceded by containment and eradication to avoid reinfection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preparation and training
The three correct answers are B, D, and E because they map directly to the core phases of the NIST SP 800-61 incident response lifecycle. B (Preparation and training) is right because preparation establishes the IR policy, tools, communication paths, and team readiness—including training and exercises—before an incident occurs. E (Detection and analysis) is right because it covers identifying and validating potential incidents and determining their scope, impact, and root cause. D (Containment, eradication, and recovery) is right because it covers limiting damage, removing the threat, and restoring normal operations. A (Vendor management process) is not a core IR phase—it is a supporting governance activity—and C (Restoring all systems from backup) is too narrow and potentially wrong, since recovery is selective and validated, not a blanket restore of every system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vendor management process
Why it's wrong here
Vendor management governs third-party risk and contracts, not the structured phases of handling a live security incident. It is tempting because supply-chain compromise is a genuine incident source, and vendor processes support risk management generally. Incident response planning instead addresses preparation, detection, analysis, containment, eradication, recovery, and lessons learned.
- ✓
Preparation and training
Why this is correct
Preparation and training build the capability required before an incident occurs, ensuring personnel know their roles, escalation paths and containment procedures. This satisfies the stem's demand for a key element, since an untested plan fails under pressure; readiness depends on rehearsed response rather than documentation alone.
- ✗
Restoring all systems from backup
Why it's wrong here
Restoring from backup is a recovery action performed after containment and eradication, not a planning element. It is tempting because backups are essential to business continuity and disaster recovery, where restoration is indeed the central activity. Incident response planning instead covers preparation, detection, containment, eradication, and post-incident review.
- ✓
Containment, eradication, and recovery
Why this is correct
Containment, eradication, and recovery form the core incident-handling phases that limit damage, remove the threat, and restore normal operations. They directly satisfy the stem's requirement for key plan elements, sitting within the response lifecycle alongside preparation, detection and analysis, and post-incident activity.
- ✓
Detection and analysis
Why this is correct
Detection and analysis is a core phase of the incident response lifecycle, covering monitoring, alert triage and determining an incident's scope and impact. It satisfies the stem's requirement for a key plan element by enabling teams to identify and validate security events before containment, eradication and recovery can be initiated.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.