hardMultiple Select
SSCP Practice Question: Which THREE steps are essential during the…
Which THREE steps are essential during the identification phase of incident response?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Monitor logs and alerts
During the identification phase of incident response, the essential steps are monitoring logs and alerts (C) to detect potential incidents, determining the scope of the incident (D) to understand its impact, and classifying incident severity (E) to prioritize response. Options A and B are not part of identification; eradication occurs later in the response phase, and stakeholder notification typically happens after identification and analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Eradicate the threat
Why it's wrong here
Eradication occurs after identification and containment.
- ✗
Notify stakeholders
Why it's wrong here
Notification belongs to the containment, eradication, recovery and post-incident communication activities, not identification. It is tempting because stakeholders must eventually be told, and in a major incident with regulatory disclosure duties, early notification would be the correct action — but the identification phase is confined to detecting and validating the event.
- ✓
Monitor logs and alerts
Why this is correct
Continuous log and alert monitoring detects anomalies and indicators of compromise, satisfying the identification phase's need to spot potential incidents early. Without this visibility, analysts cannot distinguish genuine security events from benign activity, so triage and escalation would lack the evidence required to confirm an incident.
- ✓
Determine scope of incident
Why this is correct
Determining scope establishes which systems, accounts and data the compromise has touched, directly satisfying the identification phase's requirement to understand the incident's extent before containment. Without this boundary, responders cannot prioritise evidence collection or assess business impact, making scoping an essential identification activity alongside detection and validation.
- ✓
Classify incident severity
Why this is correct
Classifying severity assigns priority based on business impact and urgency, satisfying the identification phase's requirement to determine how an incident should be handled. This rating drives escalation paths, resource allocation and response timelines, ensuring the most damaging incidents receive attention before lower-impact events.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.