Courseiva
mediumMultiple Select

SSCP Practice Question: Which TWO actions are part of the containment…

Which TWO actions are part of the containment phase of incident response?

⚠ Common exam trap

ISC2 often tests the distinction between containment actions (immediate stop-gap measures) and recovery or analysis actions, so candidates mistakenly select 'restoring from backups' or 'analyzing root cause' as containment steps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Applying temporary patches

During the containment phase of incident response, the immediate priority is to stop the incident from spreading or causing further damage. Applying temporary patches (C) can quickly close a vulnerability that is being exploited, while isolating affected systems (D) prevents lateral movement and further compromise. Both actions are short-term measures to contain the threat before eradication and recovery begin.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restoring from backups

    Why it's wrong here

    Restoring from backups is a recovery-phase activity, performed after the threat is eradicated. Containment instead isolates affected systems to stop propagation. Tempting because backups feel protective, but restoration assumes the environment is already clean and controlled.

  • ✗

    Analyzing root cause

    Why it's wrong here

    Root-cause analysis is part of the post-incident review, not containment. Containment stops the incident spreading; analysis explains it afterwards. Tempting because understanding the cause feels urgent during an incident, but it occurs once systems are stabilised.

  • ✓

    Applying temporary patches

    Why this is correct

    Temporary patches close the exploited vulnerability on production systems, halting ongoing compromise without full remediation. This satisfies containment by stopping the attack's spread, whereas permanent patching belongs to eradication once the threat is fully removed.

  • ✓

    Isolating affected systems

    Why this is correct

    Isolation severs an affected system's network connectivity, preventing lateral movement and further compromise while forensic work continues. This directly satisfies the containment phase's goal of limiting incident scope, distinct from eradication, which removes the root cause.

  • ✗

    Preserving evidence

    Why it's wrong here

    Preserving evidence belongs to the post-incident or investigation phase, where forensic integrity supports later analysis or legal action. Containment instead stops the spread, such as isolating hosts or disabling accounts. It is tempting because evidence handling often begins during containment, but it is not itself a containment action.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.