
Certified in Cybersecurity
Domain 2Objective 3
2.3 - Understand Incident Response CC Practice Questions (Page 6)
Part of the Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts domain, which accounts for 10% of the CC exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 2–3 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
9concepts
10%of the exam
Questions 26–30
- 26
Which incident response phase involves actions taken to stop the spread of an incident and limit damage?
Select an answer first - 27
After a phishing incident is contained and eradicated, the incident response team holds a meeting to discuss what went well, what did not, and what could be improved. Which post-incident activity is this, and why is it important?
Select an answer first - 28
A SOC analyst receives an alert about a possible malware infection on a server. The analyst reviews the alert, checks the server's recent process activity, and determines that the file is a false positive. Which phase of incident response is the analyst performing?
Select an answer first - 29
A security analyst is investigating a potential data breach. The analyst finds that an attacker used a compromised account to access sensitive data. The analyst wants to determine the scope of the breach. Which action would best help the analyst determine the scope?
Select an answer first - 30
A malware infection is confirmed on several servers. The incident response team has isolated the affected servers and identified the malicious files. What should the team do next to ensure the threat is completely removed and the systems can be safely restored?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CC” is a trademark of its owner, used for identification only.