
Certified Information Systems Security Professional
Domain 7Objective 6
7.6 - Conduct Incident Management CISSP Practice Questions (Page 5)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
7concepts
13%of the exam
Questions 21–25
- 21
After a ransomware incident, the incident response team has contained the spread and eradicated the malware. The organization is now ready to restore operations. Which of the following is the MOST critical step in the recovery process?
Select an answer first - 22
Which technique is used to reduce the impact of a malware outbreak by preventing it from spreading to other network segments?
Select an answer first - 23
Which of the following is an immediate action taken during incident response to limit the scope of an ongoing attack?
Select an answer first - 24
A security analyst notices that a user account has been locked out multiple times in a short period. The analyst suspects a brute-force attack. What is the BEST immediate action?
Select an answer first - 25
After a significant security incident, the incident response team is conducting a post-incident review. What is the PRIMARY purpose of this review?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.