
Systems Security Certified Practitioner
Domain 4Objective 1
4.1 - Understand and Support Incident Response Lifecycle (e.g., National Institute of Standards and Technology (NIST), International Organization for Standardization (ISO)) SSCP Practice Questions (Page 1)
Part of the Incident Response and Recovery domain, which accounts for 14% of the SSCP exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
14%of the exam
Questions 1–5
- 1
An organization is updating its incident response plan. The CISO wants to ensure that during an incident, the right people are notified quickly and that the response team knows their specific roles. Which action is MOST important to include in the preparation phase?
Select an answer first - 2
A company has just finished eradicating a malware infection from its file servers. The incident response team is now in the recovery phase. Which activity is MOST critical to perform before returning the servers to production?
Select an answer first - 3
Which phase in the ISO/IEC 27035 incident management process involves identifying and reporting potential security incidents?
Select an answer first - 4
What is the main goal of the recovery phase in incident response?
Select an answer first - 5
Which phase in the NIST SP 800-61 incident response lifecycle involves developing policies, procedures, and training before an incident occurs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “SSCP” is a trademark of its owner, used for identification only.