
Systems Security Certified Practitioner
Domain 4Objective 1
4.1 - Understand and Support Incident Response Lifecycle (e.g., National Institute of Standards and Technology (NIST), International Organization for Standardization (ISO)) SSCP Practice Questions (Page 3)
Part of the Incident Response and Recovery domain, which accounts for 14% of the SSCP exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
14%of the exam
Questions 11–15
- 11
A security operations center (SOC) analyst notices multiple failed login attempts followed by a successful login from an unusual geographic location for a user account. The account then began downloading large amounts of data. Which phase of the NIST lifecycle is the analyst currently in?
Select an answer first - 12
What is the primary purpose of a lessons learned review after an incident?
Select an answer first - 13
A security analyst has confirmed a malware infection on a critical server. The incident response team needs to inform the appropriate stakeholders. According to the NIST incident response lifecycle, which communication should occur FIRST?
Select an answer first - 14
After containing a malware outbreak, the incident response team has identified that the malware was introduced through a vulnerable third-party application. The team has removed the malware from all affected systems. What is the NEXT step to ensure the threat is fully eliminated?
Select an answer first - 15
Which activity is part of the Detection and Analysis phase in incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “SSCP” is a trademark of its owner, used for identification only.