
Systems Security Certified Practitioner
Domain 4Objective 1
4.1 - Understand and Support Incident Response Lifecycle (e.g., National Institute of Standards and Technology (NIST), International Organization for Standardization (ISO)) SSCP Practice Questions (Page 4)
Part of the Incident Response and Recovery domain, which accounts for 14% of the SSCP exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
14%of the exam
Questions 16–20
- 16
What is the primary purpose of an escalation process in incident response?
Select an answer first - 17
During an incident, a server is found to be running a cryptominer that was installed via a vulnerable web application. The incident response team needs to stop the immediate impact while preserving evidence for later analysis. Which containment strategy is most appropriate at this stage?
Select an answer first - 18
Why is it important to establish a training and awareness program during the Preparation phase of incident response?
Select an answer first - 19
A mid-sized company has just adopted the NIST incident response lifecycle. The CISO wants to ensure that when a security incident occurs, the right people are notified quickly and that the incident is properly categorized. Which two phases of the NIST lifecycle should the team focus on to achieve this goal?
Select an answer first - 20
Why is it important to communicate with public relations (PR) during a significant security incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “SSCP” is a trademark of its owner, used for identification only.