Incident Response

Study ISC2 CC incident response: preparation, detection, analysis, containment, eradication, recovery, evidence, and lessons learned.

Incident response questions test process discipline. The safest answer usually follows the approved plan, preserves evidence, limits damage, escalates correctly, and avoids improvising outside authority.

Core response phases

Phase What it means
Preparation policies, roles, contacts, tools, training, and playbooks
Detection and analysis validate the alert, scope impact, classify severity, preserve evidence
Containment limit spread while protecting evidence and business priorities
Eradication remove root cause such as malware, bad account, or vulnerable component
Recovery restore service and monitor for recurrence
Lessons learned document timeline, gaps, improvements, and ownership

First-action chooser

Scenario Better first action
suspicious phishing email report through approved process without clicking
malware alert on workstation isolate/contain according to procedure and preserve evidence
possible data exposure escalate, preserve logs, identify scope, follow notification policy
ransomware impact contain spread, activate IR/BC/DR procedures, protect backups
unclear alert validate with logs and monitoring before declaring closure

Evidence basics

CC is not a forensics expert exam, but you should recognize why evidence matters. Do not delete suspicious files, wipe hosts, or change logs before authorized collection if investigation matters.

AI-security angle

Entry-level staff may triage AI-assisted alerts or automated blocks. The exam-level instinct is not “trust the AI.” Validate the alert, follow the playbook, escalate uncertainty, and record what happened.

Revised on Monday, June 15, 2026