Study ISC2 CC incident response: preparation, detection, analysis, containment, eradication, recovery, evidence, and lessons learned.
Incident response questions test process discipline. The safest answer usually follows the approved plan, preserves evidence, limits damage, escalates correctly, and avoids improvising outside authority.
| Phase | What it means |
|---|---|
| Preparation | policies, roles, contacts, tools, training, and playbooks |
| Detection and analysis | validate the alert, scope impact, classify severity, preserve evidence |
| Containment | limit spread while protecting evidence and business priorities |
| Eradication | remove root cause such as malware, bad account, or vulnerable component |
| Recovery | restore service and monitor for recurrence |
| Lessons learned | document timeline, gaps, improvements, and ownership |
| Scenario | Better first action |
|---|---|
| suspicious phishing email | report through approved process without clicking |
| malware alert on workstation | isolate/contain according to procedure and preserve evidence |
| possible data exposure | escalate, preserve logs, identify scope, follow notification policy |
| ransomware impact | contain spread, activate IR/BC/DR procedures, protect backups |
| unclear alert | validate with logs and monitoring before declaring closure |
CC is not a forensics expert exam, but you should recognize why evidence matters. Do not delete suspicious files, wipe hosts, or change logs before authorized collection if investigation matters.
Entry-level staff may triage AI-assisted alerts or automated blocks. The exam-level instinct is not “trust the AI.” Validate the alert, follow the playbook, escalate uncertainty, and record what happened.