SSCP Certification SSCP Incident Response and Recovery 5 — Questions and Answers
Question 1: A company activates its Business Continuity Plan (BCP) after a flood damages its primary datacenter. Which phase of incident response does this MOST align with?
- Detection and Analysis
- Containment
- Eradication
- Recovery (Correct answer)
Correct answer: Recovery
Activating a BCP to restore business functions after a disaster aligns with the Recovery phase, which focuses on restoring normal operations.
Question 2: Under US federal law, which regulation requires certain organizations to report cybersecurity incidents to CISA within 72 hours?
- HIPAA Security Rule
- CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) (Correct answer)
- SOX Section 404
- GLBA Safeguards Rule
Correct answer: CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
CIRCIA mandates that covered critical infrastructure entities report significant cyber incidents to CISA within 72 hours of reasonable belief of occurrence.
Question 3: What is the key difference between an 'incident' and an 'event' in security operations?
- Events are more severe than incidents
- An incident is an adverse event that threatens confidentiality, integrity, or availability; an event is any observable occurrence (Correct answer)
- Events require escalation to management while incidents do not
- Incidents only involve external attackers while events include insider threats
Correct answer: An incident is an adverse event that threatens confidentiality, integrity, or availability; an event is any observable occurrence
An event is any observable system occurrence, while an incident is specifically an adverse event (or threat of one) that negatively impacts security.
Question 4: During a ransomware incident, the security team is deciding whether to pay the ransom. Which factor MOST influences the decision from a security policy perspective?
- The reputation of the ransomware group
- Availability of clean backups to restore from (Correct answer)
- The total value of encrypted files
- Whether the ransom is paid in cryptocurrency
Correct answer: Availability of clean backups to restore from
The existence of reliable, clean backups is the most critical factor because it provides an alternative to paying the ransom and enables recovery.
Question 5: Which incident response concept involves pre-approved, documented procedures for specific attack types that analysts follow step-by-step?
- Threat intelligence feeds
- Security playbooks (runbooks) (Correct answer)
- Vulnerability disclosure programs
- Security awareness training
Correct answer: Security playbooks (runbooks)
Security playbooks (runbooks) are pre-documented, step-by-step procedures for responding to specific incident types, ensuring consistent and efficient response.
Question 6: After a major incident, an organization discovers its incident response plan had not been tested in two years. Which activity would BEST address this gap going forward?
- Conducting quarterly tabletop exercises and annual full-scale simulations (Correct answer)
- Hiring additional security analysts to improve response speed
- Purchasing a new SIEM platform for better detection
- Requiring all employees to complete cybersecurity awareness training
Correct answer: Conducting quarterly tabletop exercises and annual full-scale simulations
Regular tabletop exercises and simulations test the IRP, identify gaps, train responders, and ensure the plan remains current with evolving threats.
Question 7: A security analyst is using the MITRE ATT&CK framework during incident investigation. What is the PRIMARY benefit of mapping attacker actions to this framework?
- It automates the containment of compromised systems
- It provides a standardized vocabulary to describe and understand adversary tactics and techniques (Correct answer)
- It calculates the financial impact of the incident
- It generates automatic patches for exploited vulnerabilities
Correct answer: It provides a standardized vocabulary to describe and understand adversary tactics and techniques
MITRE ATT&CK provides a standardized taxonomy of adversary behaviors, helping analysts understand attack patterns, communicate findings, and improve defenses.
A company activates its Business Continuity Plan (BCP) after a flood damages its primary datacenter.
Which phase of incident response does this MOST align with?