ISC2-CC - Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts - Section 2.3

Understand the purpose and phases of incident response, including the components of an incident response plan and the response team.

Walk through the incident response lifecycle - preparation, detection and analysis, containment, eradication, recovery, and post-incident (lessons learned) - and recognise the role of the computer security incident response team (CSIRT). Distinguish an event from an incident, and identify the order in which response phases occur.

Incident responseIncident response planContainmentCSIRTLessons learned

Practice question for this objective

Free sampleBusiness Continuity (BC), Disaster Recovery (DR) & Incident Response Conceptsmedium

A consultant is helping a small firm draft its incident response plan and explains which element gives the plan its practical value during a crisis. Which item is a core component that an incident response plan should contain?

  • AA marketing schedule describing when new product features will be announced to customers during the year.
  • BA depreciation table showing the accounting book value of each server over its expected service life.
  • CDefined roles, responsibilities and communication procedures for the people who will handle an incident. Correct
  • DThe individual passwords for every administrator account stored in the body of the document.
An incident response plan must define roles, responsibilities and communication procedures for the responding team. The plan's value comes from removing ambiguity in a crisis: predefining who leads, who executes each task and how information flows lets responders act decisively instead of improvising organisation during the incident.

Why A is wrong: A product announcement schedule is unrelated to handling incidents and would never appear as a component of a response plan.

Why B is wrong: Asset depreciation is a finance record; while asset inventories help, a depreciation schedule does not guide incident handling and is not a plan component.

Why C is correct: A usable plan must state who does what and how they will communicate, because clear roles and escalation paths are what let a team act quickly and consistently under pressure.

Why D is wrong: This is tempting because responders need access, but embedding live credentials in the plan is a serious security flaw, not a legitimate required component.

See more ISC2-CC practice questions with worked answers.

More in this domain

Back to all Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts objectives, or the ISC2-CC cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.