ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A security analyst observes sustained outbound traffic to an unrecognized IP address from a production EC2 instance. Before escalating the suspected incident, the analyst must create an entry in the organization's ticketing system to document the monitoring results. Which information should be recorded first to preserve traceability and enable later correlation of evidence?
A list of users who logged in to the instance during the analyst's shift
Any remediation steps the analyst attempted before escalation
The exact date and time of detection along with a unique ticket or event ID
The analyst's opinion on the most likely root cause of the traffic
Effective documentation begins with objective, verifiable data that anchors every subsequent note. Recording the precise date-time stamp together with a unique event or ticket identifier establishes an immutable reference point that auditors, managers, and incident responders can correlate with log files, packet captures, and other evidence. Remediation actions, user lists, or analyst opinions may also be captured, but they rely on the initial time-stamped event record to be meaningful and defensible.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is EC2 and its role in incident response?
Open an interactive chat with Bash
Why is the date and time of detection critical in incident documentation?
Open an interactive chat with Bash
What is a unique ticket or event ID, and how does it support traceability?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .