🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 12 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A security analyst observes sustained outbound traffic to an unrecognized IP address from a production EC2 instance. Before escalating the suspected incident, the analyst must create an entry in the organization's ticketing system to document the monitoring results. Which information should be recorded first to preserve traceability and enable later correlation of evidence?

  • The analyst's opinion on the most likely root cause of the traffic

  • The exact date and time of detection along with a unique ticket or event ID

  • Any remediation steps the analyst attempted before escalation

  • A list of users who logged in to the instance during the analyst's shift

ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot