šŸ”„ 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

After containing and eradicating a cryptomining malware infection in an Amazon EC2-based web application, the response team is preparing to return the affected instances to production. According to incident-response best practices, which action should the security administrator take during the recovery phase to meet incident‐documentation requirements and support future improvements?

  • Open new change-management tickets assigning developers to patch the vulnerable code without modifying the original incident record.

  • Delete the forensic EBS snapshots after verifying they are no longer needed to reduce ongoing storage costs.

  • Record a detailed timeline of actions, remediation steps, and evidence locations in the organization's incident ticket before bringing the servers back online.

  • Simply relaunch the instances from a golden AMI and mark the incident as closed once user testing is successful.

ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot