🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An organization has completed root-cause analysis and malware removal on several compromised application servers. As it prepares to return the systems to normal operation, management asks how the incident response team will verify that no residual malicious activity remains. Which action best demonstrates effective continuous monitoring during the recovery phase of the incident response lifecycle?

  • Deploy host and network sensors that feed real-time security event data to the SIEM and tune alerts for indicators of reinfection on the recovered servers.

  • Implement weekly full offline backups of the restored servers to safeguard data integrity.

  • Perform a company-wide wipe and reimage of all systems that were not directly impacted by the incident.

  • Conduct a lessons-learned workshop with stakeholders to update the incident response policy and procedures.

ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot