🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

You are the first responder to a suspected data-exfiltration incident on a powered-on Windows file server in the company's data center. Digital evidence may later be needed in court, so you must follow accepted evidence-handling procedures. According to NIST guidance, which initial action should you perform before interacting with the system?

  • Open a chain-of-custody log and record the date, time, location, and your identity.

  • Pull the network cable to stop data exfiltration, then photograph the server connections.

  • Install vendor patches to close the suspected vulnerability before evidence is collected.

  • Create a forensic disk image of all attached drives using a hardware write-blocker.

ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot