nerdexam
(ISC)2

SSCP · Question #919

When a possible intrusion into your organization's information system has been detected, which of the following actions should be performed first?

The correct answer is C. Determine to what extent systems and data are compromised. Upon detecting a possible intrusion, the first action is to assess the scope and extent of the compromise. Without understanding what systems are affected, what data may be involved, and how far the intrusion has spread, you cannot make informed decisions about containment or…

Submitted by andres_qro· Apr 18, 2026Incident Response and Recovery

Question

When a possible intrusion into your organization's information system has been detected, which of the following actions should be performed first?

Options

  • AEliminate all means of intruder access.
  • BContain the intrusion.
  • CDetermine to what extent systems and data are compromised.
  • DCommunicate with relevant parties.

How the community answered

(42 responses)
  • A
    17% (7)
  • B
    7% (3)
  • C
    71% (30)
  • D
    5% (2)

Explanation

Upon detecting a possible intrusion, the first action is to assess the scope and extent of the compromise. Without understanding what systems are affected, what data may be involved, and how far the intrusion has spread, you cannot make informed decisions about containment or eradication. Acting prematurely - such as cutting off access or eliminating means of entry - could tip off the intruder, destroy forensic evidence, or result in an incomplete response. Assessment comes first to guide all subsequent steps: containment, eradication, recovery, and communication.

Topics

#Incident Response#Incident Analysis#Intrusion Detection#Scope Determination

Community Discussion

No community discussion yet for this question.

Full SSCP Practice