ISC exam skill

Incident response from detection through recovery

Triage an incident, preserve evidence, contain impact, eradicate causes, recover safely, and evaluate response controls for ISC.

The decision that earns the point

Identify the objective before choosing the control

Incident response coordinates preparation, detection, analysis, containment, eradication, recovery, communication, and improvement after a cybersecurity event. The immediate choice depends on scope, severity, affected assets, evidence needs, legal or contractual duties, and business impact. Containment limits harm, eradication removes the cause, and recovery restores trusted operation. Those objectives should not be collapsed into one step.

Exam use

ISC can test incident criteria, monitoring and escalation, triage, evidence preservation, containment choices, root cause, recovery validation, communications, third parties, and lessons learned.

Check the official exam scope

Your scratch-paper plan

Solve it in three moves

  1. 1

    Validate and triage

    Confirm the event, classify severity, identify affected assets and data, preserve volatile evidence, and activate the right roles.

    NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations
  2. 2

    Contain with intent

    Choose isolation, credential action, blocking, or other containment that limits harm without needlessly destroying evidence or critical service.

    NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations
  3. 3

    Eradicate, recover, improve

    Remove the cause, restore from trusted states, test business and security operation, monitor recurrence, and feed lessons into controls.

    NIST SP 800-53 Rev. 5.1: Security and Privacy Controls

Worked problem

Work the facts before choosing the answer

Monitoring detects repeated privileged logins from an impossible location and a large database export. The account supports a critical billing process, and responders immediately plan to wipe the administrator laptop.

CPAPass exam analysis using the stated assumptions

Show the work

The team should preserve relevant volatile and log evidence, disable or contain the compromised credentials, determine affected systems and data, and maintain billing through an authorized alternative. Wiping first can destroy evidence without containing server-side access.

Rule source: NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations

Answer

Contain the identity and affected connections, preserve evidence, investigate scope, eradicate the access path, then restore and monitor trusted operations before closing the incident.

Rule source: NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations

Do it now

Test the same decision with a fresh question

Start with free ISC practice. Create an account only when you want the 5-day no-card CPAPass trial and continued section practice.

The trap and the repair

Common trap

Jumping directly from alert to disaster recovery skips validation, evidence, scope, and containment. Restoring a server without removing compromised credentials can recreate the incident on clean infrastructure.

Repair

Write the current response objective beside every action and reject any step that destroys needed evidence or restores an untrusted condition.

Authority and scope boundary

NIST SP 800-61 and SP 800-53 support the response workflow, and the Blueprint controls ISC scope. The IT general controls guide retains broad access, change, and operations control design. The business continuity and disaster recovery guide retains continuity strategy, RTO, RPO, backups, alternate processing, and disaster recovery.

2026 Uniform CPA Examination Blueprints and NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations were reviewed on 2026-08-14. Check a newer authority when the effective date or facts change.

Response decision path

Choose the next action from the current objective

A strong incident answer preserves optionality: limit harm, keep evidence usable, restore trust, and document what changed.

Response objectiveConcrete actionEvidence or completion testAuthority
Detect and analyzeValidate indicators, classify severity, scope assets and data, notify assigned rolesAlert context, timeline, asset and identity inventory, incident recordNIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations
Preserve and containCapture needed evidence, isolate affected paths, revoke compromised access, maintain critical serviceForensic copy or logs, containment approval, blocked connection, alternative operationNIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations
Eradicate and recoverRemove root cause, patch or rebuild, restore trusted data, validate functionality and controlsClean-state proof, test results, reconciliation, enhanced monitoringNIST SP 800-53 Rev. 5.1: Security and Privacy Controls
Learn and governComplete root-cause review, update controls and plans, track remediation and reporting dutiesAfter-action report, assigned actions, retest, communication recordNIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations

After a miss

Review incident response by objective

  1. 1

    Rebuild the timeline and label each known fact as alert, confirmed scope, evidence, business impact, or unresolved question.

  2. 2

    Sort proposed actions into containment, eradication, recovery, and improvement, then put them in a defensible order.

  3. 3

    Answer a new ISC incident scenario and explain why the chosen step belongs to response rather than ITGC design or BCDR.

Your exam workflow

  1. Step 1Identify the requirementConfirm the event, classify severity, identify affected assets and data, preserve volatile evidence, and activate the right roles.NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations
  2. Step 2Classify the factsChoose isolation, credential action, blocking, or other containment that limits harm without needlessly destroying evidence or critical service.NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations
  3. Step 3Apply the authorityRemove the cause, restore from trusted states, test business and security operation, monitor recurrence, and feed lessons into controls.NIST SP 800-53 Rev. 5.1: Security and Privacy Controls
  4. Step 4Check the outputContain the identity and affected connections, preserve evidence, investigate scope, eradicate the access path, then restore and monitor trusted operations before closing the incident.NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations

Quick questions

What is the key rule?

Incident response coordinates preparation, detection, analysis, containment, eradication, recovery, communication, and improvement after a cybersecurity event. The immediate choice depends on scope, severity, affected assets, evidence needs, legal or contractual duties, and business impact. Containment limits harm, eradication removes the cause, and recovery restores trusted operation. Those objectives should not be collapsed into one step.

How can this topic be tested on the CPA Exam?

ISC can test incident criteria, monitoring and escalation, triage, evidence preservation, containment choices, root cause, recovery validation, communications, third parties, and lessons learned.

What mistake most often changes the result?

Jumping directly from alert to disaster recovery skips validation, evidence, scope, and containment. Restoring a server without removing compromised credentials can recreate the incident on clean infrastructure. Write the current response objective beside every action and reject any step that destroys needed evidence or restores an untrusted condition.

Where should I practice the decision?

After the worked example, open the ISC free-practice link and work a fresh question that tests the same decision. If the miss depends on Business continuity and disaster recovery, review that handoff before trying another set.

Sources behind the rule