SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
CC · Domain 5

Security Operations and Incident Response practice questions

Security Operations and Incident Response is worth 17% of the CC exam — the 4th-heaviest of the 5 domains. Data security, security operations, incident response, asset protection, and security testing. Official weighting 17.3%. 6 fully worked examples are further down this page, answers included.

Exam weight
17%
the 4th-heaviest of the 5 domains
Questions
100
across 5 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 5 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Security Operations and Incident Response questions, fully explained

Questions from the CC bank mapped to domain 5, with the answer key and the reasoning behind every option. None of them repeat the examples on the main CC practice page.

Question 1Security Operations and Incident Response

In a typical commercial classification scheme of public, internal, confidential, and restricted, which label demands the STRONGEST protection?

Choose one.

  • a
    Restricted Correct

    Restricted is the highest sensitivity tier in this scheme, reserved for data whose disclosure would cause the most severe harm, so it demands the strongest controls.

  • b
    Public

    Public data is approved for open release and requires the least protection of any tier.

  • c
    Internal

    Internal data is meant to stay inside the organization but causes limited harm if exposed, so it sits near the low end of the scale.

  • d
    Confidential

    Confidential data is sensitive, but in this scheme it ranks below restricted, which is the top tier.

The concept

Classification schemes order labels from least to most sensitive. A common commercial ladder is public, internal, confidential, restricted, and protection strength climbs with each rung.

Why that’s the answer

Restricted sits at the top of the ladder, covering data such as trade secrets or regulated personal data whose exposure would cause severe damage. Because classification drives protection, the top label gets the strongest controls: the tightest access, the strongest encryption, and the most careful handling and disposal. Public, internal, and confidential each rank lower and warrant progressively lighter controls.

How to reason it out
  1. Order the labels from least to most sensitive: public, internal, confidential, restricted.
  2. Apply the rule that protection strength follows sensitivity.
  3. Select the top label, restricted, as the one demanding the strongest protection.

Exam tip: In the public-internal-confidential-restricted ladder, restricted is the most sensitive tier and gets the strongest protection.

Data Security: Classification, Masking, Sanitization, and Encryption Basics — the lesson that teaches this.

Question 2Security Operations and Incident Response

A customer service application displays a payment card number as XXXX-XXXX-XXXX-4321, showing only the last four digits to agents. Which data protection technique is this?

Choose one.

  • a
    Data masking Correct

    Masking obscures part of a displayed value, such as showing only the last four digits, so the full value is hidden from the viewer.

  • b
    Hashing

    Hashing converts the entire value into a fixed-length digest; it would not display a partially readable card number.

  • c
    Degaussing

    Degaussing destroys data on magnetic media with a powerful magnetic field; it is a sanitization method, not a display technique.

  • d
    Asymmetric encryption

    Encryption renders the whole value unreadable without the key; the agents here see a partly readable number on screen, which is masking.

The concept

Data masking obscures sensitive values as they are displayed or shared, commonly by replacing most characters and leaving a small recognizable portion, such as the last four digits of a card number.

Why that’s the answer

Showing XXXX-XXXX-XXXX-4321 is the signature example of masking: agents can confirm the card with a customer without ever seeing the full number. The underlying data still exists in the system, and there is no key that turns the masked display back into the full value. Hashing and encryption transform the entire value, and degaussing is a media destruction method.

How to reason it out
  1. Observe that most of the value is replaced with placeholder characters while a small portion stays visible.
  2. Recognize that obscuring displayed values while the underlying data still exists is data masking.
  3. Eliminate hashing and encryption, which transform the whole value, and degaussing, which destroys media.

Exam tip: Masking hides part of a displayed value, like showing only the last four digits, while the real data remains stored underneath.

Data Security: Classification, Masking, Sanitization, and Encryption Basics — the lesson that teaches this.

Question 3Security Operations and Incident Response

Which statement best describes how data masking differs from encryption?

Choose one.

  • a
    Masking permanently destroys the underlying data, while encryption preserves it

    Masking does not destroy anything; the underlying data still exists in the system, only its display is obscured.

  • b
    Masking is a stronger form of encryption that uses two keys

    Masking is not encryption at all; it uses no keys, and two-key operation describes asymmetric encryption.

  • c
    A masked display has no key and cannot be reversed to reveal the hidden value, while encrypted data can be decrypted by anyone holding the correct key Correct

    Masking simply obscures what is shown, with no mathematical path from the masked output back to the original; encryption is reversible by design for key holders.

  • d
    Masking converts data into a fixed-length digest for integrity checking

    Fixed-length digests for integrity describe hashing, not masking.

The concept

Masking obscures values as displayed, leaving the real data intact underneath and offering no key or algorithm to reconstruct the hidden portion from the masked output. Encryption transforms data reversibly, so anyone with the correct key can recover the original.

Why that’s the answer

The defining contrast is reversibility through a key: encryption has one, masking does not. A masked card number on screen cannot be turned back into the full number from what is displayed, yet the full number still exists in the database. Masking destroys nothing, is not a form of encryption, and produces no digest.

How to reason it out
  1. Define masking: obscure the displayed value, no key, no way to reverse the display.
  2. Define encryption: transform the value so it is recoverable only with the correct key.
  3. Contrast them on reversibility and keep the option capturing keyless irreversibility of the masked display versus key-based decryption.

Exam tip: Masking has no key and its display cannot be reversed; encryption is deliberately reversible for whoever holds the key.

Data Security: Classification, Masking, Sanitization, and Encryption Basics — the lesson that teaches this.

Question 4Security Operations and Incident Response

Before donating an old office laptop, an employee deletes all files and empties the recycle bin. From a data security standpoint, what is the state of the data?

Choose one.

  • a
    The data is likely recoverable, because deletion only removes references to the files, not the data itself Correct

    Deleting and emptying the recycle bin removes pointers to the data while the contents remain on the drive until overwritten, so recovery tools can restore them.

  • b
    The data is fully sanitized and the laptop is safe to donate

    Deletion is not sanitization; without overwriting or destroying the media, the data can still be recovered.

  • c
    The data is encrypted automatically by the deletion process

    Deletion performs no encryption; it merely marks storage space as available for reuse.

  • d
    The data has been degaussed and is unrecoverable

    Degaussing requires a purpose-built magnetic device; simply deleting files applies no magnetic field and destroys nothing.

The concept

Sanitization means securely destroying data so it cannot be recovered, using methods such as overwriting, degaussing for magnetic media, or physical destruction. Ordinary deletion and quick formatting do not qualify.

Why that’s the answer

When files are deleted and the recycle bin emptied, the file system merely forgets where the data lives; the bits stay on the disk until something overwrites them. Freely available recovery tools can restore such files, which is why donated or resold devices are a classic source of data leakage. Proper sanitization before disposal requires overwriting the drive, degaussing magnetic media, or physically destroying it.

How to reason it out
  1. Recall what deletion actually does: it removes the file system's pointers, leaving the underlying data in place.
  2. Conclude that recovery software can restore the files, so the data is still at risk.
  3. Recall the acceptable sanitization methods, overwriting, degaussing, or physical destruction, and note that none was performed.

Exam tip: Deleting files or emptying the recycle bin is not sanitization; the data remains recoverable until it is overwritten or the media is destroyed.

Data Security: Classification, Masking, Sanitization, and Encryption Basics — the lesson that teaches this.

Question 5Security Operations and Incident Response

A security team plans to sanitize retired backup tapes by degaussing them. Why is degaussing appropriate for this media but NOT for solid-state drives?

Choose one.

  • a
    Degaussing only works on media smaller than a hard drive

    Media size is irrelevant; what matters is whether the media stores data magnetically.

  • b
    Degaussing destroys data by disrupting magnetic fields, which works on magnetic media like tape but has no effect on the flash memory in solid-state drives Correct

    Tapes store data magnetically, so a strong magnetic field scrambles them; solid-state drives store charge in flash cells, which a magnet does not erase.

  • c
    Solid-state drives are already encrypted, so no sanitization is ever needed

    Not all solid-state drives are encrypted, and sanitization policy cannot assume encryption; the reason degaussing fails on them is their non-magnetic storage.

  • d
    Degaussing is a software feature that only tape drives support

    Degaussing is performed by a physical device generating a powerful magnetic field, not by software in the drive.

The concept

Degaussing sanitizes magnetic media, such as tapes and traditional hard disks, by applying a powerful magnetic field that destroys the recorded patterns. It is useless against flash-based storage, which holds data as electrical charge rather than magnetism.

Why that’s the answer

The effectiveness of degaussing depends entirely on the storage technology. Backup tapes record data magnetically, so a degausser renders them unreadable. Solid-state drives use flash memory cells that are unaffected by magnetic fields, so degaussing them leaves the data intact; they require overwriting, cryptographic erasure, or physical destruction instead. Size, encryption assumptions, and software support have nothing to do with it.

How to reason it out
  1. Identify how each media type stores data: tapes magnetically, solid-state drives as charge in flash cells.
  2. Match degaussing, a magnetic-field attack on magnetic patterns, to magnetic media only.
  3. Conclude that solid-state drives need a different sanitization method, such as destruction or overwriting.

Exam tip: Degaussing only sanitizes magnetic media; flash-based drives are immune to it and need overwriting or physical destruction.

Data Security: Classification, Masking, Sanitization, and Encryption Basics — the lesson that teaches this.

Question 6Security Operations and Incident Response

An organization is disposing of drives that held its most sensitive records and wants certainty that the data can never be recovered, accepting that the drives will not be reused. Which method gives the strongest assurance?

Choose one.

  • a
    Performing a quick format on each drive

    A quick format rebuilds file system structures without erasing the data, leaving it recoverable with common tools.

  • b
    Deleting all partitions and leaving the drives unallocated

    Removing partitions removes the map to the data, not the data itself, which recovery software can still reconstruct.

  • c
    Physical destruction of the drives, such as shredding Correct

    Physically destroying the media eliminates any possibility of recovery and is the strongest assurance when reuse is not required.

  • d
    Renaming files to meaningless strings before disposal

    Renaming changes labels only; every byte of content remains intact and readable.

The concept

Sanitization options range from overwriting, through degaussing for magnetic media, up to physical destruction. When the data is highly sensitive and the media will not be reused, physical destruction offers the highest confidence that nothing can be recovered.

Why that’s the answer

Shredding or otherwise destroying the drive removes the medium the data lives on, foreclosing every recovery avenue. Quick formatting and partition deletion are variants of the same trap as file deletion: they discard the map while leaving the territory, and recovery tools routinely restore data from both. Renaming files changes nothing about their contents.

How to reason it out
  1. Note the two requirements: maximum assurance against recovery, and no need to reuse the drives.
  2. Rank the options: renaming, quick formatting, and partition deletion all leave data recoverable; destruction removes the media entirely.
  3. Choose physical destruction as the method matching both requirements.

Exam tip: For the most sensitive data on media that will not be reused, physical destruction is the surest sanitization method.

Data Security: Classification, Masking, Sanitization, and Encryption Basics — the lesson that teaches this.

What CC domain 5 tests, topic by topic

The official exam guide breaks Security Operations and Incident Response into 5 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published CC practice questions per topic in Security Operations and Incident Response
TopicWhat it coversQuestions
Understand data securityOfficial CC sub-domain (Security Operations and Incident Response, Sept-2026 outline). Data handling (classification, labeling, masking, sanitization); and encryption (symmetric, asymmetric, hashing, quantum-resistant cryptography).20
Understand security operationsOfficial CC sub-domain. Logging and monitoring of security events; security event triage (incident use cases, prioritization, correlation); threat actors (types, motivations); cyber threat intelligence; and threat frameworks.20
Understand Incident Response (IR)Official CC sub-domain. Implementing an Incident Response Plan (IRP) with data-handling policy; and Incident Response exercises (testing, tabletop).20
Understand asset protectionOfficial CC sub-domain. Asset lifecycle management (End Of Life software and devices); and configuration and change management.20
Understand security testingOfficial CC sub-domain. Security readiness testing (blue, purple, and red teaming); application testing (vulnerability scanning, static and dynamic analysis, threat modeling); and physical penetration testing (phishing, tailgating, impersonation).20
Total100

Revise Security Operations and Incident Response before you drill it

Other CC domains

Security Operations and Incident Response: your questions

Security Operations and Incident Response is domain 5 of the CC exam guide and carries 17% of the scored content — the 4th-heaviest of the 5 domains. On a 100-question paper that works out to roughly 17 questions, though ISC2 does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official CC exam guide.