ExamOpsPractice free

CompTIA Security+ SY0-701 · Free study guide

Objective 4.8 — Execute appropriate incident response activities

Incident response is a coordinated cycle: prepare, detect, analyze, contain, eradicate, recover, and learn. Phases can overlap, but skipping analysis or evidence preservation can create a larger outage or destroy the facts needed for recovery.

Preparation establishes roles, contacts, authority, communications, tools, logging, access, playbooks, and exercises. Detection identifies a potential event. Analysis determines confidence, scope, impact, and priority. Record a timeline and distinguish confirmed facts from hypotheses.

Containment limits harm. Short-term containment may isolate a host or disable an account; longer-term containment can introduce temporary segmentation or clean services. Eradication removes persistence and the exploited condition. Recovery restores from trusted state, monitors for recurrence, and returns service through defined criteria.

Evidence and coordination

Chain of custody records who collected, transferred, stored, and accessed evidence. Acquisition should preserve relevant data using approved methods; integrity verification supports confidence that copies did not change. Legal hold prevents routine deletion of relevant information. E-discovery addresses identification and production for legal processes. Follow organizational guidance and qualified legal direction.

Stakeholders can include security, IT, legal, privacy, communications, leadership, affected business owners, insurers, regulators, vendors, and law enforcement. Notification decisions depend on confirmed facts and obligations. An analyst should not contact an attacker, customer, or authority outside authorized procedure.

Playbooks guide repeatable action without replacing judgment. Training, tabletop exercises, and simulations reveal gaps before a real event. After recovery, a lessons-learned review asks what happened, why controls failed, what worked, and who owns corrective action. Root cause analysis should improve systems rather than search for a person to blame.

Decision rule: preserve life and safety, limit ongoing harm, protect evidence, coordinate through assigned authority, restore from trusted state, and verify corrective actions after the incident.

Practice and apply this objective

A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.

Start practicing free