Triage BoardGet the app

Domain 3 · Incident Response and Management

The incident response process, step by step

For CS0-004, the incident response process is CompTIA's seven steps in order: preparation, detection, analysis, containment, eradication, recovery, post-incident (objective 3.2, CS0-004 exam objectives, version 2.0, checked October 2026). Items name a moment in an incident and ask which step you are in, or what the next step should be. NIST and SANS group the same work differently, and the exam's answer follows CompTIA's list.

  • Exam code CS0-004
  • Domain weight 24%
  • Tickets here 18

The seven steps on one incident

  1. Months before

    Preparation

    The incident response (IR) plan, the contact list, central logging and an endpoint detection and response (EDR) agent on the build server build-07.example.com are in place before anything happens.

  2. T+0

    Detection

    EDR flags a process called kworkerd holding the CPU near 100% and connecting out to 203.0.113.15 on port 3333, a port mining pools use.

  3. T+20 min

    Analysis

    You confirm no build job explains it, find which CI credential started it, and check the other build agents for the same process. That sets the scope and the severity.

  4. T+45 min

    Containment

    Pull build-07 out of the agent pool, block the pool address at the egress firewall, and copy memory and disk before anything is wiped.

  5. T+3 h

    Eradication

    Remove the miner and the cron entry that relaunched it, revoke the stolen CI token, and rebuild the agent from a known-good image.

  6. T+5 h

    Recovery

    Return the rebuilt agent to the pool and watch it for the same process and destination before calling it clean.

  7. T+2 weeks

    Post-incident

    A review of what happened, a root cause (a CI token committed to a public repository), and the changes that come out of it.

What each step means on CS0-004

Preparation and detection

Preparation is everything done before an alert: the plan, the people and their roles, tooling, logging and training. Items about preparation describe work that happens in calm weeks, so an option that only makes sense once an attacker is inside belongs to a later step. Detection is the moment someone or something notices: a security information and event management (SIEM) correlation rule, an EDR alert, a user report.

Analysis

Analysis decides whether the event is an incident, how far it reaches and how bad it is. CompTIA lists it as its own step, which matters when an item asks what to do between noticing and acting. Scope and severity come out of this step; the frameworks on the attack frameworks page are the vocabulary for describing what you found.

Containment, eradication and recovery

Three separate steps on CS0-004. Containment limits the damage and keeps evidence intact; eradication removes the cause; recovery returns systems to production and watches them. Items in this area turn on the order: a clean rebuild before containment can tip off the attacker and destroy evidence you never collected. The concept page on containment vs eradication vs recovery works through the borderline cases.

Post-incident

The step after recovery is the lessons-learned review: what happened, what the root cause was, what worked, and which changes go back into preparation. The techniques that carry each step out (playbooks, triage, evidence handling, root cause analysis) are objective 3.3, covered in incident response techniques.

What changed from CS0-003

On CS0-003, which English candidates can book until December 22, 2026 (CompTIA CS0-003 page, checked October 2026), detection through recovery formed one objective and preparation with post-incident formed another. CS0-004 puts all seven steps into one ordered objective; the full list of changes is on CS0-004 vs CS0-003.

CompTIA, NIST and SANS on the same work

How the exam's list lines up with the two models study material quotes most
PointCompTIA CS0-004 (3.2)NIST SP 800-61r2SANS
Steps≠74 phases6
Getting readyPreparationPreparationPreparation
Noticing and sizing≠Detection; AnalysisDetection and AnalysisIdentification
Stopping the spread≠ContainmentContainment, Eradication and RecoveryContainment
Removing the cause≠Eradication(same phase)Eradication
Back to service≠Recovery(same phase)Recovery
Afterwards≠Post-incidentPost-Incident ActivityLessons Learned

Rows marked ≠ are where at least one of them differs from the others. NIST SP 800-61r2 (2012) is superseded. NIST SP 800-61r3 (April 2025) drops the four-phase cycle and organizes incident response around the six NIST Cybersecurity Framework (CSF) 2.0 Functions: Govern, Identify, Protect, Detect, Respond, Recover (NIST CSRC, checked October 2026).

Contain before you cleanRule

  • When an option removes the malware, deletes an account or rebuilds a host while the attacker may still hold a foothold elsewhere, it has jumped to eradication. Containment comes first, so the cleanup does not alert the attacker or erase evidence nobody has copied yet.
  • When a stem names NIST or SANS, answer in that model's terms; otherwise use CompTIA's seven steps.

Which step are you in?

Locate the moment in the incident first; the same action can be right in one phase and premature in the next.

Ticket 1 / 18

0 right

INC-001

Which incident response phase involves the development of procedures, tools, and team training before an incident occurs?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ARecovery comes late in the process: it restores systems to normal operation after the threat has been removed, not before an incident happens.
  2. BEradication removes the cause of an incident (malware, rogue accounts) once it is contained, so it cannot happen before an incident occurs.
  3. CCorrect: Preparation is the first step in CompTIA's incident response process, where the team writes procedures, assembles tools and trains people before anything goes wrong.
  4. DDetection is the step where an incident is noticed through alerts, logs or reports, so it starts only once something has already happened.

INC-002

Immediately following the conclusion of a cyber incident, a cybersecurity team is conducting a session to reflect on the incident's details and formulate future action plans. What type of session is this?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AArchiving evidence is a records task that keeps material for legal or later use; it is not a meeting to reflect on the incident and plan improvements.
  2. BUpdating the disaster recovery plan may be one outcome of the review, but it is a document change, not the session itself.
  3. CCorrect: A post-incident review (lessons-learned meeting) right after the incident looks at what happened and what worked, and turns that into action items.
  4. DRevising the incident response policy can come out of the review, but it is a follow-up action instead of the reflection session the stem describes.

INC-003

An organization discovered that their network had been breached. The security team managed to contain the breach, identify the entry point, eradicate the adversary's presence, and restore the affected systems. What should be their next step?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AWriting a new security policy may come out of the review, but drafting it first skips the step that tells you what the policy should change.
  2. BA company-wide notice is a communication decision made under the communication plan; it is not the next phase once recovery is complete.
  3. CCorrect: Once containment, eradication and recovery are done, the post-incident step is a lessons-learned review that captures root cause and improvements.
  4. DAsking for new funding may follow from the findings, but without the lessons-learned review there is no evidence for what the money should buy.

INC-004

A security analyst needs to perform incident triage. Which of the following factors is MOST important when prioritizing security incidents?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AHow long an investigation might take affects scheduling, but a quick case on a minor system should never jump ahead of a serious one.
  2. BWhere an attack appears to come from is easy to fake and says little about how much harm the incident can do.
  3. CCorrect: Triage ranks incidents by what is at stake: how critical the affected systems are, how sensitive the data is, and what the operational damage could be.
  4. DA sophisticated technique is interesting to analysts, yet a simple attack on a critical system can matter far more.

INC-005

Which approach is MOST effective for testing an organization's incident response plan?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AHanding the plan to every employee spreads awareness, yet it never shows whether the plan works under pressure.
  2. BCorrect: A simulated incident, such as a tabletop or a functional exercise, puts people through the plan and exposes gaps before a real incident does.
  3. CAn annual read-through keeps the document current, but reading a plan does not test how the team carries it out.
  4. DNew tools may help detection, but buying them tests nothing about the response plan itself.

INC-006

A company experienced a significant data breach due to vulnerabilities in their software. Which of the following is the first step they should take to respond to this incident?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Containment comes first once a breach is confirmed, because it stops further unauthorized access and limits the damage while the investigation continues.
  2. BCustomer notification follows the communication plan and legal advice once the scope is known; doing it before containment leaves the breach active.
  3. CA full system audit is a slow, broad review that belongs to analysis and post-incident work, too late for the immediate response to an active breach.
  4. DThe cause was a software vulnerability, so replacing hardware does not address it and would also destroy evidence.

INC-007

When responding to a web application attack, which containment action should be performed FIRST?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Blocking the attacking source IPs at the firewall or WAF is fast, targeted containment that stops the attack while the team investigates.
  2. BRebuilding the server is eradication and recovery work; doing it first destroys evidence and takes the application down without knowing the scope.
  3. CTaking the whole network offline is far out of proportion to one web application attack and causes more disruption than the attack itself.
  4. DDisabling every user account locks out legitimate users and does nothing about attack traffic coming from outside.

INC-008

What should be the FIRST step when responding to a suspected data exfiltration incident?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ANotifying customers is a later, legally driven step; it does not stop data from leaving and comes after the scope of the loss is known.
  2. BRebuilding servers is eradication or recovery work that destroys evidence and does not stop data that is leaving over an active channel.
  3. CCutting off every employee is disruptive and unfocused, and it fails if the exfiltration runs over an attacker-controlled channel rather than an employee account.
  4. DCorrect: Finding and blocking the channel the data is leaving through (a connection, protocol, service or account) is the containment step that stops further loss.

INC-009

Confirmed C2 callbacks are detected but scope is incomplete. What is the correct first action?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ABlocking known C2 IPs alone is easy to get around, because malware often switches to other addresses or domains, so the infected hosts stay under attacker control.
  2. BCorrect: With active C2 and an incomplete scope, isolating the affected hosts cuts the attacker off right away and keeps evidence on the hosts for analysis.
  3. CReimaging before containment and scoping destroys evidence and can miss other infected hosts that are still calling out.
  4. DEradication across the whole network before the scope is known is premature; you cannot reliably remove what you have not yet found.

INC-010

Based on the attacker lateral movement timeline, which action is the most appropriate immediate step?

Exhibit

TimeHostObserved Activity
08:15WKS-01Suspicious powershell execution
08:30WKS-01Pass-the-hash attempt successful to SRV-02
08:45SRV-02Scheduled task created for persistence

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AResetting admin credentials and patching are needed after a pass-the-hash compromise, but they are eradication steps, and the active foothold on both hosts must be contained first.
  2. BCorrect: Isolating WKS-01 and SRV-02 stops the attacker moving further from both compromised hosts and keeps them intact for forensics.
  3. CMemory images are valuable evidence, but capturing them on every host takes time and does not stop the movement that is happening now.
  4. DRebuilding from backups is recovery work; doing it now destroys evidence and leaves other footholds unknown.

INC-011

A SOC analyst detects ransomware lateral movement across a segmented corporate network. Evidence shows compromise limited to a single VLAN with no confirmed exfiltration. Which containment approach best balances operational continuity and spread prevention?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: EDR isolation of the affected hosts plus tighter ACLs on that VLAN stops the spread while the rest of the network keeps working.
  2. BBlocking all outbound traffic hurts the whole business and does not stop movement inside the network, which is what is spreading the ransomware.
  3. CWaiting for legal approval lets the ransomware keep spreading; routine containment is normally pre-authorized in the incident response plan and playbooks.
  4. DCutting all inter-VLAN routing is broader than needed when the compromise is confined to one VLAN, and it disrupts every other segment.

INC-012

Which containment strategy should be implemented when dealing with a compromised server that hosts critical business applications?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AShutting the server down stops the critical business applications and wipes volatile evidence such as memory.
  2. BRebuilding right away is an eradication and recovery step; doing it before scoping destroys evidence and may reinstall the same weakness.
  3. CCutting the server off the network completely stops the attacker, but it also takes down the critical applications the business depends on.
  4. DCorrect: logical containment uses network controls such as ACLs, firewall rules and segmentation to block the attacker's paths while the server keeps serving the business.

INC-013

Review the incident timeline log below. Which critical missing containment step allowed the compromise to progress to data exfiltration despite the workstation isolation?

Exhibit

TimeActorAction TakenResult
14:00AttackerPhishing email deliveredUser clicks malicious link
14:05AttackerPayload executionInitial access established
14:15AnalystIsolates user workstationWorkstation disconnected
14:30AttackerAccesses internal file shareData exfiltration begins

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ASegmenting the file server is a longer-term architecture change; it does not cancel the stolen credentials that the attacker is already using from somewhere else.
  2. BCorrect: The attacker kept reaching the file share after the workstation was isolated, which means they had the user's credentials or session, so resetting those and revoking active sessions was the missing step.
  3. CBlocking inbound connections at the perimeter does not stop an attacker who is already authenticated inside with valid credentials, and exfiltration usually goes outbound.
  4. DUpdating EDR signatures helps detect known malware, but it does nothing about an attacker logging in with a stolen identity.

INC-014

During a ransomware incident, which recovery method should be attempted FIRST if available?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Restoring from clean, offline backups is the most reliable recovery, because backups kept off the network during the attack should not be encrypted.
  2. BRebuilding everything from scratch takes far longer than restoring from backups and is only a fallback when no clean backups exist.
  3. CPaying the ransom gives no guarantee of a working decryptor, funds the attacker and may carry legal sanctions risk, so it is not a first choice.
  4. DBreaking modern ransomware encryption is not practical; free decryptors exist only for some families with known flaws, so this is not a first step.

INC-015

EDR has already network-isolated a marketing workstation after a confirmed initial access payload executed on it. The analyst has acknowledged the alert and verified the payload's malicious nature. What should triage do next, before the broader containment playbook runs?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AEDR has already isolated the workstation, so pulling its switch cable adds nothing; the open question is which other hosts are involved.
  2. BNotifying all executives at this point is premature; escalation follows the communication plan once the severity and scope are understood.
  3. CReimaging is eradication; doing it before scoping destroys evidence and can leave persistence on other hosts untouched.
  4. DCorrect: With the first host already isolated, triage sets the scope (for example, checking for lateral movement) so the containment playbook covers every affected host instead of only the first one found.

INC-016

Which of the following is NOT a recommended action to include in the preliminary analysis phase of incident response?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Bringing every employee into the analysis is not recommended; it spreads sensitive details, risks tipping off an insider and makes it easier to mishandle evidence.
  2. BTelling key stakeholders early, through the communication plan, is a normal part of the first analysis.
  3. CWorking out the scope of the incident is a central goal of the analysis step.
  4. DCollecting and preserving evidence early, with chain of custody, protects it for root-cause work and any legal action.

INC-017

An unauthorized access incident has been detected on a company's database. A cybersecurity analyst needs to establish how far-reaching the breach is and the potential consequences for the organization. Which of the following is the primary concern the analyst is addressing?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Working out how far the breach reaches and what it could cost the organization is assessing the scope of impact.
  2. BRTO (recovery time objective) is a continuity target for how long a system can be down; it is not about how far a breach spread.
  3. CData integrity is about whether data was changed, which is only one part of the impact the analyst is assessing.
  4. DDowntime measures how long a service is unavailable, which is narrower than the overall reach and consequences of a breach.

INC-018

After completing an incident response, which activity should be updated to ensure better readiness against potential future attacks of the same nature?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ANetwork configuration may change after an incident, but it does not capture how the team should respond next time.
  2. BAsset inventories support response, yet they record what you own rather than the steps for handling this attack type.
  3. CCorrect: Lessons learned feed back into the incident response playbooks, so the next attack of the same kind is handled faster and more consistently.
  4. DFirewall rules may be tightened as a fix, but they do not carry the response procedure forward.

Shift tally

0 / 0

The seven steps, asked and answered

Can I use NIST's four phases on objective 3.2?

Not safely. Objective 3.2 lists CompTIA's own seven steps (CS0-004 objectives, version 2.0, checked October 2026). The four-phase cycle came from NIST SP 800-61r2, which NIST SP 800-61r3 replaced in April 2025. Use NIST or SANS terms only when the stem names them.

How do I tell detection from analysis in a stem?

Detection is the moment an alert fires or someone reports something. Analysis is the work that follows: deciding whether it is an incident, how many systems it touches and how serious it is.

Should I treat recovery and restoration as the same thing?

Recovery is the step; restoration is one of the techniques inside it, listed under objective 3.3 with release from isolation and verification. Containment vs eradication vs recovery separates them.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.