Triage BoardGet the app

Domain 3 · Incident Response and Management

Incident response techniques: plans, triage and evidence

Incident response techniques are the hands-on half of incident response on CS0-004 (objective 3.3): the plans and playbooks written in advance, the exercises that test them, and the work done mid-incident, from triage and the timeline through evidence handling, isolation, restoration and root cause analysis. CompTIA words it as a given a scenario objective (CS0-004 objectives, version 2.0, checked October 2026), so items describe a live incident and ask what you do next.

  • Exam code CS0-004
  • Domain weight 24%
  • Tickets here 18

One incident, technique by technique

  1. 09:02

    Alert

    The security information and event management (SIEM) system flags a new inbox rule on ap-clerk@example.com that forwards any message containing “invoice” to an address at example.net.

  2. 09:10

    Triage

    A finance mailbox, automatic forwarding outside the company, payment details in reach: the analyst rates it high and opens an incident.

  3. 09:25

    Correlation and enrichment

    Sign-in logs show the rule was created from 192.0.2.66, an address the user has never signed in from. Reputation and GeoIP results go into the ticket.

  4. 09:40

    Evidence

    Legal places a hold on the mailbox. The analyst exports the audit log and message trace, hashes both exports with SHA-256 and opens a chain-of-custody record.

  5. 10:05

    Isolation

    With the evidence saved: revoke the account's sessions, reset the password, require multifactor authentication (MFA) and delete the rule.

  6. 11:30

    Remediation and verification

    Search the tenant for other forwarding rules and unfamiliar app consents, then release the mailbox to the user and watch its sign-ins for a week.

  7. Day 5

    Root cause and corrective action

    The password was reused from a breached personal site, and the tenant allowed automatic forwarding to outside domains. Corrective actions: block external auto-forwarding and add an inbox-rule detection to the playbook.

The parts of objective 3.3, one at a time

Plans, playbooks and roles

The incident response (IR) plan says who is in charge, what counts as an incident and how severity is set. The communication plan says who talks to whom; it is a separate document, and objective 4.2 covers it in depth on incident reporting and communication. Playbooks are the per-scenario procedures: phishing, ransomware, a stolen credential. Many teams index them by ATT&CK technique so detection and response share one vocabulary. Roles name who leads, who does the technical work and who speaks for the organization, so nobody improvises authority in the middle of an incident.

Training: tabletop and simulation

CS0-004 names two kinds of exercise. A tabletop is a discussion around a scenario; nobody touches a system. A simulation has people perform the response against a staged incident. Both end with the same output: a list of gaps in the plan, each with an owner.

Log collection, correlation and enrichment

Collection gets the logs into one place, correlation links events from different sources into one story, and enrichment adds context such as asset owner, reputation and geolocation. A finding that rests on one log source is weaker than one confirmed by two.

Triage, timeline, severity and prioritization

Triage decides whether an alert deserves an analyst now. The timeline puts every event and every response action on one clock; record time zones, because logs from different systems rarely agree. Severity measures how bad an incident is; prioritization sets the order you work incidents in, and the two can differ.

Isolation, restoration and root cause

These techniques serve the seven steps of objective 3.2, laid out on the incident response process page; 3.3 is how each step gets done.

Isolate the affected target, remediate, verify the fix, and only then release it from isolation and restore service. Root cause analysis (RCA) asks why the incident was possible; corrective actions change that condition so the same path does not open again.

What the enrichment step reads

audit logSign-in and mailbox audit events for ap-clerk@example.com, the fictional incident above (UTC)
2026-10-05T16:40:03Z UserLoggedIn  ip=10.20.4.31  agent="Mozilla/5.0 (Windows NT 10.0)"2026-10-06T08:57:12Z UserLoggedIn  ip=192.0.2.66  agent="python-requests/2.31"2026-10-06T09:01:48Z New-InboxRule ip=192.0.2.66  name="."    SubjectOrBodyContainsWords="invoice" ForwardTo="billing-desk@example.net"    MarkAsRead=True

Addresses come from the RFC 1918 and RFC 5737 ranges. Three details carry the triage: a sign-in from a new address with a scripted user agent, a rule named with a single dot so it is easy to overlook, and MarkAsRead on the forwarded mail so the user never sees it.

Evidence terms that look alike

Chain of custody
The record of who held the evidence, when, and what they did with it, from collection to court. Details on the chain of custody page.
Data integrity validation
Proving the evidence has not changed: hash it (SHA-256) when collected and again before analysis; matching values are the proof.
Preservation
Keeping the original unchanged: work on copies, store the original read-only.
Legal hold
An instruction to suspend deletion of data that may be needed. It stops routine destruction; it does not collect anything.
Order of volatility
Collect the most short-lived data first: CPU registers and cache, then memory, temporary files, disk, remote logs, archival media (RFC 3227). See order of volatility.
Release from isolation
The recorded decision to reconnect a contained system after remediation has been verified.

Remediation without verification is unfinishedTrap

CS0-004 lists remediation and verification together. An option that closes the ticket straight after the patch, reset or rule deletion, with no rescan, log check or retest, skips the half that proves the fix worked. The same applies to release from isolation: it comes after verification.

Work the incident queue

These decisions are made in the middle of an incident, often with a log or tool output to read before you act.

Ticket 1 / 18

0 right

INC-001

Which component is essential to implement first for effective incident response management?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: The incident response plan comes first because it defines roles, authority, procedures, and communication paths that every later response action depends on.
  2. BData analytics helps analyze incident data during an investigation, but without a plan nobody knows who acts on the results or how.
  3. CAntivirus is a preventive and detective endpoint tool, not the foundation of incident response management.
  4. DA firewall is a preventive network control; it does not tell the team how to detect, escalate, or handle an incident.

INC-002

Which role is responsible for making critical business decisions during a major security incident?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AA network administrator carries out technical tasks such as blocking traffic but normally lacks the authority to make business-level decisions.
  2. BA security analyst investigates and recommends actions; the analyst escalates business decisions rather than making them.
  3. CCorrect: The incident commander has the authority to direct resources, approve containment that affects operations, and balance security against business needs.
  4. DA help desk technician handles user-facing support and ticket intake, not decisions about how the business responds to a major incident.

INC-003

What is the PRIMARY purpose of conducting a tabletop exercise for incident response?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ATesting technical security controls is the job of vulnerability scans, penetration tests or control validation, which a discussion-based tabletop exercise does not do.
  2. BA tabletop exercise is a walk-through of a scenario; it does not deploy or implement any tools.
  3. CPatching is a remediation activity; a tabletop changes no systems at all.
  4. DCorrect: A tabletop exercise walks the team through a scenario so each person can confirm they understand their role, decision points, and communication paths.

INC-004

Which testing method provides the MOST realistic evaluation of an organization's incident response capabilities?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ADocumentation review only checks that the plan exists and reads correctly; it never exercises people or systems.
  2. BCorrect: A full-scale simulation exercises people, processes, tools, and communications under conditions close to a real incident, so it gives the most realistic picture.
  3. CStaff interviews show what people believe they would do and cannot show how they actually perform under pressure.
  4. DChecklist validation confirms that steps are listed, which is the least realistic form of testing.

INC-005

During an incident response drill, a security analyst is tasked with monitoring the actions of both the red team and the blue team, as well as documenting the entire process. Which team is the security analyst most likely assigned to?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AThe blue team defends against the simulated attack; it does not oversee both sides.
  2. BThe red team plays the attacker; it is one of the participants being observed.
  3. CA green team is not the neutral overseer; the term usually refers to a team that builds or improves systems based on exercise findings.
  4. DCorrect: The white team acts as the neutral referee that plans the exercise, sets the rules, observes red and blue teams, and documents the results.

INC-006

A playbook requires analysts to immediately reimage any host showing suspicious behavior. Which statement identifies the primary pitfall of this guidance?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AApproval steps are about documentation and authority; the real problem is that the rule forces an action before anyone has scoped the incident.
  2. BReimaging immediately would, if anything, shorten time to respond; the real issue is lost evidence and scope.
  3. CCorrect: A blanket rule to reimage at the first sign of suspicion removes analyst judgment, destroys evidence, and hides how far the compromise has spread before scope is known.
  4. DLegal notification matters for some incidents, but missing it is not the main flaw of a playbook that wipes hosts before analysis.

INC-007

A confirmed Pass-the-Hash lateral-movement incident requires a repeatable playbook. Which set of steps should the playbook contain?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AIgnoring network logs misses exactly where Pass-the-Hash lateral movement shows up, such as NTLM authentications and SMB connections between hosts.
  2. BA generic malware scan plus isolating every workstation is not specific to the technique and causes needless disruption.
  3. CCorrect: A Pass-the-Hash playbook needs authentication log review (NTLM and Kerberos), credential resets, blocking lateral SMB paths, and detection tuning so the technique is caught next time.
  4. DClosing the ticket right after documentation skips containment, credential resets, and detection improvements, so the attacker keeps access.

INC-008

A junior analyst detects a suspicious login and immediately disables the affected user account before performing any contextual enrichment or coordinating with stakeholders. What is the most significant negative consequence of this incident response approach?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Acting before enrichment can kill active sessions and the volatile evidence tied to them, and it signals to the attacker that they have been noticed, which may make them change tactics.
  2. BDisabling an account removes access; it cannot hand the adversary administrative privileges.
  3. CBreach notification duties depend on whether data was compromised, and an analyst disabling an account does not trigger them.
  4. DDisabling one user account does not lock administrators out of the identity provider's console.

INC-009

When classifying security incidents, which factor MOST influences the incident priority level?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ATime of occurrence affects staffing and response logistics, but an incident at 3 a.m. is not automatically more severe.
  2. BCorrect: Priority is driven mainly by potential business impact, meaning effect on critical functions, regulated data, finances, and reputation.
  3. CThe affected system matters only through its business value, which is why business impact is the better answer.
  4. DTechnical complexity affects how hard the incident is to handle but has no bearing on how urgently it must be handled.

INC-010

Based on the SIEM alert queue below, which incident should the security analyst prioritize first?

Exhibit

TimeHostUserEventData Classification
08:12WKSTN-102J.DoeMultiple Failed LoginsPublic
08:15DB-FIN-01SYSTEMHigh Volume Outbound TrafficRegulated (PCI)
08:18DEV-SRV-04T.SmithMalware QuarantinedInternal
08:21WEB-EXT-01ApacheSQL Injection AttemptPublic

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: High outbound traffic from a database holding regulated PCI data points to possible active exfiltration on a critical asset, so it carries the highest business impact.
  2. BThe malware on DEV-SRV-04 was already quarantined, so the immediate threat is contained and the asset holds only internal data.
  3. CFailed logins on a workstation with public data may be a brute-force attempt, but nothing shows a successful compromise.
  4. DA SQL injection attempt against a public-facing server is common background noise unless there is evidence it succeeded.

INC-011

An incident timeline shows a compromised host with active network connections, running processes, and available memory artifacts. Which sequence of containment actions preserves the most forensic value while limiting business impact?

Exhibit

TimeEventArtifact Available
T+0Initial beacon detectedMemory dump possible
T+5Lateral SMB trafficProcess list captured
T+10Data staging beginsDisk image pending
T+15C2 callback confirmedNetwork flows logged

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: memory holds running processes, network connections and other volatile artifacts that are lost when the host is isolated or powered off, so capture it first and then isolate to stop the C2 and lateral movement.
  2. BA full disk image takes a long time, and while it runs the attacker keeps moving and staging data; disk is also less volatile than memory, so it comes later.
  3. CReimaging at once destroys all the evidence and leaves you blind to how far the attacker spread.
  4. DRebooting wipes memory and active connections, the most volatile evidence, and does not reliably remove persistence.

INC-012

EDR telemetry on the endpoints is kept for 7 days and the intrusion began 6 days ago; firewall logs are kept for 90 days. Which evidence collection step is required now for a complete investigation?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AFirewall logs are kept for 90 days and can wait, and rule change history alone would still miss the endpoint data that is about to age out.
  2. BCorrect: The earliest EDR records of the intrusion age out in about a day, so capture the EDR telemetry now or the timeline will have a gap at its start.
  3. CA weekly archive may run after the oldest EDR data has already expired, about a day from now.
  4. DDisk images alone lack process, network, and memory activity, so the timeline would be incomplete.

INC-013

Which documentation element is MOST critical to maintain throughout the incident response process?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AVendor SLAs may matter for escalation, but they do not record what happened during the incident.
  2. BCorrect: A detailed timeline of every action taken supports the investigation, legal proceedings, chain of custody, and the lessons-learned review.
  3. CContact lists belong in the incident response plan, prepared ahead of time; they are not the record kept during the response.
  4. DWarranty information has no role in documenting or investigating an incident.

INC-014

What term describes the process of investigating a suspected security breach on a network device that cannot be taken offline?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Live forensics collects evidence such as memory, running processes, and network connections from a system that must stay powered on and in service.
  2. BEndpoint security is a category of protective controls instead of a method of investigating a device.
  3. CHard drive imaging usually requires taking the system offline or capturing it as a static copy, which the scenario rules out.
  4. DPacket analysis examines network traffic; it does not investigate the device itself.

INC-015

A cybersecurity analyst is managing an incident that affects both IT systems and operational technology (OT) environments. What is the primary challenge unique to this scenario that must be addressed in the incident response plan?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AIT and OT rarely share a uniform patch process; OT patching is often limited by vendors and uptime, so uniformity is not the challenge to plan around.
  2. BCorrect: OT systems put safety and availability first and run different architectures and protocols, so the plan must handle different priorities, containment options, and recovery steps for each environment.
  3. CLimited connectivity between IT and OT is often a deliberate design, and it can even slow spread; it is not the unique planning challenge.
  4. DStandard firewall policies are routine network controls and do not address how IT and OT incidents must be handled differently.

INC-016

During the lessons learned phase of an incident involving a compromised remote access account, the analyst finds that the account's reused password was accepted by a VPN gateway that did not require MFA, and that the attacker then executed a malicious payload. What is the most accurate root cause?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: The root cause is the control failure that let the remote access account be abused, here the lack of mandatory MFA; everything after login is a consequence.
  2. BPrivilege escalation is a later step in the attack chain, a symptom of the compromise rather than its cause.
  3. CExecuting the payload is what the attacker did after gaining access, the proximate event that does not explain why access was possible.
  4. DLateral movement is another later step in the attack chain, so it cannot be the underlying weakness.

INC-017

Logs show credential theft followed by lateral movement. Patch history indicates delays and provisioning records lack MFA enforcement. What is the technical root cause?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AMissing EDR affects how fast the attack was detected but does not explain why the credentials could be stolen and reused.
  2. BUnpatched domain controllers are only part of the picture and ignore the credential theft and missing MFA shown in the evidence.
  3. CNothing in the logs points to brute force; the evidence shows credential theft, which weak passwords alone do not explain.
  4. DCorrect: The evidence ties the attack to stolen credentials that worked because MFA was not enforced, made worse by delayed patching, so that combination is the root cause.

INC-018

During root cause analysis following an incident, which technique helps identify underlying factors that contributed to the incident?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ARebooting is a recovery or troubleshooting action, and it can destroy volatile evidence; it does not uncover causes.
  2. BCorrect: The 5 Whys technique asks why repeatedly, moving past symptoms to the underlying process or control failure.
  3. CChanging passwords is a containment or remediation step and finds nothing about causes.
  4. DTerminating a user is an HR or disciplinary action and does nothing to find what contributed to an incident.

Shift tally

0 / 0

Before you move on

  • Plans, playbooks and roles are written before the incident; the communication plan is a separate document.
  • Collect, correlate, enrich: a finding confirmed by two log sources outweighs one.
  • Severity is how bad; prioritization is the order you work it in.
  • Hash at collection and again before analysis; a legal hold stops deletion but collects nothing.
  • Isolate, remediate, verify, then release and restore. RCA explains why; corrective action changes it.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.