4.8 Explain appropriate incident response activities
Domain 4: Security Operations
Incident response questions revolve around the process lifecycle: preparation, detection, analysis, containment, eradication, recovery, and lessons learned. Memorize the order and, more importantly, be able to place a described action into the correct phase — isolating a compromised host is containment, rebuilding it is recovery, and updating the runbook afterward is lessons learned. Know the supporting activities: tabletop exercises and simulations for training and testing, threat hunting as proactive detection, and root cause analysis after the fact. Digital forensics has its own sub-vocabulary the exam tests directly: legal hold, chain of custody, acquisition, preservation, reporting, and e-discovery. Order of volatility guides what evidence to capture first. The most common candidate error is jumping phases — choosing eradication or recovery actions when the scenario is still mid-containment, or wiping a machine before evidence is preserved. Also distinguish an event from an incident, and remember that communication plans and escalation paths are decided in preparation, not improvised during the crisis.
What you must know
- incident response lifecycle
- containment vs eradication
- chain of custody
- order of volatility
- tabletop exercises
- root cause analysis
common pitfall · Candidates skip ahead in the lifecycle, picking eradication or recovery actions when the scenario still calls for containment or evidence preservation.
Try a sample question
A security analyst confirms that ransomware is actively encrypting files on a corporate file server, and the incident response plan has been activated. Which of the following actions are part of the containment phase? (Select TWO.)
- A Disconnecting the infected server from the network
- B Restoring the encrypted files from the most recent backup
- C Interviewing staff about what went well during the response
- D Disabling the user accounts the attacker is using
- E Writing the final incident report for leadership
Show answer & explanations
- A correct ·Disconnecting the infected server stops the ransomware from encrypting network shares and spreading laterally to other hosts, which is the core purpose of the containment phase.
- B Restoring files from backup is a recovery activity that returns systems to normal operation; performing it before containment risks the restored data being encrypted all over again.
- C Interviews about what went well and what failed belong to the lessons-learned stage after resolution, not to the immediate effort to stop the ransomware from spreading.
- D correct ·Disabling the accounts the attacker is using removes their access and limits further malicious activity, a standard containment step performed alongside isolating the affected systems.
- E The final report is produced during post-incident activity once the timeline and impact are fully understood; writing it now would divert effort from stopping active damage.
sample item — the full bank runs 450+ questions at exam difficulty
Is objective 4.8 your weak spot?
The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.
Check my readiness — free