CS0-004 - Incident Response and Management - Section 3.2

Summarize the incident response process.

Summarise the incident response lifecycle - preparation, detection and analysis, containment, eradication, recovery, and post-incident lessons learned - and the governance around it: playbooks, communication plans, roles and responsibilities, and testing. Recognise which activity belongs to which phase, since acting out of phase order is the classic response error.

IR lifecycle phasespreparation and playbookscontainment vs eradication vs recoverylessons learnedroles and communication plans

Practice question for this objective

Free sampleIncident Response and Managementmedium

During an active ransomware incident, an analyst confirms three file servers are encrypting shares and the malware is spreading laterally over SMB. Executives are pressing for a full rebuild of the affected servers straight away. Following the incident response lifecycle, what should the analyst do next?

  • AWipe and rebuild the three file servers immediately to restore service for the business
  • BIsolate the affected servers from the network to stop the lateral spread before any rebuild begins Correct
  • CRun a full antivirus scan across every server to remove the ransomware binary from disk
  • DBegin drafting the lessons-learned report while the encryption is still in progress
Containment to stop active spread precedes eradication and recovery in the incident response lifecycle. The incident response lifecycle orders containment before eradication and recovery so that active damage and lateral movement are stopped first, preserving other hosts and evidence before any cleanup or rebuild is attempted.

Why A is wrong: Rebuilding is a recovery task and appeals to executive pressure, but doing it while the malware is still spreading leaves other hosts exposed and destroys evidence needed for scoping.

Why B is correct: Containment precedes eradication and recovery in the lifecycle; isolating the hosts halts further encryption and lateral movement, which is the priority while spread is active.

Why C is wrong: Scanning to remove the binary is eradication and sounds decisive, but it does not stop the active lateral spread and comes before the incident is contained.

Why D is wrong: Lessons learned is a genuine phase and tempts an analyst wanting to capture detail early, but it is the final phase and does nothing to address an incident still unfolding.

See more CS0-004 practice questions, answers explained.

More in this domain

Back to all Incident Response and Management objectives, or the CS0-004 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.