SY0-701 - Security Operations (28% of the exam) - Section 4.8

Explain appropriate incident response activities.

Describe the incident response lifecycle from preparation through containment, eradication, recovery, and lessons learned, and explain how digital forensics supports root cause analysis without compromising evidence integrity. Recognise which phase each activity belongs to, and understand why preparation - including playbooks and communication plans - determines how effectively teams execute the later phases under pressure.

incident response processpreparationcontainment and eradicationroot cause analysisdigital forensics

Practice question for this objective

Free sampleSecurity Operationsmedium

Which statement most accurately captures the defining purpose of digital forensics as it supports the incident response process?

  • ADigital forensics is the activity of patching exploited vulnerabilities on affected systems so that the same flaw cannot be re-used by the attacker once recovery is complete.
  • BDigital forensics is the rapid blocking of known malicious indicators at firewalls and proxies during an active incident so that command and control traffic stops reaching infected hosts.
  • CDigital forensics is the structured collection, preservation, and analysis of digital evidence using a defensible chain of custody so that findings stand up to internal, regulatory, or legal scrutiny. Correct
  • DDigital forensics is the periodic review of security policies and standards by an internal audit team to confirm that the organisation is complying with its own documented control set.
Recognise digital forensics as the structured, defensible collection, preservation, and analysis of digital evidence in support of incident response. Digital forensics gives incident response its evidentiary backbone. Acquiring data with proven techniques, preserving its integrity through hashing, and maintaining a documented chain of custody allow the resulting analysis to support internal decisions, regulatory reporting, and legal proceedings, which is the role the SY0-701 incident response activities objective assigns to it.

Why A is wrong: Patching exploited vulnerabilities is part of eradication or longer-term remediation; digital forensics is concerned with collecting and analysing evidence, not with applying fixes to the underlying flaws.

Why B is wrong: Rapid blocking of indicators at the perimeter is a containment action driven by threat intelligence; digital forensics may inform such blocks but is itself the evidence-handling discipline rather than the blocking action.

Why C is correct: Digital forensics is defined by sound evidence handling: acquiring data in a repeatable way, preserving its integrity with hashes, maintaining a documented chain of custody, and analysing it so the results are defensible in internal reviews, regulatory action, or court.

Why D is wrong: Periodic policy and control reviews by internal audit are governance activities; digital forensics is the technical evidence discipline that supports incident response and any subsequent investigations, not a compliance review function.

See more SY0-701 practice questions, answers explained.

Exam traps in Security Operations

Answers that look right on this material and are not. Each one is a distractor from a different question in the SY0-701 bank for this domain.

  • Subscribe to a commercial threat intelligence feed, deploy a new endpoint detection product across the estate, and stand up a 24x7 managed detection service so that future incidents are identified more quickly at the technical layer.

    Why it is wrong: Improved detection shortens time to discover an incident but does nothing about the decision-making, contact, and documentation problems that delayed the previous response for six hours after the event was already known. The investments target a different phase of the response than the one the review identified as broken.

  • Catalogue every indicator of compromise observed during the incident and submit the file hashes and network signatures to the SOC platform so that any recurrence is detected more quickly.

    Why it is wrong: Capturing and sharing indicators of compromise is a valuable lessons learned and detection engineering activity, but it answers what the attacker did rather than why the organisation was vulnerable in the first place. Root cause analysis is about identifying the underlying condition that allowed the incident, not enumerating the surface artefacts.

  • Preparation is the phase in which responders confirm that an active intrusion is in progress and then classify it by severity before any containment work begins.

    Why it is wrong: Confirming an active intrusion and classifying its severity is the detection and analysis phase; preparation happens long before an incident is declared and does not depend on any specific event.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.