SY0-701 - Security Operations - Section 4.8

Explain appropriate incident response activities.

Describe the incident response lifecycle from preparation through containment, eradication, recovery, and lessons learned, and explain how digital forensics supports root cause analysis without compromising evidence integrity. Recognise which phase each activity belongs to, and understand why preparation - including playbooks and communication plans - determines how effectively teams execute the later phases under pressure.

incident response processpreparationcontainment and eradicationroot cause analysisdigital forensics

Practice question for this objective

Free sampleSecurity Operationsmedium

Which statement most accurately captures the defining purpose of digital forensics as it supports the incident response process?

  • ADigital forensics is the activity of patching exploited vulnerabilities on affected systems so that the same flaw cannot be re-used by the attacker once recovery is complete.
  • BDigital forensics is the rapid blocking of known malicious indicators at firewalls and proxies during an active incident so that command and control traffic stops reaching infected hosts.
  • CDigital forensics is the structured collection, preservation, and analysis of digital evidence using a defensible chain of custody so that findings stand up to internal, regulatory, or legal scrutiny. Correct
  • DDigital forensics is the periodic review of security policies and standards by an internal audit team to confirm that the organisation is complying with its own documented control set.
Recognise digital forensics as the structured, defensible collection, preservation, and analysis of digital evidence in support of incident response. Digital forensics gives incident response its evidentiary backbone. Acquiring data with proven techniques, preserving its integrity through hashing, and maintaining a documented chain of custody allow the resulting analysis to support internal decisions, regulatory reporting, and legal proceedings, which is the role the SY0-701 incident response activities objective assigns to it.

Why A is wrong: Patching exploited vulnerabilities is part of eradication or longer-term remediation; digital forensics is concerned with collecting and analysing evidence, not with applying fixes to the underlying flaws.

Why B is wrong: Rapid blocking of indicators at the perimeter is a containment action driven by threat intelligence; digital forensics may inform such blocks but is itself the evidence-handling discipline rather than the blocking action.

Why C is correct: Digital forensics is defined by sound evidence handling: acquiring data in a repeatable way, preserving its integrity with hashes, maintaining a documented chain of custody, and analysing it so the results are defensible in internal reviews, regulatory action, or court.

Why D is wrong: Periodic policy and control reviews by internal audit are governance activities; digital forensics is the technical evidence discipline that supports incident response and any subsequent investigations, not a compliance review function.

See more SY0-701 practice questions with worked answers.

More in this domain

Back to all Security Operations objectives, or the SY0-701 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.