220-1102 Operational Procedures Practice Question
According to incident response best practices, which step should be performed after containment, eradication, and recovery activities have been completed?
⚠ Common exam trap
Watch out — candidates often confuse the order of incident response phases and select 'Reporting to law enforcement' as the final step, but the CompTIA 220-1102 exam emphasizes that lessons learned is the concluding phase for process improvement, not legal reporting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lessons learned
The lessons learned phase is the standard final step in incident response frameworks such as NIST SP 800-61. After containment, eradication, and recovery have been completed, the team reviews the incident to identify process improvements, update playbooks, and document findings to prevent recurrence. This step ensures continuous improvement of the security posture rather than prematurely closing the incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Lessons learned
Why this is correct
Lessons learned is the formal post-incident review conducted after containment, eradication, and recovery are complete. The team analyzes the full timeline, evaluates the effectiveness of detection and response actions, and identifies specific improvements to processes, tools, training, and playbooks. This phase is explicitly required in frameworks like NIST SP 800-61 and is essential for closing the loop and preventing recurrence.
- ✗
Identification
Why it's wrong here
Identification is the earliest phase in the incident response lifecycle, where the organization detects a potential security event through intrusion detection systems, log analysis, or user reports and validates that it is indeed a real incident. It occurs at the very beginning of the response, before containment, eradication, and recovery, so it is chronologically opposite to a step that follows recovery. The question specifically asks for the step that should come after recovery, and identification is already long past by that point.
- ✗
Preparation
Why it's wrong here
Preparation is a continuous, forward-looking phase that takes place before any incident occurs, focusing on establishing response policies, hiring and training team members, acquiring forensic tools, and maintaining communication plans. It is not a step that happens after recovery; rather, it is the foundational groundwork that makes a successful response possible. After recovery, the team should engage in a retrospective lessons learned review, not preparation, which is about readiness for future incidents.
- ✗
Reporting to law enforcement
Why it's wrong here
Reporting to law enforcement is an optional and situational action that an organization may take during or after an incident if legal, regulatory, or contractual obligations are triggered, such as when criminal activity is suspected. It is not a formal phase in the incident response lifecycle and does not always occur after recovery; for example, a purely internal data breach may not require law enforcement involvement. The standard, universally recommended next step after recovery is the lessons learned review, not a police report.
Go deeper
Related to this question
Learn chapter
Backup and Recovery
Key term
Lessons learned
Lessons learned is the process of capturing, analyzing, and documenting knowledge gained from past incidents or projects to improve future security operations and prevent recurrence of problems.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.