Courseiva
Operational Procedures →easyMultiple Choice

220-1102 Operational Procedures Practice Question

A technician is documenting an incident response plan. According to industry best practices, which step should occur FIRST after a security incident is detected?

⚠ Common exam trap

Watch out — candidates often confuse the urgency of containment with the logical order of the incident response process, mistakenly believing that stopping the damage immediately is more important than first confirming what they are dealing with.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identification

Identification is the first step after detection because the incident response lifecycle (NIST SP 800-61) mandates that the nature and scope of the incident must be confirmed before any containment or eradication actions are taken. Without proper identification, containment could be applied to the wrong systems or miss critical indicators of compromise (IoCs), potentially causing data loss or legal issues. This step involves analyzing logs, alerts, and forensic evidence to validate that a security incident has actually occurred.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Containment

    Why it's wrong here

    In the incident response lifecycle defined by NIST SP 800-61, containment follows identification and analysis. Documenting the plan should begin with the identification phase because that is where analysts determine the existence and scope of a security event. Containment strategies—such as isolating affected hosts or blocking network traffic—are only meaningful after an incident has been confirmed, so they appear later in the plan.

  • ✓

    Identification

    Why this is correct

    Identification is the initial phase of the incident response lifecycle, as defined by frameworks such as NIST SP 800-61. It encompasses detecting potential security events, verifying whether an incident has occurred, and collecting preliminary data to inform subsequent actions. Documenting this step first is industry best practice because it ensures that responders know how to recognize and report incidents consistently, which is a prerequisite for all follow-up phases.

  • ✗

    Eradication

    Why it's wrong here

    Eradication, which involves removing the root cause of an incident—for example, deleting malware or revoking compromised credentials—occurs after the incident has been identified and contained. In a documented incident response plan, the eradication phase is placed later because it requires the findings from identification to know what to eliminate. Attempting to document eradication before identification would skip the essential detection and validation steps that determine the incident's nature and scope.

  • ✗

    Recovery

    Why it's wrong here

    Recovery is the phase where normal operations are restored, such as rebuilding systems from backups and verifying integrity, and it is inherently a late-stage activity. The incident response plan must first document identification because recovery actions are contingent upon understanding what happened and ensuring the threat is eliminated. Without proper identification, recovery cannot be safely executed, so recovery documentation follows in the plan's chronological structure.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.