220-1102 Operational Procedures Practice Question
A technician is documenting an incident response plan. According to industry best practices, which step should occur FIRST after a security incident is detected?
⚠ Common exam trap
Watch out — candidates often confuse the urgency of containment with the logical order of the incident response process, mistakenly believing that stopping the damage immediately is more important than first confirming what they are dealing with.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identification
Identification is the first step after detection because the incident response lifecycle (NIST SP 800-61) mandates that the nature and scope of the incident must be confirmed before any containment or eradication actions are taken. Without proper identification, containment could be applied to the wrong systems or miss critical indicators of compromise (IoCs), potentially causing data loss or legal issues. This step involves analyzing logs, alerts, and forensic evidence to validate that a security incident has actually occurred.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Containment
Why it's wrong here
In the incident response lifecycle defined by NIST SP 800-61, containment follows identification and analysis. Documenting the plan should begin with the identification phase because that is where analysts determine the existence and scope of a security event. Containment strategies—such as isolating affected hosts or blocking network traffic—are only meaningful after an incident has been confirmed, so they appear later in the plan.
- ✓
Identification
Why this is correct
Identification is the initial phase of the incident response lifecycle, as defined by frameworks such as NIST SP 800-61. It encompasses detecting potential security events, verifying whether an incident has occurred, and collecting preliminary data to inform subsequent actions. Documenting this step first is industry best practice because it ensures that responders know how to recognize and report incidents consistently, which is a prerequisite for all follow-up phases.
- ✗
Eradication
Why it's wrong here
Eradication, which involves removing the root cause of an incident—for example, deleting malware or revoking compromised credentials—occurs after the incident has been identified and contained. In a documented incident response plan, the eradication phase is placed later because it requires the findings from identification to know what to eliminate. Attempting to document eradication before identification would skip the essential detection and validation steps that determine the incident's nature and scope.
- ✗
Recovery
Why it's wrong here
Recovery is the phase where normal operations are restored, such as rebuilding systems from backups and verifying integrity, and it is inherently a late-stage activity. The incident response plan must first document identification because recovery actions are contingent upon understanding what happened and ensuring the threat is eliminated. Without proper identification, recovery cannot be safely executed, so recovery documentation follows in the plan's chronological structure.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Eradication
Eradication is the phase in incident response where the root cause of a security breach is completely removed from the system to prevent the attack from happening again.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.