Courseiva
easyMultiple SelectObjective-mapped

CAS-004 Practice Question: Which TWO of the following are key components of…

Which TWO of the following are key components of a successful incident response plan according to NIST SP 800-61?

⚠ Common exam trap

The CAS-004 exam often tests the distinction between activities that are part of the incident response lifecycle phases versus supporting security processes, leading candidates to mistakenly select vulnerability scanning or patch management as core components when they are actually separate operational tasks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Preparation

NIST SP 800-61 defines the incident response lifecycle as having four phases: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. Preparation (Option B) is the foundational phase that ensures the organization has the tools, policies, and trained personnel ready before an incident occurs. Detection and Analysis (Option E) is the second phase, focusing on identifying and validating security incidents through monitoring, alerting, and forensic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Vulnerability scanning

    Why it's wrong here

    Vulnerability scanning is a security assessment technique, not a phase of the incident response plan.

  • Preparation

    Why this is correct

    Preparation is a foundational phase of the incident response lifecycle.

  • Patch management

    Why it's wrong here

    Patch management is an ongoing maintenance process, not a phase of incident response.

  • User training

    Why it's wrong here

    User training is part of preparation but is not a separate phase in the NIST incident response lifecycle.

  • Detection and Analysis

    Why this is correct

    Detection and Analysis is a critical phase in the incident response lifecycle.

About these practice questions

One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.