easyMultiple SelectObjective-mapped
CAS-004 Practice Question: Which TWO of the following are key components of…
Which TWO of the following are key components of a successful incident response plan according to NIST SP 800-61?
⚠ Common exam trap
The CAS-004 exam often tests the distinction between activities that are part of the incident response lifecycle phases versus supporting security processes, leading candidates to mistakenly select vulnerability scanning or patch management as core components when they are actually separate operational tasks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preparation
NIST SP 800-61 defines the incident response lifecycle as having four phases: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. Preparation (Option B) is the foundational phase that ensures the organization has the tools, policies, and trained personnel ready before an incident occurs. Detection and Analysis (Option E) is the second phase, focusing on identifying and validating security incidents through monitoring, alerting, and forensic analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vulnerability scanning
Why it's wrong here
Vulnerability scanning is a security assessment technique, not a phase of the incident response plan.
- ✓
Preparation
Why this is correct
Preparation is a foundational phase of the incident response lifecycle.
- ✗
Patch management
Why it's wrong here
Patch management is an ongoing maintenance process, not a phase of incident response.
- ✗
User training
Why it's wrong here
User training is part of preparation but is not a separate phase in the NIST incident response lifecycle.
- ✓
Detection and Analysis
Why this is correct
Detection and Analysis is a critical phase in the incident response lifecycle.
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.