Courseiva

CS0-003 Incident Response and Management Practice Question

An organization is implementing an incident response plan. Which phase of the NIST SP 800-61 lifecycle includes activities such as creating policies, establishing IR teams, and acquiring necessary tools?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preparation

Preparation involves all proactive measures to enable effective incident response, including policy, team, and tool readiness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Containment, Eradication, and Recovery

    Why it's wrong here

    While this phase is critical for limiting the blast radius of an active threat, neutralizing the adversary's presence, and restoring affected systems to a secure baseline, it occurs after an incident has already been identified. It does not encompass the proactive planning, policy creation, or tool deployment activities that establish an organization's baseline readiness.

  • ✗

    Detection and Analysis

    Why it's wrong here

    This phase involves monitoring security feeds, analyzing alerts from SIEM or EDR tools, and validating whether an anomalous event constitutes a true security incident. Because it relies on active monitoring and triage of live events, it is reactive to ongoing threats rather than establishing the foundational policies, training, and infrastructure required beforehand.

  • ✓

    Preparation

    Why this is correct

    Preparation is the foundational phase of the NIST incident response lifecycle that occurs before any security event begins. It involves establishing incident response capabilities, drafting playbooks, training personnel, securing communication channels, and deploying defensive tools. Implementing the incident response plan itself is a core component of this proactive readiness phase.

  • ✗

    Post-Incident Activity

    Why it's wrong here

    This final phase focuses on conducting "lessons learned" sessions, updating incident response plans based on forensic findings, and retaining evidence for legal compliance. It occurs strictly after an incident has been fully resolved and closed, making it incorrect for the initial implementation of readiness controls and proactive planning.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.