CS0-003 Incident Response and Management Practice Question
An organization is implementing an incident response plan. Which phase of the NIST SP 800-61 lifecycle includes activities such as creating policies, establishing IR teams, and acquiring necessary tools?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preparation
Preparation involves all proactive measures to enable effective incident response, including policy, team, and tool readiness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Containment, Eradication, and Recovery
Why it's wrong here
While this phase is critical for limiting the blast radius of an active threat, neutralizing the adversary's presence, and restoring affected systems to a secure baseline, it occurs after an incident has already been identified. It does not encompass the proactive planning, policy creation, or tool deployment activities that establish an organization's baseline readiness.
- ✗
Detection and Analysis
Why it's wrong here
This phase involves monitoring security feeds, analyzing alerts from SIEM or EDR tools, and validating whether an anomalous event constitutes a true security incident. Because it relies on active monitoring and triage of live events, it is reactive to ongoing threats rather than establishing the foundational policies, training, and infrastructure required beforehand.
- ✓
Preparation
Why this is correct
Preparation is the foundational phase of the NIST incident response lifecycle that occurs before any security event begins. It involves establishing incident response capabilities, drafting playbooks, training personnel, securing communication channels, and deploying defensive tools. Implementing the incident response plan itself is a core component of this proactive readiness phase.
- ✗
Post-Incident Activity
Why it's wrong here
This final phase focuses on conducting "lessons learned" sessions, updating incident response plans based on forensic findings, and retaining evidence for legal compliance. It occurs strictly after an incident has been fully resolved and closed, making it incorrect for the initial implementation of readiness controls and proactive planning.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.