CS0-003 Incident Response and Management Practice Question
During the preparation phase of the NIST SP 800-61 incident response lifecycle, a security analyst is tasked with ensuring the team has the necessary tools and resources. Which of the following is the MOST important activity to perform during this phase?
⚠ Common exam trap
CS0-004 often tests phase mapping — candidates see a security activity that sounds important (sharing IOCs, sandboxing malware) and pick it without checking whether it belongs to the preparation phase versus detection, analysis, or post-incident activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Developing and testing incident response playbooks
In the NIST SP 800-61 preparation phase, the most important activity is establishing the capability to respond before an incident occurs, which centers on developing, documenting, and testing incident response playbooks. Playbooks codify roles, communication paths, and step-by-step procedures so the team can act consistently under pressure. Testing them (tabletop exercises, simulations) validates that tools, contacts, and escalation paths actually work.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sharing indicators of compromise with threat intel platforms
Why it's wrong here
Sharing indicators of compromise (IOCs) with external threat intelligence platforms or ISACs is a key component of the Post-Incident Activity phase. During this final phase, organizations compile lessons learned and distribute threat data to improve collective defense. Doing this during preparation is impossible as the specific incident-related IOCs have not yet been generated or identified.
- ✓
Developing and testing incident response playbooks
Why this is correct
Developing, documenting, and testing incident response playbooks through tabletop exercises or simulations is a fundamental task of the Preparation phase. This proactive step ensures that the incident response team has validated, repeatable procedures to follow when an active threat is detected. It establishes the necessary operational readiness before any actual security incident occurs.
- ✗
Conducting root cause analysis of past incidents
Why it's wrong here
Conducting a comprehensive root cause analysis (RCA) of past security incidents is performed during the Post-Incident Activity (or Lessons Learned) phase. This retrospective analysis aims to identify the underlying vulnerabilities or process failures that allowed the breach to occur. While the output of this analysis can inform future preparation, the act of conducting the RCA itself belongs to the post-incident phase.
- ✗
Analyzing malware samples in a sandbox
Why it's wrong here
Analyzing suspicious malware samples within an isolated sandbox environment is an active investigative task that occurs during the Detection and Analysis phase. This technical analysis helps responders understand the capabilities, behavior, and impact of a live threat currently affecting the network. It is a reactive measure taken once an indicator of compromise has already triggered an alert.
Go deeper
Related to this question
Learn chapter
Endpoint Detection and Response
Key term
Incident response lifecycle
The Incident response lifecycle is the structured process organizations follow to detect, contain, eradicate, and recover from cybersecurity incidents while learning from each event to improve future defenses.
Key term
Preparation
Preparation is the first phase of incident response where organizations proactively establish policies, tools, training, and procedures to handle security incidents effectively.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.