Courseiva

CS0-003 Incident Response and Management Practice Question

During which phase of the NIST SP 800-61 incident response lifecycle would an organization conduct a lessons learned meeting?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Post-Incident Activity

The post-incident activity phase includes lessons learned, root cause analysis, and improvement actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Containment, Eradication, and Recovery

    Why it's wrong here

    The Containment, Eradication, and Recovery phase is dedicated to actively stopping the spread of the incident, removing the attacker's foothold, and restoring affected systems to normal operation, all of which happen while the incident is still live, well before any retrospective review is convened.

  • ✗

    Detection and Analysis

    Why it's wrong here

    Detection and Analysis is the earliest operational phase, focused on identifying indicators of compromise and confirming that an incident is actually occurring, which happens at the start of the timeline and has not yet generated the outcomes a lessons-learned meeting would evaluate.

  • ✓

    Post-Incident Activity

    Why this is correct

    NIST SP 800-61 explicitly places the lessons-learned meeting within Post-Incident Activity, where the team reviews the full incident timeline, evaluates response effectiveness, updates playbooks and detection rules, and produces a formal report once containment and recovery are complete.

  • ✗

    Preparation

    Why it's wrong here

    Preparation occurs before any incident is even detected and covers building the incident response plan, training staff, and deploying tools and baselines, so by definition it precedes the incident entirely and cannot include a retrospective on how that incident was handled.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.