CS0-003 Incident Response and Management Practice Question
During which phase of the NIST SP 800-61 incident response lifecycle would an organization conduct a lessons learned meeting?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Post-Incident Activity
The post-incident activity phase includes lessons learned, root cause analysis, and improvement actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Containment, Eradication, and Recovery
Why it's wrong here
The Containment, Eradication, and Recovery phase is dedicated to actively stopping the spread of the incident, removing the attacker's foothold, and restoring affected systems to normal operation, all of which happen while the incident is still live, well before any retrospective review is convened.
- ✗
Detection and Analysis
Why it's wrong here
Detection and Analysis is the earliest operational phase, focused on identifying indicators of compromise and confirming that an incident is actually occurring, which happens at the start of the timeline and has not yet generated the outcomes a lessons-learned meeting would evaluate.
- ✓
Post-Incident Activity
Why this is correct
NIST SP 800-61 explicitly places the lessons-learned meeting within Post-Incident Activity, where the team reviews the full incident timeline, evaluates response effectiveness, updates playbooks and detection rules, and produces a formal report once containment and recovery are complete.
- ✗
Preparation
Why it's wrong here
Preparation occurs before any incident is even detected and covers building the incident response plan, training staff, and deploying tools and baselines, so by definition it precedes the incident entirely and cannot include a retrospective on how that incident was handled.
Go deeper
Related to this question
Learn chapter
DDoS Attack Incident Response
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Root cause analysis
Root cause analysis is a systematic process used to identify the fundamental underlying cause of a problem, rather than just treating its symptoms.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.