Drag a concept onto its matching description — or click a concept then click the description.
Establish policies and tools
Identify potential incidents
Isolate affected systems
Remove threat from environment
Restore normal operations
Match each incident response phase to its activity.
Drag a concept onto its matching description — or click a concept then click the description.
Establish policies and tools
Identify potential incidents
Isolate affected systems
Remove threat from environment
Restore normal operations
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Preparation: Developing and maintaining incident response policies, procedures, and tools.
The incident response phases are correctly matched as: Preparation with developing policies, Detection and Analysis with identifying incidents, Containment, Eradication, and Recovery with limiting damage and restoring operations, and Post-Incident Activity with lessons learned. Common confusions include swapping Preparation and Detection activities.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
Preparation: Developing and maintaining incident response policies, procedures, and tools.
Why this is correct
Preparation is the proactive readiness phase that precedes any incident. It involves developing and maintaining the incident response policy, detailed procedures and playbooks, and acquiring the required tools and resources, such as forensic kits, communication systems, and monitoring infrastructure. This phase also includes training personnel, conducting tabletop exercises, and ensuring that the roles and responsibilities in the response plan align with legal and regulatory requirements.
Detection and Analysis: Identifying, analyzing, and validating potential security incidents.
Why this is correct
Detection and Analysis is the reactive phase where the organization actively identifies and validates potential security incidents. Security analysts monitor telemetry from SIEMs, EDR, and other sources, correlate indicators, and perform forensics to confirm whether an event is a true incident. The phase also assesses the scope, impact, and the tactics, techniques, and procedures (TTPs) involved, which is essential for determining an appropriate response and escalation path.
Containment, Eradication, and Recovery: Containing the incident, eradicating the threat, and restoring normal operations.
Why this is correct
Containment, Eradication, and Recovery is the action-oriented phase focused on stopping the threat and returning to normal operations. Containment isolates affected systems to limit lateral movement, eradication removes the root cause such as malware, backdoors, or compromised accounts, and recovery restores systems from clean backups while validating integrity. This phase often requires a delicate balance between preserving forensic evidence and achieving swift containment to minimize business impact.
Post-Incident Activity: Conducting post-mortem analysis, lessons learned, and updating procedures.
Why this is correct
Post-Incident Activity is the final phase that ensures the organization learns from the incident and improves its response capability. It involves conducting a post-mortem analysis, cataloging lessons learned, updating incident response procedures and playbooks, and potentially disseminating indicators of compromise (IOCs) to the broader security community. The goal is to identify process gaps, improve prevention and detection, and prevent recurrence of similar incidents.
Preparation: Identifying and analyzing potential security incidents.
Why it's wrong here
Identifying and analyzing potential security incidents is the core responsibility of the Detection and Analysis phase, not Preparation. Preparation is purely forward-looking and involves standing up policies, procedures, and tools before an incident occurs. Attributing this detection-centric activity to Preparation misrepresents the timeline and conflates proactive readiness with the reactive monitoring and validation actions that take place during an ongoing or suspected event.
Detection and Analysis: Developing incident response policies and procedures.
Why it's wrong here
Developing incident response policies and procedures is a foundational artifact of the Preparation phase, which sets the governance framework for the entire response effort. Detection and Analysis, in contrast, is concerned with real-time identification, triage, and deep investigation of potential threats, not the upfront creation of official guidance documents. While detection analysts may create operational notes, the formal IR policy and procedure set is established and maintained as part of preparation to provide a consistent response playbook.
Go deeper
Learn chapter
SIEM Log Analysis
Key term
Preparation
Preparation is the first phase of incident response where organizations proactively establish policies, tools, training, and procedures to handle security incidents effectively.
Key term
Eradication
Eradication is the phase in incident response where the root cause of a security breach is completely removed from the system to prevent the attack from happening again.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.