CS0-003 Incident Response and Management Practice Question
Which of the following is the FIRST step in the NIST SP 800-61 incident response lifecycle?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preparation
The NIST SP 800-61 lifecycle begins with Preparation, which includes establishing policies, tools, and training before an incident occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Detection and Analysis
Why it's wrong here
Detection and Analysis is the second phase of the NIST SP 800-61 lifecycle, immediately following Preparation but preceding containment and recovery. It involves monitoring network telemetry, correlating alerts, verifying suspicious activity, and performing threat intelligence–enriched analysis to determine the scope, impact, and indicators of compromise. This phase is only possible when the preparation phase has already supplied the sensors, playbooks, and baselines, so it cannot be the first step in the process.
- ✗
Post-Incident Activity
Why it's wrong here
Post-Incident Activity is the final phase of the NIST SP 800-61 incident response lifecycle, taking place after the incident has been contained and remediated. It involves conducting a lessons-learned review, preserving evidence for potential legal or regulatory needs, and updating policies, playbooks, and training based on observed gaps. Because it synthesizes data from every preceding phase, it cannot logically occur first—it is the closing loop of the continuous improvement cycle.
- ✓
Preparation
Why this is correct
Preparation is the first phase in the NIST SP 800-61 incident response lifecycle, and it occurs before any incident actually happens. It entails building an incident response team, establishing communication plans, deploying necessary tooling (such as SIEM and EDR), creating playbooks, and conducting training and tabletop exercises. Without this pre-emptive groundwork, downstream phases like detection and analysis lack the required procedures and resources, making Preparation the non-negotiable starting point.
- ✗
Containment, Eradication, and Recovery
Why it's wrong here
Containment, Eradication, and Recovery is actually the third phase of the NIST SP 800-61 lifecycle, not the first. It follows Detection and Analysis, because responders must first know what they are dealing with before they can isolate affected hosts, remove malware and persistence mechanisms, and restore systems to normal operation. Attempting this phase prematurely, without a prepared baseline and an accurate analysis, risks spreading the incident or missing attacker footholds, which is why it cannot be entry-level.
Go deeper
Related to this question
Learn chapter
Endpoint Detection and Response
Key term
Preparation
Preparation is the first phase of incident response where organizations proactively establish policies, tools, training, and procedures to handle security incidents effectively.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.