Courseiva
Incident Response and ManagementeasyMultiple ChoiceObjective-mapped

CS0-003 Incident Response and Management Practice Question

Which of the following is the FIRST step in the NIST SP 800-61 incident response lifecycle?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Preparation

The NIST SP 800-61 lifecycle begins with Preparation, which includes establishing policies, tools, and training before an incident occurs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Detection and Analysis

    Why it's wrong here

    Detection and Analysis is the second phase of the NIST SP 800-61 lifecycle, immediately following Preparation but preceding containment and recovery. It involves monitoring network telemetry, correlating alerts, verifying suspicious activity, and performing threat intelligence–enriched analysis to determine the scope, impact, and indicators of compromise. This phase is only possible when the preparation phase has already supplied the sensors, playbooks, and baselines, so it cannot be the first step in the process.

  • Post-Incident Activity

    Why it's wrong here

    Post-Incident Activity is the final phase of the NIST SP 800-61 incident response lifecycle, taking place after the incident has been contained and remediated. It involves conducting a lessons-learned review, preserving evidence for potential legal or regulatory needs, and updating policies, playbooks, and training based on observed gaps. Because it synthesizes data from every preceding phase, it cannot logically occur first—it is the closing loop of the continuous improvement cycle.

  • Preparation

    Why this is correct

    Preparation is the first phase in the NIST SP 800-61 incident response lifecycle, and it occurs before any incident actually happens. It entails building an incident response team, establishing communication plans, deploying necessary tooling (such as SIEM and EDR), creating playbooks, and conducting training and tabletop exercises. Without this pre-emptive groundwork, downstream phases like detection and analysis lack the required procedures and resources, making Preparation the non-negotiable starting point.

  • Containment, Eradication, and Recovery

    Why it's wrong here

    Containment, Eradication, and Recovery is actually the third phase of the NIST SP 800-61 lifecycle, not the first. It follows Detection and Analysis, because responders must first know what they are dealing with before they can isolate affected hosts, remove malware and persistence mechanisms, and restore systems to normal operation. Attempting this phase prematurely, without a prepared baseline and an accurate analysis, risks spreading the incident or missing attacker footholds, which is why it cannot be entry-level.

About these practice questions

One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.