mediumMultiple Select
CS0-003 Practice Question: Which TWO of the following are key phases of the…
Which TWO of the following are key phases of the incident response process as defined by NIST?
⚠ Common exam trap
The CS0-004 exam often tests the distinction between the four key NIST phases and the sub-steps within the third phase, causing candidates to mistakenly select Containment, Eradication, or Recovery as separate key phases instead of recognizing they are combined.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preparation
The NIST SP 800-61 Rev. 2 incident response lifecycle consists of four key phases: Preparation, Detection & Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. Option C (Preparation) is correct because it is the foundational phase where policies, tools (e.g., SIEM, EDR), and communication plans are established before any incident occurs. Option E (Post-Incident Activity) is correct because it includes lessons learned, evidence retention, and report generation to improve future response efforts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Recovery
Why it's wrong here
While recovery is a critical step in restoring affected systems to normal operations, it is not classified as a standalone primary phase under the NIST SP 800-61 r2 framework. Instead, it is grouped alongside containment and eradication within the single, broader phase known as Containment, Eradication, and Recovery.
- ✗
Containment
Why it's wrong here
Containment focuses on limiting the scope and impact of a security incident to prevent further damage. Under standard incident response frameworks like NIST, containment is treated as a sub-step within the "Containment, Eradication, and Recovery" phase rather than being designated as one of the four high-level, independent phases.
- ✓
Preparation
Why this is correct
Preparation is the foundational first phase of the incident response lifecycle, establishing the necessary policies, tools, and training before an incident occurs. This phase ensures that the organization has a trained Incident Response Team (IRT), defined communication channels, and pre-configured security controls to effectively handle threats.
- ✗
Eradication
Why it's wrong here
Eradication involves completely removing the root cause of an incident, such as deleting malware or disabling compromised user accounts. Although vital for ensuring a threat is fully eliminated, it is categorized as a component of the combined "Containment, Eradication, and Recovery" phase rather than serving as an independent primary phase.
- ✓
Post-Incident Activity
Why this is correct
Post-Incident Activity is the final primary phase of the incident response lifecycle, focusing on documenting lessons learned to improve future security posture. This phase involves conducting a thorough retrospective, updating incident response plans based on observed gaps, and retaining evidence in compliance with legal and organizational requirements.
Go deeper
Related to this question
Learn chapter
Business Email Compromise (BEC) Response
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
Key term
Preparation
Preparation is the first phase of incident response where organizations proactively establish policies, tools, training, and procedures to handle security incidents effectively.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.