Courseiva
mediumMultiple Select

CS0-003 Practice Question: Which TWO of the following are key phases of the…

Which TWO of the following are key phases of the incident response process as defined by NIST?

⚠ Common exam trap

The CS0-004 exam often tests the distinction between the four key NIST phases and the sub-steps within the third phase, causing candidates to mistakenly select Containment, Eradication, or Recovery as separate key phases instead of recognizing they are combined.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preparation

The NIST SP 800-61 Rev. 2 incident response lifecycle consists of four key phases: Preparation, Detection & Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. Option C (Preparation) is correct because it is the foundational phase where policies, tools (e.g., SIEM, EDR), and communication plans are established before any incident occurs. Option E (Post-Incident Activity) is correct because it includes lessons learned, evidence retention, and report generation to improve future response efforts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Recovery

    Why it's wrong here

    While recovery is a critical step in restoring affected systems to normal operations, it is not classified as a standalone primary phase under the NIST SP 800-61 r2 framework. Instead, it is grouped alongside containment and eradication within the single, broader phase known as Containment, Eradication, and Recovery.

  • ✗

    Containment

    Why it's wrong here

    Containment focuses on limiting the scope and impact of a security incident to prevent further damage. Under standard incident response frameworks like NIST, containment is treated as a sub-step within the "Containment, Eradication, and Recovery" phase rather than being designated as one of the four high-level, independent phases.

  • ✓

    Preparation

    Why this is correct

    Preparation is the foundational first phase of the incident response lifecycle, establishing the necessary policies, tools, and training before an incident occurs. This phase ensures that the organization has a trained Incident Response Team (IRT), defined communication channels, and pre-configured security controls to effectively handle threats.

  • ✗

    Eradication

    Why it's wrong here

    Eradication involves completely removing the root cause of an incident, such as deleting malware or disabling compromised user accounts. Although vital for ensuring a threat is fully eliminated, it is categorized as a component of the combined "Containment, Eradication, and Recovery" phase rather than serving as an independent primary phase.

  • ✓

    Post-Incident Activity

    Why this is correct

    Post-Incident Activity is the final primary phase of the incident response lifecycle, focusing on documenting lessons learned to improve future security posture. This phase involves conducting a thorough retrospective, updating incident response plans based on observed gaps, and retaining evidence in compliance with legal and organizational requirements.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.