Courseiva
Security OperationsmediumMultiple SelectObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst is reviewing the organization's incident response procedures. According to the NIST SP 800-61 framework, which four of the following are recognized phases of the incident response lifecycle? (Choose four.)

⚠ Common exam trap

It's easy for candidates to confuse proactive security activities like Threat Hunting or Risk Assessment with the formal incident response phases, but NIST SP 800-61 strictly lists only the four phases given as correct answers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Preparation

The NIST SP 800-61 Revision 2 framework defines the incident response lifecycle as consisting of four phases: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. These phases form a continuous cycle, with lessons learned from Post-Incident Activity feeding back into Preparation. The question asks for the four recognized phases, and these four options directly match the NIST model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Preparation

    Why this is correct

    Preparation is the correct initial phase because it involves establishing the incident response policy, assembling and training the response team, acquiring necessary tools, and defining communication and escalation procedures before any incident occurs. Without this groundwork, later phases lack the authority, resources, and playbooks needed to execute consistently. In the NIST SP 800-61 lifecycle, Preparation is the foundation that makes Detection, Containment, and Recovery effective.

  • Detection and Analysis

    Why this is correct

    Detection and Analysis is a legitimate phase of the incident response lifecycle, focused on identifying suspicious activity, triaging alerts, validating whether an incident has occurred, and determining its scope and impact. However, it is not the correct answer when the question targets the first phase because this stage relies on preparation artifacts such as monitoring baselines, defined alert thresholds, and trained analysts. It is executed after readiness is established, not before.

  • Containment, Eradication, and Recovery

    Why this is correct

    Containment, Eradication, and Recovery is a critical phase that involves isolating affected hosts, blocking malicious network traffic, removing the threat actor's presence, and restoring systems to known-good state. This phase is performed after Detection and Analysis confirms the incident and provides actionable indicators. It is a reactive, operational stage rather than the foundational first phase, so it cannot be the correct answer if the question asks for the initial step in the procedures.

  • Post-Incident Activity

    Why this is correct

    Post-Incident Activity is the final phase of the incident response lifecycle, encompassing lessons learned, after-action reviews, evidence retention, and updates to procedures, playbooks, and training. This phase ensures the organization improves its future handling of incidents by capturing what worked and what did not. Because it necessarily occurs after response and recovery are complete, it is not the phase to review first when examining an incident response program.

  • Threat Hunting

    Why it's wrong here

    Threat Hunting is not a phase of the NIST SP 800-61 incident response lifecycle; it is a proactive security operation where analysts search through networks, endpoints, and logs to discover hidden threats that evaded automated detection. While threat hunting can feed Detection and Analysis by producing hypotheses and indicators, it is a continuous, separate practice rather than a step in the formal response procedure. Therefore, it is incorrect for describing an incident response phase.

  • Risk Assessment

    Why it's wrong here

    Risk Assessment is a governance and planning activity used to identify, evaluate, and prioritize risks based on potential impact and likelihood, and it is not a phase within the incident response lifecycle. It may inform Preparation by helping decide which assets to monitor and which controls to deploy, but it does not occur after an incident is detected. Treating Risk Assessment as an incident response phase confuses proactive security management with reactive incident handling, so it is an incorrect choice.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.