SY0-701 Security Operations Practice Question
A security analyst is reviewing the organization's incident response procedures. According to the NIST SP 800-61 framework, which four of the following are recognized phases of the incident response lifecycle? (Choose four.)
⚠ Common exam trap
It's easy for candidates to confuse proactive security activities like Threat Hunting or Risk Assessment with the formal incident response phases, but NIST SP 800-61 strictly lists only the four phases given as correct answers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preparation
The NIST SP 800-61 Revision 2 framework defines the incident response lifecycle as consisting of four phases: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. These phases form a continuous cycle, with lessons learned from Post-Incident Activity feeding back into Preparation. The question asks for the four recognized phases, and these four options directly match the NIST model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Preparation
Why this is correct
Preparation is the correct initial phase because it involves establishing the incident response policy, assembling and training the response team, acquiring necessary tools, and defining communication and escalation procedures before any incident occurs. Without this groundwork, later phases lack the authority, resources, and playbooks needed to execute consistently. In the NIST SP 800-61 lifecycle, Preparation is the foundation that makes Detection, Containment, and Recovery effective.
- ✓
Detection and Analysis
Why this is correct
Detection and Analysis is a legitimate phase of the incident response lifecycle, focused on identifying suspicious activity, triaging alerts, validating whether an incident has occurred, and determining its scope and impact. However, it is not the correct answer when the question targets the first phase because this stage relies on preparation artifacts such as monitoring baselines, defined alert thresholds, and trained analysts. It is executed after readiness is established, not before.
- ✓
Containment, Eradication, and Recovery
Why this is correct
Containment, Eradication, and Recovery is a critical phase that involves isolating affected hosts, blocking malicious network traffic, removing the threat actor's presence, and restoring systems to known-good state. This phase is performed after Detection and Analysis confirms the incident and provides actionable indicators. It is a reactive, operational stage rather than the foundational first phase, so it cannot be the correct answer if the question asks for the initial step in the procedures.
- ✓
Post-Incident Activity
Why this is correct
Post-Incident Activity is the final phase of the incident response lifecycle, encompassing lessons learned, after-action reviews, evidence retention, and updates to procedures, playbooks, and training. This phase ensures the organization improves its future handling of incidents by capturing what worked and what did not. Because it necessarily occurs after response and recovery are complete, it is not the phase to review first when examining an incident response program.
- ✗
Threat Hunting
Why it's wrong here
Threat Hunting is not a phase of the NIST SP 800-61 incident response lifecycle; it is a proactive security operation where analysts search through networks, endpoints, and logs to discover hidden threats that evaded automated detection. While threat hunting can feed Detection and Analysis by producing hypotheses and indicators, it is a continuous, separate practice rather than a step in the formal response procedure. Therefore, it is incorrect for describing an incident response phase.
- ✗
Risk Assessment
Why it's wrong here
Risk Assessment is a governance and planning activity used to identify, evaluate, and prioritize risks based on potential impact and likelihood, and it is not a phase within the incident response lifecycle. It may inform Preparation by helping decide which assets to monitor and which controls to deploy, but it does not occur after an incident is detected. Treating Risk Assessment as an incident response phase confuses proactive security management with reactive incident handling, so it is an incorrect choice.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Incident response lifecycle
The Incident response lifecycle is the structured process organizations follow to detect, contain, eradicate, and recover from cybersecurity incidents while learning from each event to improve future defenses.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.