Security OperationsQuestion 63 of 100
Which is the correct order of the incident response process?
a.Preparation, detection, containment, eradication, recovery, lessons learned
b.Detection, preparation, recovery, containment, eradication
c.Containment, detection, recovery, preparation, eradication
d.Recovery, containment, detection, preparation, lessons learned
Explanation
A standard incident response lifecycle proceeds through preparation, detection and analysis, containment, eradication, recovery, and lessons learned. Preparation comes first so the team is ready before an incident. Lessons learned closes the loop to improve future response.
Practice all 100 questions free — no signup required.
Related questions on this topic
- During incident response, which step focuses on limiting the damage and preventing the threat from spreading?
- Which system aggregates and correlates log data from many sources to detect security events in near real time?
- Which control monitors network traffic and actively blocks detected malicious activity inline?
- Which technology inspects data in motion and at rest to prevent unauthorized exfiltration of sensitive information?
- Which process applies vendor updates to fix known software vulnerabilities?
- Reducing a system's attack surface by disabling unneeded services and applying secure configurations is called:
Last reviewed: · editorial process
PrepPass Editorial Team · Verified against CompTIA Security+ (SY0-701) · How we review