CompTIA Security+ guideHigh-value skills

Security+ Incident Response: Steps and Next Actions

Use one fictional incident to separate an alert from a confirmed incident, and containment from eradication and recovery.

Short answer

SY0-701 lists incident response as preparation, detection, analysis, containment, eradication, recovery, and lessons learned. An alert is not yet an incident. Containment limits damage, eradication removes the cause, and recovery restores service. NIST withdrew SP 800-61 Rev. 2 on April 3, 2025. The current publication, Rev. 3, does not keep that older phase list as NIST’s guide. Use the exam list for the exam, and do not describe Rev. 2 as current NIST guidance.

The exam list and the NIST change

The SY0-701 objectives, under incident response, list this process: preparation, detection, analysis, containment, eradication, recovery, and lessons learned. They also list training, tabletop and simulation testing, root cause analysis, and digital forensics items such as legal hold, chain of custody, acquisition, and preservation.

NIST’s current incident-response publication is SP 800-61 Rev. 3, finalized in April 2025. NIST says it supersedes Rev. 2. Rev. 2, the Computer Security Incident Handling Guide, was withdrawn on April 3, 2025. Rev. 3 maps incident response into the Cybersecurity Framework 2.0. It does not keep Rev. 2’s phase handbook as the current NIST recommendation. When a practice item uses the seven words above, it is following the exam objectives. It is not a claim that NIST still teaches Rev. 2.

Reading a log is the log guide. This page is what you do after the line means something.

One fictional incident

Northwind Clinic is invented. Addresses are documentation ranges. Nothing here is a recalled exam item.

TimeWhat is knownNext action
08:10Alert only: many connections from 192.0.2.40Analyze. Do not wipe the host
08:22Files are being renamed on the disk and the shareIsolate the host. That is containment
08:40Host is isolated. Legal may need the diskPreserve evidence before a reimage
10:05Copy saved. Process removed. Share restored from 06:00Removal is eradication. Restore is recovery

Lessons learned is the next day: why the host could see the whole share, and what the backup could not bring back. That gap is a recovery-point question, covered in the recovery metrics guide.

Containment, eradication, recovery

Phase on this incidentWhat changesWhat is still true afterward
Containment at 08:22The host can no longer reach the shareThe malicious process may still be on the disk. Service is not back
Eradication before 10:05The process is removed after a copy is keptThe documents may still be damaged. Users do not have the share yet
Recovery at 10:05The share is restored from the 06:00 backupChanges made between 06:00 and 08:22 are gone. The incident write-up is still undone

Why “always shut it down” is a bad rule

Shutting the laptop off would stop the encryption. It can also destroy volatile evidence the objectives put under acquisition and preservation. If the only goal is to stop a spreading process and the host is about to encrypt a server, isolation or shutdown can be the containment you can actually perform. If counsel has already said to preserve memory, shutdown is the wrong containment. The scenario has to include that constraint. This timeline isolated the host and kept it powered because a copy was still required. A different constraint would change the step. It would not change the meaning of eradication or recovery.

Practice the next-action choice in multiple choice. The free set will not run a tabletop for you.

Trust the source

Official sources

Exam policies can change. Use these primary sources for the most current details.