CompTIA Security+ guideHigh-value skills
Security+ Incident Response: Steps and Next Actions
Use one fictional incident to separate an alert from a confirmed incident, and containment from eradication and recovery.
Short answer
SY0-701 lists incident response as preparation, detection, analysis, containment, eradication, recovery, and lessons learned. An alert is not yet an incident. Containment limits damage, eradication removes the cause, and recovery restores service. NIST withdrew SP 800-61 Rev. 2 on April 3, 2025. The current publication, Rev. 3, does not keep that older phase list as NIST’s guide. Use the exam list for the exam, and do not describe Rev. 2 as current NIST guidance.
The exam list and the NIST change
The SY0-701 objectives, under incident response, list this process: preparation, detection, analysis, containment, eradication, recovery, and lessons learned. They also list training, tabletop and simulation testing, root cause analysis, and digital forensics items such as legal hold, chain of custody, acquisition, and preservation.
NIST’s current incident-response publication is SP 800-61 Rev. 3, finalized in April 2025. NIST says it supersedes Rev. 2. Rev. 2, the Computer Security Incident Handling Guide, was withdrawn on April 3, 2025. Rev. 3 maps incident response into the Cybersecurity Framework 2.0. It does not keep Rev. 2’s phase handbook as the current NIST recommendation. When a practice item uses the seven words above, it is following the exam objectives. It is not a claim that NIST still teaches Rev. 2.
Reading a log is the log guide. This page is what you do after the line means something.
One fictional incident
Northwind Clinic is invented. Addresses are documentation ranges. Nothing here is a recalled exam item.
| Time | What is known | Next action |
|---|---|---|
| 08:10 | Alert only: many connections from 192.0.2.40 | Analyze. Do not wipe the host |
| 08:22 | Files are being renamed on the disk and the share | Isolate the host. That is containment |
| 08:40 | Host is isolated. Legal may need the disk | Preserve evidence before a reimage |
| 10:05 | Copy saved. Process removed. Share restored from 06:00 | Removal is eradication. Restore is recovery |
Lessons learned is the next day: why the host could see the whole share, and what the backup could not bring back. That gap is a recovery-point question, covered in the recovery metrics guide.
Containment, eradication, recovery
| Phase on this incident | What changes | What is still true afterward |
|---|---|---|
| Containment at 08:22 | The host can no longer reach the share | The malicious process may still be on the disk. Service is not back |
| Eradication before 10:05 | The process is removed after a copy is kept | The documents may still be damaged. Users do not have the share yet |
| Recovery at 10:05 | The share is restored from the 06:00 backup | Changes made between 06:00 and 08:22 are gone. The incident write-up is still undone |
Why “always shut it down” is a bad rule
Shutting the laptop off would stop the encryption. It can also destroy volatile evidence the objectives put under acquisition and preservation. If the only goal is to stop a spreading process and the host is about to encrypt a server, isolation or shutdown can be the containment you can actually perform. If counsel has already said to preserve memory, shutdown is the wrong containment. The scenario has to include that constraint. This timeline isolated the host and kept it powered because a copy was still required. A different constraint would change the step. It would not change the meaning of eradication or recovery.
Practice the next-action choice in multiple choice. The free set will not run a tabletop for you.
Trust the source
Official sources
Exam policies can change. Use these primary sources for the most current details.