A+ Lesson

Incident Reports and Standard Operating Procedures for A+

Last updated: 6/10/2026

Short answer

Incident reports capture what happened and how it was handled; they are used for auditing, compliance, and learning. SOPs prescribe how tasks should be done repeatedly and are used to ensure consistency. An incident may reveal a gap that prompts updating an SOP; this flow must be documented. After-action and root-cause items in an incident report guide remediation and prevent recurrence.

Why it appears on the exam

- Classification: given a document excerpt, determine whether it is an incident report or an SOP. - identify the correct follow-up document to create after a recurring incident is observed. - Editing: choose the elements missing from an incident report that would be needed for compliance review.

Key concepts

Concept 1

Required terms

Incident Report: A descriptive record written after an unexpected event summarizing timeline, impact, actions taken, and observable outcomes. Standard Operating Procedure (SOP): A prescriptive, step-by-step document that defines the approved method for a repeatable operation or task. After-Action / Root Cause: Post-incident analysis elements that capture why the incident occurred and what corrective actions are required.

Example

Incident report: timeline showing outage start, detection, containment steps, user impact, recovery time, and follow-up items.

Concept 2

How Incident Reports and Standard Operating Procedures works

Incident reports capture what happened and how it was handled; they are used for auditing, compliance, and learning. SOPs prescribe how tasks should be done repeatedly and are used to ensure consistency. An incident may reveal a gap that prompts updating an SOP; this flow must be documented. After-action and root-cause items in an incident report guide remediation and prevent recurrence.

Example

SOP: 'Imaging a new workstation' with a materials list, step-by-step instructions, and a verification checklist.

Concept 3

Common confusion

- Writing an SOP as a narrative incident log; SOPs should be clear, ordered steps for future use. Conversely, incident reports should not be written as prescriptive instructions.

Example

After-action note: 'Root cause: failed automatic update process; corrective: adjust update schedule and add pre-update health checks.'

Concept 4

Core 2 (220-1202) question cues

Classification: given a document excerpt, determine whether it is an incident report or an SOP; identify the correct follow-up document to create after a recurring incident is observed; Editing: choose the elements missing from an incident report that would be needed for compliance review.

Example

Incident report: timeline showing outage start, detection, containment steps, user impact, recovery time, and follow-up items.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.A technician is troubleshooting this situation: Incident report: timeline showing outage start, detection, containment steps, user impact, recovery time, and follow-up items. What should they identify?

Q2.A technician sees this situation: SOP: 'Imaging a new workstation' with a materials list, step-by-step instructions, and a verification checklist. Which answer should they choose?

Q3.Read this A+ scenario: After-action note: 'Root cause: failed automatic update process; corrective: adjust update schedule and add pre-update health checks.' Which term or action matches it?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8