Exam objective
SY0-701 4.8: Incident Response Activities
Incident Response Activities for Security+
This Security+ topic covers incident response process activities: preparation, detection, analysis, containment, eradication, recovery, and lessons learned; Incident response readiness activities: training, tabletop exercise, and simulation; Follow-on analysis and investigative activities at Security+ depth: root cause analysis, threat hunting, and digital forensics; Digital forensics handling concepts: legal hold, chain of custody, acquisition, reporting, preservation, and e-discovery.
Start first lesson3 lessons in this topic
Common mistakes to avoid
Learners often confuse containment with eradication. Containment limits immediate damage or spread. Eradication removes the root malicious condition or vulnerability so the incident does not continue or recur.
Learners often confuse tabletop exercises with simulations. A tabletop is discussion-based and low risk. A simulation is more realistic and may involve tools, alerts, hands-on investigation, or operational pressure.
Learners often confuse root cause analysis with eradication. Eradication removes the malicious condition or exploited weakness. Root cause analysis determines why the incident was possible so controls can be improved.