Incident Response Procedures
CompTIA Security+ SY0-701 (V7) PBQ
Match incident response phases with appropriate actions and procedures. This helps students understand what steps should be taken during each phase of the incident response lifecycle according to best practices.
Some options will have multiple correct answers.
Update incident response plan and security controls
Apply short-term fixes or network segmentation
Validate and categorize security incidents
Establish and train response team roles and responsibilities
Monitor systems and validate normal operations
Isolate affected systems to prevent spread
Analyze logs and alerts to detect anomalies
Develop incident response plan
Remove malware and malicious artifacts
Disable compromised user accounts and credentials
Restore systems and data from clean backups
Conduct post-incident review and root cause analysis
Eradication
Lessons Learned
Containment
Recovery
Identification
Preparation