30% off all memberships for Memorial Day – Today Only

12 hours, 42 minutes remaining!
Preview Mode — This PBQ requires a Premium Membership and is being shown in a read-only preview mode.     See Plans

Incident Response Procedures

CompTIA Security+ SY0-701 (V7) PBQ

Match incident response phases with appropriate actions and procedures. This helps students understand what steps should be taken during each phase of the incident response lifecycle according to best practices.

Some options will have multiple correct answers.


Analyze logs and alerts to detect anomalies
Remove malware and malicious artifacts
Isolate affected systems to prevent spread
Develop incident response plan
Monitor systems and validate normal operations
Update incident response plan and security controls
Conduct post-incident review and root cause analysis
Validate and categorize security incidents
Disable compromised user accounts and credentials
Establish and train response team roles and responsibilities
Apply short-term fixes or network segmentation
Restore systems and data from clean backups
Preparation
Eradication
Recovery
Identification
Containment
Lessons Learned