CompTIA Security+ SY0-701 Incident Response Practice Test
Topic 21 focuses on Incident Response for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
What is the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs?
Correct Answer: A
Correct Answer
Answer A is correct because Preparation means the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Incorrect Answers
Answer B is incorrect because Eradication would fit a different scenario. Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment.
Answer C is incorrect because Simulation exercise represents a different security function. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.
Answer D is incorrect because Legal hold addresses a different requirement. Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation.
Question 2
To identify candidate incidents from alerts, observations, or reports, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Detection means recognition that a potentially security-relevant event has occurred.
Incorrect Answers
Answer A is incorrect because Forensic acquisition addresses a different requirement. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.
Answer B is incorrect because Threat hunting would fit a different scenario. Threat hunting refers to proactive search for signs of attackers or compromise not already identified by routine detections.
Answer C is incorrect because Recovery addresses a different security requirement. Recovery refers to restoration of systems and business services to normal operation with appropriate validation and monitoring.
Question 3
Which term describes investigation of evidence to determine scope, cause, severity, and likely impact?
Correct Answer: C
Correct Answer
Answer C is correct because Analysis means investigation of evidence to determine scope, cause, severity, and likely impact.
Incorrect Answers
Answer A is incorrect because Tabletop exercise addresses a different requirement. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.
Answer B is incorrect because Forensic acquisition would fit a different scenario. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.
Answer D is incorrect because Lessons learned represents a different security function. Lessons learned refers to post-incident review of what happened, what worked, what failed, and what should change.
Question 4
To isolate affected systems or accounts before the situation worsens, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Containment means actions that limit spread or ongoing damage while preserving the ability to investigate.
Incorrect Answers
Answer B is incorrect because E-discovery would fit a different scenario. E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings.
Answer C is incorrect because Digital forensics addresses a different requirement. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.
Answer D is incorrect because Eradication addresses a different security requirement. Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment.
Question 5
Which term describes removal of malware, attacker persistence, compromised accounts, or root causes from the environment?
Correct Answer: D
Correct Answer
Answer D is correct because Eradication means removal of malware, attacker persistence, compromised accounts, or root causes from the environment.
Incorrect Answers
Answer A is incorrect because Analysis addresses a different requirement. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.
Answer B is incorrect because Containment represents a different security function. Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate.
Answer C is incorrect because Digital forensics would fit a different scenario. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.
Question 6
To return to production safely after eradication, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Recovery means restoration of systems and business services to normal operation with appropriate validation and monitoring.
Incorrect Answers
Answer B is incorrect because Tabletop exercise would fit a different scenario. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.
Answer C is incorrect because Containment addresses a different security requirement. Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate.
Answer D is incorrect because Legal hold addresses a different requirement. Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation.
Question 7
Which term describes post-incident review of what happened, what worked, what failed, and what should change?
Correct Answer: C
Correct Answer
Answer C is correct because Lessons learned means post-incident review of what happened, what worked, what failed, and what should change.
Incorrect Answers
Answer A is incorrect because Digital forensics would fit a different scenario. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.
Answer B is incorrect because Threat hunting represents a different security function. Threat hunting refers to proactive search for signs of attackers or compromise not already identified by routine detections.
Answer D is incorrect because E-discovery addresses a different requirement. E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings.
Question 8
To build capability before pressure from a real incident, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Incident-response training means education that teaches responders and stakeholders their responsibilities and procedures.
Incorrect Answers
Answer B is incorrect because Containment addresses a different requirement. Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate.
Answer C is incorrect because Tabletop exercise would fit a different scenario. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.
Answer D is incorrect because E-discovery addresses a different security requirement. E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings.
Question 9
Which term describes discussion-based walkthrough of an incident scenario?
Correct Answer: D
Correct Answer
Answer D is correct because Tabletop exercise means discussion-based walkthrough of an incident scenario.
Incorrect Answers
Answer A is incorrect because Simulation exercise would fit a different scenario. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.
Answer B is incorrect because Preparation represents a different security function. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Answer C is incorrect because Containment addresses a different requirement. Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate.
Question 10
To evaluate operational behavior under conditions closer to a real event, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Simulation exercise means practice activity that imitates a more realistic incident and response environment.
Incorrect Answers
Answer A is incorrect because Analysis addresses a different requirement. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.
Answer B is incorrect because Threat hunting would fit a different scenario. Threat hunting refers to proactive search for signs of attackers or compromise not already identified by routine detections.
Answer D is incorrect because Detection addresses a different security requirement. Detection refers to recognition that a potentially security-relevant event has occurred.
Question 11
Which term describes structured effort to identify the underlying condition that allowed an incident to occur?
Correct Answer: C
Correct Answer
Answer C is correct because Root cause analysis means structured effort to identify the underlying condition that allowed an incident to occur.
Incorrect Answers
Answer A is incorrect because Detection addresses a different requirement. Detection refers to recognition that a potentially security-relevant event has occurred.
Answer B is incorrect because Digital forensics represents a different security function. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.
Answer D is incorrect because Analysis would fit a different scenario. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.
Question 12
To discover hidden threats using hypotheses and available telemetry, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Threat hunting means proactive search for signs of attackers or compromise not already identified by routine detections.
Incorrect Answers
Answer A is incorrect because Lessons learned would fit a different scenario. Lessons learned refers to post-incident review of what happened, what worked, what failed, and what should change.
Answer C is incorrect because Digital forensics addresses a different requirement. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.
Answer D is incorrect because Detection addresses a different security requirement. Detection refers to recognition that a potentially security-relevant event has occurred.
Question 13
Which term describes disciplined collection, preservation, examination, and reporting of digital evidence?
Correct Answer: A
Correct Answer
Answer A is correct because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence.
Incorrect Answers
Answer B is incorrect because E-discovery addresses a different requirement. E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings.
Answer C is incorrect because Analysis would fit a different scenario. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.
Answer D is incorrect because Preparation represents a different security function. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Question 14
To prevent normal deletion or modification of potentially discoverable evidence, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Legal hold means instruction to preserve relevant information because of litigation, investigation, or legal obligation.
Incorrect Answers
Answer B is incorrect because Digital forensics addresses a different requirement. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.
Answer C is incorrect because Forensic acquisition would fit a different scenario. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.
Answer D is incorrect because Tabletop exercise addresses a different security requirement. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.
Question 15
Which term describes documentation showing who collected, handled, transferred, stored, and examined evidence?
Correct Answer: B
Correct Answer
Answer B is correct because Chain of custody means documentation showing who collected, handled, transferred, stored, and examined evidence.
Incorrect Answers
Answer A is incorrect because Tabletop exercise would fit a different scenario. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.
Answer C is incorrect because Root cause analysis addresses a different requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.
Answer D is incorrect because Containment represents a different security function. Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate.
Question 16
To analyze evidence without unnecessarily modifying the source, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Forensic acquisition means creation of a defensible copy of digital evidence using methods that preserve original data.
Incorrect Answers
Answer A is incorrect because E-discovery would fit a different scenario. E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings.
Answer C is incorrect because Incident-response training addresses a different requirement. Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures.
Answer D is incorrect because Root cause analysis addresses a different security requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.
Question 17
Which term describes protection of evidence from alteration, loss, or unauthorized access?
Correct Answer: B
Correct Answer
Answer B is correct because Evidence preservation means protection of evidence from alteration, loss, or unauthorized access.
Incorrect Answers
Answer A is incorrect because Eradication would fit a different scenario. Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment.
Answer C is incorrect because Simulation exercise represents a different security function. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.
Answer D is incorrect because Root cause analysis addresses a different requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.
Question 18
To satisfy litigation or regulatory information requests, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because E-discovery means identification, preservation, collection, and production of electronically stored information for legal proceedings.
Incorrect Answers
Answer B is incorrect because Simulation exercise would fit a different scenario. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.
Answer C is incorrect because Root cause analysis addresses a different security requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.
Answer D is incorrect because Evidence preservation addresses a different requirement. Evidence preservation refers to protection of evidence from alteration, loss, or unauthorized access.
Question 19
To make the organization capable of responding effectively before a real event, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Preparation means the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Incorrect Answers
Answer A is incorrect because Digital forensics represents a different security function. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.
Answer C is incorrect because Analysis addresses a different security requirement. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.
Answer D is incorrect because Legal hold would fit a different scenario. Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation.
Question 20
Which term describes recognition that a potentially security-relevant event has occurred?
Correct Answer: D
Correct Answer
Answer D is correct because Detection means recognition that a potentially security-relevant event has occurred.
Incorrect Answers
Answer A is incorrect because Preparation represents a different security function. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Answer B is incorrect because Evidence preservation addresses a different requirement. Evidence preservation refers to protection of evidence from alteration, loss, or unauthorized access.
Answer C is incorrect because Forensic acquisition addresses a different security requirement. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.
Question 21
To decide whether an event is an incident and understand what happened, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Analysis means investigation of evidence to determine scope, cause, severity, and likely impact.
Incorrect Answers
Answer B is incorrect because Root cause analysis would fit a different scenario. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.
Answer C is incorrect because Preparation represents a different security function. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Answer D is incorrect because Recovery addresses a different security requirement. Recovery refers to restoration of systems and business services to normal operation with appropriate validation and monitoring.
Question 22
Which term describes actions that limit spread or ongoing damage while preserving the ability to investigate?
Correct Answer: C
Correct Answer
Answer C is correct because Containment means actions that limit spread or ongoing damage while preserving the ability to investigate.
Incorrect Answers
Answer A is incorrect because Chain of custody addresses a different security requirement. Chain of custody refers to documentation showing who collected, handled, transferred, stored, and examined evidence.
Answer B is incorrect because Simulation exercise represents a different security function. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.
Answer D is incorrect because Root cause analysis addresses a different requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.
Question 23
To eliminate the threat after it has been contained, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Eradication means removal of malware, attacker persistence, compromised accounts, or root causes from the environment.
Incorrect Answers
Answer A is incorrect because Tabletop exercise represents a different security function. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.
Answer B is incorrect because Preparation would fit a different scenario. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Answer C is incorrect because Analysis addresses a different security requirement. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.
Question 24
Which term describes restoration of systems and business services to normal operation with appropriate validation and monitoring?
Correct Answer: D
Correct Answer
Answer D is correct because Recovery means restoration of systems and business services to normal operation with appropriate validation and monitoring.
Incorrect Answers
Answer A is incorrect because Simulation exercise represents a different security function. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.
Answer B is incorrect because Preparation addresses a different requirement. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Answer C is incorrect because Incident-response training addresses a different security requirement. Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures.
Question 25
To improve controls and response processes after an event, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Lessons learned means post-incident review of what happened, what worked, what failed, and what should change.
Incorrect Answers
Answer A is incorrect because Analysis addresses a different security requirement. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.
Answer B is incorrect because Simulation exercise would fit a different scenario. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.
Answer D is incorrect because Detection represents a different security function. Detection refers to recognition that a potentially security-relevant event has occurred.
Question 26
Which term describes education that teaches responders and stakeholders their responsibilities and procedures?
Correct Answer: B
Correct Answer
Answer B is correct because Incident-response training means education that teaches responders and stakeholders their responsibilities and procedures.
Incorrect Answers
Answer A is incorrect because Preparation represents a different security function. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Answer C is incorrect because Root cause analysis addresses a different requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.
Answer D is incorrect because Legal hold addresses a different security requirement. Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation.
Question 27
To test decisions, communications, and plan completeness without affecting production, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Tabletop exercise means discussion-based walkthrough of an incident scenario.
Incorrect Answers
Answer A is incorrect because Analysis represents a different security function. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.
Answer B is incorrect because Root cause analysis would fit a different scenario. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.
Answer C is incorrect because Containment addresses a different security requirement. Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate.
Question 28
Which term describes practice activity that imitates a more realistic incident and response environment?
Correct Answer: C
Correct Answer
Answer C is correct because Simulation exercise means practice activity that imitates a more realistic incident and response environment.
Incorrect Answers
Answer A is incorrect because Threat hunting addresses a different requirement. Threat hunting refers to proactive search for signs of attackers or compromise not already identified by routine detections.
Answer B is incorrect because Detection represents a different security function. Detection refers to recognition that a potentially security-relevant event has occurred.
Answer D is incorrect because Legal hold addresses a different security requirement. Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation.
Question 29
To prevent recurrence by fixing causes rather than symptoms alone, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Root cause analysis means structured effort to identify the underlying condition that allowed an incident to occur.
Incorrect Answers
Answer A is incorrect because Lessons learned addresses a different security requirement. Lessons learned refers to post-incident review of what happened, what worked, what failed, and what should change.
Answer B is incorrect because Forensic acquisition represents a different security function. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.
Answer C is incorrect because Recovery would fit a different scenario. Recovery refers to restoration of systems and business services to normal operation with appropriate validation and monitoring.
Question 30
Which term describes proactive search for signs of attackers or compromise not already identified by routine detections?
Correct Answer: B
Correct Answer
Answer B is correct because Threat hunting means proactive search for signs of attackers or compromise not already identified by routine detections.
Incorrect Answers
Answer A is incorrect because Root cause analysis represents a different security function. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.
Answer C is incorrect because Incident-response training addresses a different requirement. Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures.
Answer D is incorrect because Eradication addresses a different security requirement. Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment.
Question 31
To support incident understanding while maintaining evidentiary integrity, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence.
Incorrect Answers
Answer A is incorrect because E-discovery represents a different security function. E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings.
Answer C is incorrect because Simulation exercise would fit a different scenario. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.
Answer D is incorrect because Tabletop exercise addresses a different security requirement. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.
Question 32
Which term describes instruction to preserve relevant information because of litigation, investigation, or legal obligation?
Correct Answer: B
Correct Answer
Answer B is correct because Legal hold means instruction to preserve relevant information because of litigation, investigation, or legal obligation.
Incorrect Answers
Answer A is incorrect because Eradication addresses a different requirement. Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment.
Answer C is incorrect because Analysis represents a different security function. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.
Answer D is incorrect because Incident-response training addresses a different security requirement. Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures.
Question 33
To demonstrate integrity and accountability for evidence handling, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Chain of custody means documentation showing who collected, handled, transferred, stored, and examined evidence.
Incorrect Answers
Answer B is incorrect because Forensic acquisition represents a different security function. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.
Answer C is incorrect because Evidence preservation would fit a different scenario. Evidence preservation refers to protection of evidence from alteration, loss, or unauthorized access.
Answer D is incorrect because Root cause analysis addresses a different security requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.
Question 34
Which term describes creation of a defensible copy of digital evidence using methods that preserve original data?
Correct Answer: C
Correct Answer
Answer C is correct because Forensic acquisition means creation of a defensible copy of digital evidence using methods that preserve original data.
Incorrect Answers
Answer A is incorrect because Incident-response training represents a different security function. Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures.
Answer B is incorrect because Lessons learned addresses a different security requirement. Lessons learned refers to post-incident review of what happened, what worked, what failed, and what should change.
Answer D is incorrect because Preparation addresses a different requirement. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Question 35
To maintain reliability of information needed for investigation or legal use, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Evidence preservation means protection of evidence from alteration, loss, or unauthorized access.
Incorrect Answers
Answer A is incorrect because Forensic acquisition represents a different security function. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.
Answer B is incorrect because Detection would fit a different scenario. Detection refers to recognition that a potentially security-relevant event has occurred.
Answer D is incorrect because Tabletop exercise addresses a different security requirement. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.
Popular posts
Recent Posts
