Incident Response & Management
62 practice questions with explanations — 15 free to try
PassNova has 62 CompTIA CySA+ practice questions on Incident Response & Management, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.
Incident Response & Management: example questions & answers
3 worked examples with answers and explanations below. Try 15 CompTIA CySA+ questions free in the browser; the full 62-question Incident Response & Management bank is part of PassNova Premium.
The four phases of the NIST SP 800-61 incident response lifecycle are, in order:
- APreparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-Incident Activity✓
- BContainment; Preparation; Recovery; Reporting
- CDetection; Recovery; Preparation; Eradication
- DReporting; Containment; Preparation; Lessons Learned
Answer: NIST SP 800-61 defines the lifecycle as Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity.
During an active intrusion, the immediate priority after confirming a compromise is to limit the spread and prevent further damage. Which incident response phase is this?
- ALessons learned
- BPreparation
- CRecovery
- DContainment✓
Answer: Containment focuses on isolating affected systems to stop the attacker from spreading or causing further harm before eradication and recovery.
When collecting digital evidence, an analyst documents every person who handled it and when, to ensure it is admissible. This documentation is called the:
- AService level agreement
- BAcceptable use policy
- CBusiness impact analysis
- DChain of custody✓
Answer: Chain of custody records the seizure, transfer, and handling of evidence over time to preserve its integrity and legal admissibility.