CompTIA CySA+

Incident Response & Management

62 practice questions with explanations — 15 free to try

PassNova has 62 CompTIA CySA+ practice questions on Incident Response & Management, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.

Sample questions

Incident Response & Management: example questions & answers

3 worked examples with answers and explanations below. Try 15 CompTIA CySA+ questions free in the browser; the full 62-question Incident Response & Management bank is part of PassNova Premium.

  1. The four phases of the NIST SP 800-61 incident response lifecycle are, in order:

    • APreparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-Incident Activity
    • BContainment; Preparation; Recovery; Reporting
    • CDetection; Recovery; Preparation; Eradication
    • DReporting; Containment; Preparation; Lessons Learned

    Answer: NIST SP 800-61 defines the lifecycle as Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity.

  2. During an active intrusion, the immediate priority after confirming a compromise is to limit the spread and prevent further damage. Which incident response phase is this?

    • ALessons learned
    • BPreparation
    • CRecovery
    • DContainment

    Answer: Containment focuses on isolating affected systems to stop the attacker from spreading or causing further harm before eradication and recovery.

  3. When collecting digital evidence, an analyst documents every person who handled it and when, to ensure it is admissible. This documentation is called the:

    • AService level agreement
    • BAcceptable use policy
    • CBusiness impact analysis
    • DChain of custody

    Answer: Chain of custody records the seizure, transfer, and handling of evidence over time to preserve its integrity and legal admissibility.

Start practising Incident Response & Management →