Cyber Intelligence
Security Operations · 28% of exam

L14. Incident Response: Detection, Containment & Recovery

Course outlineLesson 14 of 20

Every organization will experience security incidents. The difference between a minor disruption and a major breach often comes down to how quickly and effectively the IR process is executed.

NIST Incident Response Lifecycle (SP 800-61)

The NIST IR lifecycle has six phases:

  1. Preparation: IR plan, playbooks, contact lists, tooling, tabletop exercises
  2. Detection & Analysis: identify that an incident has occurred; determine scope and severity
  3. Containment: stop the spread; short-term (isolate host) then long-term (patch/rebuild)
  4. Eradication: remove the root cause (malware, compromised accounts, vulnerable software)
  5. Recovery: restore systems to normal operation; monitor for recurrence
  6. Post-Incident Activity: lessons learned report; update playbooks; share IOCs
Memory hook: Prep, Detect, Contain, Eradicate, Recover, Learn.

Preparation

Strong preparation is the phase that determines IR success:

  • Written IR plan with roles, responsibilities, and escalation paths
  • Playbooks for common scenarios (ransomware, data breach, insider threat)
  • Pre-authorized forensic tools on standby
  • Legal and PR contact lists
  • Tabletop exercises (discussion-based drills) to test the plan without real disruption

Containment Strategies

Short-term containment: immediately isolate the affected system (disconnect from network, block at firewall) to stop the spread. Preserve the system for forensics. Long-term containment: apply temporary mitigations (patch, change credentials, block IOCs) while eradication and recovery are planned. Evidence preservation: before wiping/rebuilding, capture a memory dump and disk image. Maintain chain of custody.

Recovery and Post-Incident

Recovery involves restoring from known-good backups, monitoring for re-infection, and gradually returning systems to production.

Post-incident lessons learned should capture: what happened, how it was detected, what worked, what failed, and what changes will be made to prevent recurrence. These findings feed back into the Preparation phase.

Exam Focus Points
  • NIST IR lifecycle: Preparation, Detection, Containment, Eradication, Recovery, Post-Incident (Lessons Learned)
  • Containment comes before eradication: stop the spread first, then remove the root cause
  • Tabletop exercises are discussion-based drills that test the IR plan without causing real system disruption
  • Chain of custody must be documented for forensic evidence to be admissible in legal proceedings
  • Post-incident lessons learned feed back into Preparation: update playbooks, share IOCs, improve controls
Knowledge Check

1. During an active ransomware incident, a responder disconnects the affected server from the network to stop the spread. Which IR phase is this action part of?

2. A security team conducts a meeting-based exercise where participants walk through a ransomware scenario and discuss their responses without actually activating any systems. What type of exercise is this?

3. After containing a breach, the IR team restores affected systems from the most recent clean backup and monitors them for 30 days. Which IR phase is this?

Recommended: Pluralsight

Turn your CompTIA Security+ concepts into passing marks: Pluralsight adds structured study plans, practice exams, and hands-on scenario labs.

Start Security+ prep free10-day free trial available