When prevention fails, incident response (IR) limits the damage. Security+ expects you to know the lifecycle and the basics of preserving evidence — and this is core knowledge for any SOC or security role.
Interactive explainer: the incident response lifecycle
Explore the four NIST phases. Notice that the cycle starts and ends with preparation and learning:
The Incident Response Lifecycle
The NIST four-phase model for handling a security incident.
Tap or hover a part to learn more.
Be ready.
Plans, playbooks, tooling, contacts and training built before anything happens. The phase most often skipped and later regretted.
Check your understanding
1. Which phase includes 'lessons learned'?
2. Why capture volatile data before powering a machine off?
Beginner: why a lifecycle
Treating IR as a repeatable lifecycle — rather than improvising under pressure — is what separates organisations that recover quickly from those that make things worse. Preparation (plans, playbooks, contacts, tooling) is the phase people skip and later regret.
Intermediate: containment and evidence
- Containment — short-term (isolate the host) and long-term (rebuild cleanly).
- Eradication — remove the malware and close the entry point.
- Recovery — restore from known-good backups and monitor closely.
- Evidence handling — preserve integrity with chain of custody, hashing and write-blockers.
Advanced considerations
Order of volatility matters: capture volatile data (memory, running processes, network connections) before powering a machine off. Legal and regulatory obligations shape timing — under UK GDPR, qualifying personal-data breaches must be reported to the ICO within 72 hours. Regular tabletop exercises keep the plan usable and expose gaps before a real incident.
Practical example
Ransomware is detected on a file server. The analyst isolates it from the network (containment), captures a memory image (evidence), identifies the initial phishing entry point (analysis), rebuilds from clean offline backups (recovery), and updates email filtering and training (lessons learned). See how this links back to Security Operations detection.
Common mistakes
- No tested IR plan until an incident hits.
- Powering off machines and destroying volatile evidence.
- Restoring from backups that are themselves compromised.
- Skipping the lessons-learned phase, so the same incident recurs.
Best practices
Maintain and rehearse an IR plan, preserve evidence correctly, keep tested offline backups, meet breach-notification deadlines, and always run a post-incident review.
What employers expect
You can name the IR phases in order, explain why evidence preservation and clean backups matter, and stay calm and methodical under pressure.
Technical interview questions
- What are the phases of the incident response lifecycle?
- What is chain of custody and why does it matter?
- Why capture volatile data before shutting a machine down?
- How do you ensure backups are safe to restore after ransomware?
- What are your breach-notification obligations under UK GDPR?
Behavioural interview questions
- Tell me about a time you stayed calm during a stressful, fast-moving problem.
- Describe a situation where careful documentation of your actions mattered.
Practice questions
- Which IR phase includes 'lessons learned'? (Post-incident activity)
- What preserves evidence integrity through hand-offs? (Chain of custody)
- Which data should be captured first? (Volatile — e.g. memory)
- UK GDPR requires breach notification within how long? (72 hours)
Where this fits in your Security+ pathway
This domain is one part of the CompTIA Security+ study hub. When you're confident here, review Security Operations and move on to Governance, Risk & Compliance to keep building toward the full exam.
Practise with Missiora
- AI Interview™ — rehearse Security+ style questions on this topic and get scored feedback.
- Career Coach™ — turn this knowledge into a study-to-job plan.
- Job Intelligence™ — see which of these skills real security adverts demand.
