Security+ Domain: Incident Response & Digital Forensics

IT & Cyber Certifications

Security+ Domain: Incident Response & Digital Forensics

3 min readPublished 22 Jul 2026

Track your progress. Sign in to mark this guide complete and build your Job Readiness Score.

When prevention fails, incident response (IR) limits the damage. Security+ expects you to know the lifecycle and the basics of preserving evidence — and this is core knowledge for any SOC or security role.

Interactive explainer: the incident response lifecycle

Explore the four NIST phases. Notice that the cycle starts and ends with preparation and learning:

Interactive explainer

The Incident Response Lifecycle

The NIST four-phase model for handling a security incident.

1Preparation2Detection & Analysis3Containment, Eradication & Recovery4Post-Incident Activity

Tap or hover a part to learn more.

Preparation

Be ready.

Plans, playbooks, tooling, contacts and training built before anything happens. The phase most often skipped and later regretted.

Check your understanding

1. Which phase includes 'lessons learned'?

2. Why capture volatile data before powering a machine off?

Practise this in AI Interview™

Beginner: why a lifecycle

Treating IR as a repeatable lifecycle — rather than improvising under pressure — is what separates organisations that recover quickly from those that make things worse. Preparation (plans, playbooks, contacts, tooling) is the phase people skip and later regret.

Intermediate: containment and evidence

  • Containment — short-term (isolate the host) and long-term (rebuild cleanly).
  • Eradication — remove the malware and close the entry point.
  • Recovery — restore from known-good backups and monitor closely.
  • Evidence handling — preserve integrity with chain of custody, hashing and write-blockers.

Advanced considerations

Order of volatility matters: capture volatile data (memory, running processes, network connections) before powering a machine off. Legal and regulatory obligations shape timing — under UK GDPR, qualifying personal-data breaches must be reported to the ICO within 72 hours. Regular tabletop exercises keep the plan usable and expose gaps before a real incident.

Practical example

Ransomware is detected on a file server. The analyst isolates it from the network (containment), captures a memory image (evidence), identifies the initial phishing entry point (analysis), rebuilds from clean offline backups (recovery), and updates email filtering and training (lessons learned). See how this links back to Security Operations detection.

Common mistakes

  • No tested IR plan until an incident hits.
  • Powering off machines and destroying volatile evidence.
  • Restoring from backups that are themselves compromised.
  • Skipping the lessons-learned phase, so the same incident recurs.

Best practices

Maintain and rehearse an IR plan, preserve evidence correctly, keep tested offline backups, meet breach-notification deadlines, and always run a post-incident review.

What employers expect

You can name the IR phases in order, explain why evidence preservation and clean backups matter, and stay calm and methodical under pressure.

Technical interview questions

  1. What are the phases of the incident response lifecycle?
  2. What is chain of custody and why does it matter?
  3. Why capture volatile data before shutting a machine down?
  4. How do you ensure backups are safe to restore after ransomware?
  5. What are your breach-notification obligations under UK GDPR?

Behavioural interview questions

  1. Tell me about a time you stayed calm during a stressful, fast-moving problem.
  2. Describe a situation where careful documentation of your actions mattered.

Practice questions

  1. Which IR phase includes 'lessons learned'? (Post-incident activity)
  2. What preserves evidence integrity through hand-offs? (Chain of custody)
  3. Which data should be captured first? (Volatile — e.g. memory)
  4. UK GDPR requires breach notification within how long? (72 hours)

Where this fits in your Security+ pathway

This domain is one part of the CompTIA Security+ study hub. When you're confident here, review Security Operations and move on to Governance, Risk & Compliance to keep building toward the full exam.

Practise with Missiora

Interview Intelligence

How this topic actually shows up in interviews — and how to demonstrate you understand it.

Why employers ask about this

When an incident hits, process beats panic; interviewers test whether you can respond methodically and preserve evidence.

Technical questions
What are the phases of incident response?+

Preparation, Identification, Containment, Eradication, Recovery and Lessons Learned.

Why is preserving evidence important?+

To support investigation and any legal action — maintain chain of custody and avoid altering the original data.

Behavioural questions
Tell me about staying calm during a stressful incident.+

Describe following the process, communicating clearly and not making rushed changes that could worsen things.

Real-world scenarios
“A server is actively compromised.”+

Expected answer: Contain first (isolate it), preserve evidence, then eradicate and recover — resisting the urge to wipe it immediately.

Common candidate mistakes
  • Wiping a compromised system before preserving evidence.
  • Skipping the lessons-learned phase.

Employability Intelligence

Where this knowledge takes you — the jobs, skills and certifications it feeds into.

Relevant roles
Incident ResponderSOC AnalystDigital Forensics Analyst
Skills you're proving
Incident response processContainmentEvidence handlingPost-incident review
Recommended certifications
Career progression

SOC Analyst → Incident Responder → DFIR / Security Engineer.

What employers expect

That you respond calmly, follow the IR process and preserve evidence correctly.

Frequently asked questions

Do I need forensics experience for Security+?

No. You need to understand the incident response lifecycle and evidence-handling principles conceptually, not perform deep forensic analysis.

How detailed is the breach-notification content?

Know that regulations impose notification timeframes (UK GDPR: 72 hours to the ICO for qualifying breaches) and that this shapes IR decisions.

Why is the order of volatility important in digital forensics?

Evidence such as system memory and active network connections disappears when a machine is powered off, so responders must capture the most volatile data first to preserve it for the investigation.

Related guides

Practise what you've learned

Turn this guide into real, evidenced progress

Missiora helps you measure, improve and evidence the capabilities employers actually value — start with the tools best suited to this topic.

M
Published by
Missiora

Missiora is an AI Employability Intelligence platform. Our resources are researched and reviewed by the Missiora team to help you measure, improve and prove your career readiness.