TechKnowSurge
CompTIA Security+ 4.8 ISC2 CC 5.3 Cisco CCST Cybersecurity 5.4 NIST 800-53 IR-4 ISC2 CISSP 7.6 NIST CSF RS.MI-01 NIST CSF RS.MI-02
InteractiveSecurityFree

Which Phase Is This?

Sort each response action into its phase, from preparing to learning.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Fault tolerance makes downtime rarer; incident response makes it shorter. The process has a before, a during and an after. Before: prepare. A detailed plan of who is in charge, who is told and how, who troubleshoots and how efforts are coordinated makes a chaotic situation less chaotic. Some things only help if they exist beforehand, such as baseline configurations to compare against. Training and testing matter too, because people skip steps in a process they have only read. During: detect the incident (a user calls, or monitoring such as a SIEM raises an alert); analyze it, scoping out what is happening, quickly; contain it, stopping it immediately and keeping it in one spot, even by pulling the plug; eradicate it, removing the cause completely, preferably from a clean slate rather than with a cleanup tool; and recover, getting services back to full use without the infection, then backing out emergency changes and fixing the damage done to users. After: learn. Decide what to fix and do differently, and do a root cause analysis: keep asking why until you reach the real cause, then plan how to prevent it.

What you'll learn

Aligned to

CompTIA Security+
4.8 Explain appropriate incident response activities.
ISC2 CC
5.3 Understand Incident Response (IR)
Cisco CCST Cybersecurity
5.4 Describe the elements of cybersecurity incident response
NIST 800-53
IR-4 Incident Handling
ISC2 CISSP
7.6 Conduct incident management
NIST CSF
RS.MI-01 Incidents are contained.
RS.MI-02 Incidents are eradicated.

Key terms

Incident Response
IR
A structured process for identifying, containing, eradicating, and recovering from security incidents.
Incident Response Plan
IRP
An Incident Response Plan is a documented set of procedures that defines the roles, processes, and communication protocols an organization follows to detect, contain, eradicate, and recover from security incidents in a coordinated manner.
Preparation
The pre-incident phase of an incident response plan in which tools, procedures, and resources are put in place to minimize the duration and impact of future incidents.
Containment
The phase of incident response focused on limiting the spread and impact of a security incident to prevent further damage.
Eradication
The phase of incident response in which the root cause and components of an incident, such as malware, are completely removed from affected systems.
Recovery
The phase of incident response in which affected systems and services are restored to normal operation after an incident.
Lessons Learned
A post-incident review process that documents findings and identifies improvements to prevent future incidents and strengthen response procedures.
Root Cause Analysis
RCA
A systematic investigation process that identifies the underlying cause of a security incident or system failure, going beyond symptoms to prevent recurrence. RCA findings drive corrective actions and improvements to security controls.
Incident Response Lifecycle
The sequential phases organizations follow to manage a security incident, including preparation, detection, analysis, containment, eradication, recovery, and post-incident review.

Topics

Incident Response Containment Eradication Root Cause Analysis Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →