TechKnowSurge
CompTIA Security+ 4.8 CompTIA CySA+ 3.2 ISC2 CISSP 7.6 NIST CSF RS.MA-01 CompTIA CySA+ 3.3 NIST 800-53 IR-4 NIST CSF RC.RP-01 CompTIA SecurityX 4.4 NIST CSF RS.MI-01 NIST CSF RS.MI-02 NIST CSF RS.AN-03
InteractiveSecurityFree

Incident Response Phase Sequencer

Order one incident through the response lifecycle — Preparation, Detection, Analysis, Containment, Eradication, Recovery, Lessons Learned — and say what each phase changes.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

The incident response lifecycle is usually met as a list of seven words in a row — preparation, detection, analysis, containment, eradication, recovery, lessons learned — and a student who can recite that list still cannot say what has to be true before any one of those phases can begin, or what each of them actually changes. Closing that gap is what this set is for, and it is why no card opens with its phase name. Each card describes the work and ends with what that phase changes, so the vocabulary is attached to the behaviour rather than standing in for it. The chronology here is causal rather than conventional, and three constraints do most of the work. The first is that nothing used during an incident can be invented during it. The plan, the named response team, the authority to disconnect a production system without asking permission, the centralised logging that means the evidence exists before anyone needs it, the measured baseline that lets abnormal be recognised at all, the backups that were actually restored in a test rather than merely taken — all of it has to already exist at the moment the alert fires. That is why preparation sits outside the incident entirely, and it is also why it is the phase most often skipped: it is the only one with no incident to justify it. A team that begins writing its plan after the alert is not responding, it is improvising. The second constraint is that you cannot act on what you have not yet understood, and it is the reason detection and analysis are separate cards rather than the single NIST phase they are grouped under. Detection ends at a declaration: this is a real incident and not one of the many false positives that make up most of a queue, so the plan formally starts and the clock starts with it. Analysis is the entirely different job of establishing scope, reconstructing the timeline backwards to the initial point of entry — very often much earlier than the moment of detection — estimating severity so the response is proportionate, and collecting evidence under chain of custody. Collapsing the two is the most expensive mistake in the lifecycle, because a team that acts on the alert alone contains the one host it noticed while three others stay under the attacker's control, and finds out only when the attacker uses them. The third constraint is that the bleeding is stopped before the wound is cleaned. Containment is urgent, reversible and deliberately evidence-preserving: isolate, disable, block, quarantine, segment, and leave the attacker's tooling in place for the analysis that is still running. Eradication is slow and thorough: delete the malware, hunt the persistence mechanisms — the scheduled tasks, the service accounts, the web shells left behind so the attacker can walk back in — rotate the credentials, patch the vulnerability that allowed entry, and rebuild from a known-good image wherever cleaning cannot be proven complete. Run them the other way round and you are removing an attacker's tooling from a system the attacker still reaches, which invites them to put it back. Recovery is where the set makes its one point about who decides: restoring from validated backups, checked against the timeline so that a backup taken after the initial compromise does not reintroduce it, and then a defined watch period, because the commonest failure mode is a cause that was not fully eradicated announcing itself a week later. The incident closes when normal operations are confirmed by the business, not when the technical work stops. The last card is the one students most reliably treat as optional, and the set is built so that it cannot be. Lessons learned produces artifacts rather than feelings — an after-action report, a corrective action plan with owners and dates, updated playbooks, new detection rules for the indicators this incident produced — and every one of those flows straight back into preparation, which is what makes this a loop rather than a line. It also blames the system rather than the people, because a team that expects to be punished for the findings stops reporting incidents and the organisation loses the only signal it had. Seven phases are shipped rather than the four NIST SP 800-61 groups them into, and that is deliberate: the seven-step expansion is what pspo-14's own lessons teach across Preparation (pspo-14-0050), Detecting, Declaring, and Escalating (0080), Containment, Eradication, and Recovery (0090) and Incident Follow-Up (0120), it is what Security+ objective 4.8 enumerates word for word, and it is how the security ladder's own incident-response-lifecycle term is defined. Collapsing it back to four would contradict all three. All seven cards are presented on every run rather than sampled: this is the naturally finite domain the pool guideline makes an exception for — a lifecycle with a phase removed is not a shorter version of the same object, it is a broken chain, and the chain is the entire skill being assessed. This pairs best with the module's own sequence — run it after IR Process (pspo-14-0040) and alongside Containment, Eradication, and Recovery (0090), so that the phases the cards separate are ones the student has already seen taught together.

What you'll learn

Aligned to

CompTIA Security+
4.8 Explain appropriate incident response activities.
CompTIA CySA+
3.2 Given a scenario, perform incident response activities.
3.3 Explain the preparation and post-incident activity phases of the incident management life cycle.
ISC2 CISSP
7.6 Conduct incident management
NIST CSF
RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared.
RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process.
RS.MI-01 Incidents are contained.
RS.MI-02 Incidents are eradicated.
RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident.
NIST 800-53
IR-4 Incident Handling
CompTIA SecurityX
4.4 Explain incident response and recovery procedures.

Key terms

Incident Response
IR
A structured process for identifying, containing, eradicating, and recovering from security incidents.
Incident Response Lifecycle
The sequential phases organizations follow to manage a security incident, including preparation, detection, analysis, containment, eradication, recovery, and post-incident review.
Preparation
The pre-incident phase of an incident response plan in which tools, procedures, and resources are put in place to minimize the duration and impact of future incidents.
Containment
The phase of incident response focused on limiting the spread and impact of a security incident to prevent further damage.
Eradication
The phase of incident response in which the root cause and components of an incident, such as malware, are completely removed from affected systems.
Recovery
The phase of incident response in which affected systems and services are restored to normal operation after an incident.
Lessons Learned
A post-incident review process that documents findings and identifies improvements to prevent future incidents and strengthen response procedures.
Root Cause Analysis
RCA
A systematic investigation process that identifies the underlying cause of a security incident or system failure, going beyond symptoms to prevent recurrence. RCA findings drive corrective actions and improvements to security controls.
Incident Response Plan
IRP
An Incident Response Plan is a documented set of procedures that defines the roles, processes, and communication protocols an organization follows to detect, contain, eradicate, and recover from security incidents in a coordinated manner.
Playbook
A security playbook is a structured set of predefined response procedures for specific incident types, guiding analysts through detection, containment, eradication, and recovery steps in a consistent and repeatable manner.
Escalation
The process of elevating a security issue — such as a critical vulnerability or active incident — to a higher priority or authority level when the standard response process is insufficient or too slow to address the threat.
Alerting
The automated notification process that triggers when monitored systems deviate from expected thresholds, informing administrators of potential issues.
Security Information and Event Management
SIEM
A system that aggregates and analyzes security event data from across an organization to detect and respond to threats.
Quarantine
A disposition action taken by a mail gateway that isolates suspicious or high-scoring email messages for review rather than delivering them directly to the recipient or dropping them outright.
Network Segmentation
The practice of dividing a network into smaller segments to improve performance and limit the spread of security threats.
Reimaging
The process of wiping a compromised system and reinstalling the operating system and software from a clean image to ensure complete removal of threats.
Hardening
The process of securing a system by reducing its attack surface — disabling unnecessary services, applying configuration best practices, removing default credentials, and keeping software patched. Hardened systems offer fewer opportunities for exploitation.
After-Action Report
AAR
A summary document that captures findings from the incident response process, including root cause analysis, trends, and lessons learned.
Corrective Action Plan
A documented set of action items developed to address the root cause of an incident and prevent it from happening again.
Chain of Custody
CoC
Chain of Custody is the chronological documentation of who has collected, handled, and transferred digital evidence, establishing its integrity and admissibility in legal proceedings.
Digital Forensics
Digital Forensics is the science of collecting, preserving, analyzing, and presenting electronic evidence in a legally sound manner to support incident investigations or criminal proceedings.
Evidence
Facts or information collected during an investigation that indicate whether a belief or claim is valid or true.
Baseline
A documented set of minimum security standards or performance metrics used as a reference point.
Continuous Monitoring
An ongoing process of collecting and analyzing data about an organization's systems and risks to maintain an up-to-date risk posture.
Tabletop Exercise
A discussion-based DR testing method where participants walk through a disaster scenario step by step to identify gaps in the plan without disrupting live systems.
Runbook
A detailed, step-by-step set of instructions used to guide responders through a specific incident response task or scenario.
Security Operations Center
SOC
A centralized team and facility responsible for monitoring, detecting, and responding to security incidents.
Endpoint Detection and Response
EDR
A security solution that continuously monitors endpoint devices to detect, investigate, and respond to threats.
False Positive
An alert that fires when no actual issue exists, which over time can cause administrators to ignore notifications and reduce monitoring effectiveness.
Patch Management
The process of acquiring, testing, and installing software updates to fix vulnerabilities and improve functionality.
Backup
A copy of data captured at a specific point in time and stored separately from the source system, used to restore information in the event of data loss, corruption, or a security incident such as ransomware.

Topics

Interactive Ordering

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →