Topic 21 Practice Test 2 covers Incident Response for CompTIA Security+ SY0-701 and maps to objective 4.8: Explain appropriate incident response activities. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
Which term describes restoration of systems and business services to normal operation with appropriate validation and monitoring?
- Preparation
- Incident-response training
- Recovery
- Simulation exercise
Correct Answer: C
Correct Answer
Answer C is correct because Recovery means restoration of systems and business services to normal operation with appropriate validation and monitoring. This is the precise fit for the scenario. Simulation exercise serves the different purpose of practice activity that imitates a more realistic incident and response environment.
Incorrect Answers
Answer A is incorrect because Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs. That concept can be valid in another scenario, but this question is testing restoration of systems and business services to normal operation with appropriate validation and monitoring; Recovery therefore fits the requirement more directly.
Answer B is incorrect because Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures. The question is not asking for this function. It is testing restoration of systems and business services to normal operation with appropriate validation and monitoring, so Recovery is the stronger fit.
Answer D is incorrect because Simulation exercise refers to practice activity that imitates a more realistic incident and response environment. This could be appropriate elsewhere, but the required function is restoration of systems and business services to normal operation with appropriate validation and monitoring; that makes Recovery the precise choice.
Question 2
Two requirements remain open in an incident-response exercise: post-incident review of what happened, what worked, what failed, and what should change; disciplined collection, preservation, examination, and reporting of digital evidence. Which TWO options close those specific gaps? Choose TWO.
- Lessons learned
- Containment
- Simulation exercise
- Eradication
- Digital forensics
Correct Answers: A, E
Correct Answers
Answer A is correct because Lessons learned means post-incident review of what happened, what worked, what failed, and what should change. It belongs in the fixed-count answer set because it covers one of the stated requirements. Containment instead serves actions that limit spread or ongoing damage while preserving the ability to investigate and cannot replace this function.
Answer E is correct because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence. This option satisfies a specific requirement in the stem; Simulation exercise serves practice activity that imitates a more realistic incident and response environment and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because Containment means actions that limit spread or ongoing damage while preserving the ability to investigate. The required choices are Digital forensics, Lessons learned. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer C is incorrect because Simulation exercise means practice activity that imitates a more realistic incident and response environment. Every answer slot must map to a stated requirement. The correct set is Digital forensics, Lessons learned, so this option cannot replace one of those selections.
Answer D is incorrect because Eradication means removal of malware, attacker persistence, compromised accounts, or root causes from the environment. The question requires exactly 2 selections: Digital forensics, Lessons learned. This option falls outside that required set. For example, Digital forensics is required for disciplined collection, preservation, examination, and reporting of digital evidence.
Question 3
A review during an incident-response exercise identifies two gaps. One requires structured effort to identify the underlying condition that allowed an incident to occur. The other requires creation of a defensible copy of digital evidence using methods that preserve original data. Which TWO options should be included in the remediation plan? Choose TWO.
- Root cause analysis
- Legal hold
- Eradication
- Lessons learned
- Forensic acquisition
Correct Answers: A, E
Correct Answers
Answer A is correct because Root cause analysis means structured effort to identify the underlying condition that allowed an incident to occur. The fixed-count item needs this function in the answer set. Legal hold covers instruction to preserve relevant information because of litigation, investigation, or legal obligation, a different requirement.
Answer E is correct because Forensic acquisition means creation of a defensible copy of digital evidence using methods that preserve original data. The fixed-count item needs this function in the answer set. Lessons learned covers post-incident review of what happened, what worked, what failed, and what should change, a different requirement.
Incorrect Answers
Answer B is incorrect because Legal hold means instruction to preserve relevant information because of litigation, investigation, or legal obligation. The scenario calls for Root cause analysis, Forensic acquisition. Selecting this option would leave one of those required functions uncovered.
Answer C is incorrect because Eradication means removal of malware, attacker persistence, compromised accounts, or root causes from the environment. The question requires exactly 2 selections: Root cause analysis, Forensic acquisition. This option falls outside that required set. For example, Forensic acquisition is required for creation of a defensible copy of digital evidence using methods that preserve original data.
Answer D is incorrect because Lessons learned means post-incident review of what happened, what worked, what failed, and what should change. The scenario calls for Root cause analysis, Forensic acquisition. Selecting this option would leave one of those required functions uncovered.
Question 4
Two requirements remain open in an incident-response exercise: recognition that a potentially security-relevant event has occurred; documentation showing who collected, handled, transferred, stored, and examined evidence. Which TWO options close those specific gaps? Choose TWO.
- Digital forensics
- Legal hold
- Detection
- Chain of custody
- E-discovery
Correct Answers: C, D
Correct Answers
Answer C is correct because Detection means recognition that a potentially security-relevant event has occurred. One required function is exactly what this option provides. Digital forensics may be useful elsewhere, but it is used for disciplined collection, preservation, examination, and reporting of digital evidence.
Answer D is correct because Chain of custody means documentation showing who collected, handled, transferred, stored, and examined evidence. This selection maps directly to one of the named needs. Legal hold addresses instruction to preserve relevant information because of litigation, investigation, or legal obligation, so it does not satisfy the same slot.
Incorrect Answers
Answer A is incorrect because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence. The required choices are Chain of custody, Detection. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer B is incorrect because Legal hold means instruction to preserve relevant information because of litigation, investigation, or legal obligation. The required choices are Chain of custody, Detection. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because E-discovery means identification, preservation, collection, and production of electronically stored information for legal proceedings. Every answer slot must map to a stated requirement. The correct set is Chain of custody, Detection, so this option cannot replace one of those selections.
Question 5
Which term describes structured effort to identify the underlying condition that allowed an incident to occur?
- Analysis
- Detection
- Root cause analysis
- Digital forensics
Correct Answer: C
Correct Answer
Answer C is correct because Root cause analysis means structured effort to identify the underlying condition that allowed an incident to occur. The requirement maps directly to this function, whereas Digital forensics is aimed at disciplined collection, preservation, examination, and reporting of digital evidence.
Incorrect Answers
Answer A is incorrect because Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact. This could be appropriate elsewhere, but the required function is structured effort to identify the underlying condition that allowed an incident to occur; that makes Root cause analysis the precise choice.
Answer B is incorrect because Detection refers to recognition that a potentially security-relevant event has occurred. This could be appropriate elsewhere, but the required function is structured effort to identify the underlying condition that allowed an incident to occur; that makes Root cause analysis the precise choice.
Answer D is incorrect because Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence. The concept is valid, but it does not match this stem. The required function is structured effort to identify the underlying condition that allowed an incident to occur, which maps to Root cause analysis.
Question 6
To support incident understanding while maintaining evidentiary integrity, which security approach should be selected?
- Digital forensics
- Simulation exercise
- E-discovery
- Tabletop exercise
Correct Answer: A
Correct Answer
Answer A is correct because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence. This matches the requirement as written. Tabletop exercise can be valid in another context, but it is used for discussion-based walkthrough of an incident scenario.
Incorrect Answers
Answer B is incorrect because Simulation exercise refers to practice activity that imitates a more realistic incident and response environment. The concept is valid, but it does not match this stem. The required function is disciplined collection, preservation, examination, and reporting of digital evidence, which maps to Digital forensics.
Answer C is incorrect because E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings. The question is not asking for this function. It is testing disciplined collection, preservation, examination, and reporting of digital evidence, so Digital forensics is the stronger fit.
Answer D is incorrect because Tabletop exercise refers to discussion-based walkthrough of an incident scenario. The question is not asking for this function. It is testing disciplined collection, preservation, examination, and reporting of digital evidence, so Digital forensics is the stronger fit.
Question 7
The control set for an incident-response exercise must address both incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs and documentation showing who collected, handled, transferred, stored, and examined evidence. Which TWO choices map directly to those needs? Choose TWO.
- Recovery
- Digital forensics
- Preparation
- Chain of custody
- Eradication
Correct Answers: C, D
Correct Answers
Answer C is correct because Preparation means the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs. It belongs in the fixed-count answer set because it covers one of the stated requirements. Recovery instead serves restoration of systems and business services to normal operation with appropriate validation and monitoring and cannot replace this function.
Answer D is correct because Chain of custody means documentation showing who collected, handled, transferred, stored, and examined evidence. It belongs in the fixed-count answer set because it covers one of the stated requirements. Recovery instead serves restoration of systems and business services to normal operation with appropriate validation and monitoring and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Recovery means restoration of systems and business services to normal operation with appropriate validation and monitoring. The scenario calls for Chain of custody, Preparation. Selecting this option would leave one of those required functions uncovered.
Answer B is incorrect because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence. The fixed-count answer set is Chain of custody, Preparation; this option does not fill one of those named functions. For example, Chain of custody is required for documentation showing who collected, handled, transferred, stored, and examined evidence.
Answer E is incorrect because Eradication means removal of malware, attacker persistence, compromised accounts, or root causes from the environment. The scenario calls for Chain of custody, Preparation. Selecting this option would leave one of those required functions uncovered.
Question 8
To prevent normal deletion or modification of potentially discoverable evidence, which security approach should be selected?
- Forensic acquisition
- Legal hold
- Digital forensics
- Tabletop exercise
Correct Answer: B
Correct Answer
Answer B is correct because Legal hold means instruction to preserve relevant information because of litigation, investigation, or legal obligation. This is the precise fit for the scenario. Tabletop exercise serves the different purpose of discussion-based walkthrough of an incident scenario.
Incorrect Answers
Answer A is incorrect because Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data. This could be appropriate elsewhere, but the required function is instruction to preserve relevant information because of litigation, investigation, or legal obligation; that makes Legal hold the precise choice.
Answer C is incorrect because Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence. The scenario instead requires instruction to preserve relevant information because of litigation, investigation, or legal obligation, which is why Legal hold is the better answer; this option serves the different function defined above.
Answer D is incorrect because Tabletop exercise refers to discussion-based walkthrough of an incident scenario. The concept is valid, but it does not match this stem. The required function is instruction to preserve relevant information because of litigation, investigation, or legal obligation, which maps to Legal hold.
Question 9
To eliminate the threat after it has been contained, which security approach should be selected?
- Preparation
- Eradication
- Tabletop exercise
- Analysis
Correct Answer: B
Correct Answer
Answer B is correct because Eradication means removal of malware, attacker persistence, compromised accounts, or root causes from the environment. That is the function the question is testing. Preparation would instead be used for the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Incorrect Answers
Answer A is incorrect because Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs. That concept can be valid in another scenario, but this question is testing removal of malware, attacker persistence, compromised accounts, or root causes from the environment; Eradication therefore fits the requirement more directly.
Answer C is incorrect because Tabletop exercise refers to discussion-based walkthrough of an incident scenario. The question is not asking for this function. It is testing removal of malware, attacker persistence, compromised accounts, or root causes from the environment, so Eradication is the stronger fit.
Answer D is incorrect because Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact. This could be appropriate elsewhere, but the required function is removal of malware, attacker persistence, compromised accounts, or root causes from the environment; that makes Eradication the precise choice.
Question 10
To prevent recurrence by fixing causes rather than symptoms alone, which security approach should be selected?
- Lessons learned
- Forensic acquisition
- Recovery
- Root cause analysis
Correct Answer: D
Correct Answer
Answer D is correct because Root cause analysis means structured effort to identify the underlying condition that allowed an incident to occur. This is the precise fit for the scenario. Lessons learned serves the different purpose of post-incident review of what happened, what worked, what failed, and what should change.
Incorrect Answers
Answer A is incorrect because Lessons learned refers to post-incident review of what happened, what worked, what failed, and what should change. The scenario instead requires structured effort to identify the underlying condition that allowed an incident to occur, which is why Root cause analysis is the better answer; this option serves the different function defined above.
Answer B is incorrect because Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data. The scenario instead requires structured effort to identify the underlying condition that allowed an incident to occur, which is why Root cause analysis is the better answer; this option serves the different function defined above.
Answer C is incorrect because Recovery refers to restoration of systems and business services to normal operation with appropriate validation and monitoring. This could be appropriate elsewhere, but the required function is structured effort to identify the underlying condition that allowed an incident to occur; that makes Root cause analysis the precise choice.
Question 11
During an incident-response exercise, the team has two independent requirements: (1) actions that limit spread or ongoing damage while preserving the ability to investigate; and (2) instruction to preserve relevant information because of litigation, investigation, or legal obligation. Which TWO choices best satisfy those requirements? Choose TWO.
- Legal hold
- Incident-response training
- Threat hunting
- Lessons learned
- Containment
Correct Answers: A, E
Correct Answers
Answer A is correct because Legal hold means instruction to preserve relevant information because of litigation, investigation, or legal obligation. This selection maps directly to one of the named needs. Lessons learned addresses post-incident review of what happened, what worked, what failed, and what should change, so it does not satisfy the same slot.
Answer E is correct because Containment means actions that limit spread or ongoing damage while preserving the ability to investigate. This option satisfies a specific requirement in the stem; Incident-response training serves education that teaches responders and stakeholders their responsibilities and procedures and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because Incident-response training means education that teaches responders and stakeholders their responsibilities and procedures. The scenario calls for Legal hold, Containment. Selecting this option would leave one of those required functions uncovered. For example, Containment is required for actions that limit spread or ongoing damage while preserving the ability to investigate.
Answer C is incorrect because Threat hunting means proactive search for signs of attackers or compromise not already identified by routine detections. The fixed-count answer set is Legal hold, Containment; this option does not fill one of those named functions.
Answer D is incorrect because Lessons learned means post-incident review of what happened, what worked, what failed, and what should change. The scenario calls for Legal hold, Containment. Selecting this option would leave one of those required functions uncovered.
Question 12
To improve controls and response processes after an event, which security approach should be selected?
- Detection
- Simulation exercise
- Lessons learned
- Analysis
Correct Answer: C
Correct Answer
Answer C is correct because Lessons learned means post-incident review of what happened, what worked, what failed, and what should change. That is the function the question is testing. Detection would instead be used for recognition that a potentially security-relevant event has occurred.
Incorrect Answers
Answer A is incorrect because Detection refers to recognition that a potentially security-relevant event has occurred. The key mismatch is functional: Lessons learned addresses post-incident review of what happened, what worked, what failed, and what should change, the need stated by the question.
Answer B is incorrect because Simulation exercise refers to practice activity that imitates a more realistic incident and response environment. The question is not asking for this function. It is testing post-incident review of what happened, what worked, what failed, and what should change, so Lessons learned is the stronger fit.
Answer D is incorrect because Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact. The question is not asking for this function. It is testing post-incident review of what happened, what worked, what failed, and what should change, so Lessons learned is the stronger fit.
Question 13
To discover hidden threats using hypotheses and available telemetry, which security approach should be selected?
- Detection
- Lessons learned
- Digital forensics
- Threat hunting
Correct Answer: D
Correct Answer
Answer D is correct because Threat hunting means proactive search for signs of attackers or compromise not already identified by routine detections. This is the precise fit for the scenario. Detection serves the different purpose of recognition that a potentially security-relevant event has occurred.
Incorrect Answers
Answer A is incorrect because Detection refers to recognition that a potentially security-relevant event has occurred. The scenario instead requires proactive search for signs of attackers or compromise not already identified by routine detections, which is why Threat hunting is the better answer; this option serves the different function defined above.
Answer B is incorrect because Lessons learned refers to post-incident review of what happened, what worked, what failed, and what should change. The concept is valid, but it does not match this stem. The required function is proactive search for signs of attackers or compromise not already identified by routine detections, which maps to Threat hunting.
Answer C is incorrect because Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence. This could be appropriate elsewhere, but the required function is proactive search for signs of attackers or compromise not already identified by routine detections; that makes Threat hunting the precise choice.
Question 14
To isolate affected systems or accounts before the situation worsens, which security approach should be selected?
- Eradication
- E-discovery
- Digital forensics
- Containment
Correct Answer: D
Correct Answer
Answer D is correct because Containment means actions that limit spread or ongoing damage while preserving the ability to investigate. That makes it the best answer here; Digital forensics addresses disciplined collection, preservation, examination, and reporting of digital evidence, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment. That concept can be valid in another scenario, but this question is testing actions that limit spread or ongoing damage while preserving the ability to investigate; Containment therefore fits the requirement more directly.
Answer B is incorrect because E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings. That concept can be valid in another scenario, but this question is testing actions that limit spread or ongoing damage while preserving the ability to investigate; Containment therefore fits the requirement more directly.
Answer C is incorrect because Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence. The key mismatch is functional: Containment addresses actions that limit spread or ongoing damage while preserving the ability to investigate, the need stated by the question.
Question 15
To identify candidate incidents from alerts, observations, or reports, which security approach should be selected?
- Detection
- Recovery
- Threat hunting
- Forensic acquisition
Correct Answer: A
Correct Answer
Answer A is correct because Detection means recognition that a potentially security-relevant event has occurred. The deciding point is functional fit: this option covers the stated need, while Threat hunting addresses proactive search for signs of attackers or compromise not already identified by routine detections.
Incorrect Answers
Answer B is incorrect because Recovery refers to restoration of systems and business services to normal operation with appropriate validation and monitoring. The scenario instead requires recognition that a potentially security-relevant event has occurred, which is why Detection is the better answer; this option serves the different function defined above.
Answer C is incorrect because Threat hunting refers to proactive search for signs of attackers or compromise not already identified by routine detections. The question is not asking for this function. It is testing recognition that a potentially security-relevant event has occurred, so Detection is the stronger fit.
Answer D is incorrect because Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data. The concept is valid, but it does not match this stem. The required function is recognition that a potentially security-relevant event has occurred, which maps to Detection.
Question 16
To make the organization capable of responding effectively before a real event, which security approach should be selected?
- Digital forensics
- Legal hold
- Analysis
- Preparation
Correct Answer: D
Correct Answer
Answer D is correct because Preparation means the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs. That makes it the best answer here; Analysis addresses investigation of evidence to determine scope, cause, severity, and likely impact, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence. The question is not asking for this function. It is testing the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs, so Preparation is the stronger fit.
Answer B is incorrect because Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation. The question is not asking for this function. It is testing the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs, so Preparation is the stronger fit.
Answer C is incorrect because Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact. The concept is valid, but it does not match this stem. The required function is the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs, which maps to Preparation.
Question 17
Which term describes disciplined collection, preservation, examination, and reporting of digital evidence?
- Digital forensics
- Analysis
- E-discovery
- Preparation
Correct Answer: A
Correct Answer
Answer A is correct because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence. This is the precise fit for the scenario. E-discovery serves the different purpose of identification, preservation, collection, and production of electronically stored information for legal proceedings.
Incorrect Answers
Answer B is incorrect because Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact. That concept can be valid in another scenario, but this question is testing disciplined collection, preservation, examination, and reporting of digital evidence; Digital forensics therefore fits the requirement more directly.
Answer C is incorrect because E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings. The question is not asking for this function. It is testing disciplined collection, preservation, examination, and reporting of digital evidence, so Digital forensics is the stronger fit. This question specifically tests the requirement represented by Digital forensics.
Answer D is incorrect because Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs. The key mismatch is functional: Digital forensics addresses disciplined collection, preservation, examination, and reporting of digital evidence, the need stated by the question.
Question 18
To satisfy litigation or regulatory information requests, which security approach should be selected?
- Root cause analysis
- E-discovery
- Simulation exercise
- Evidence preservation
Correct Answer: B
Correct Answer
Answer B is correct because E-discovery means identification, preservation, collection, and production of electronically stored information for legal proceedings. That is the function the question is testing. Simulation exercise would instead be used for practice activity that imitates a more realistic incident and response environment.
Incorrect Answers
Answer A is incorrect because Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur. The question is not asking for this function. It is testing identification, preservation, collection, and production of electronically stored information for legal proceedings, so E-discovery is the stronger fit.
Answer C is incorrect because Simulation exercise refers to practice activity that imitates a more realistic incident and response environment. This could be appropriate elsewhere, but the required function is identification, preservation, collection, and production of electronically stored information for legal proceedings; that makes E-discovery the precise choice.
Answer D is incorrect because Evidence preservation refers to protection of evidence from alteration, loss, or unauthorized access. The scenario instead requires identification, preservation, collection, and production of electronically stored information for legal proceedings, which is why E-discovery is the better answer; this option serves the different function defined above.
Question 19
Which term describes recognition that a potentially security-relevant event has occurred?
- Detection
- Preparation
- Evidence preservation
- Forensic acquisition
Correct Answer: A
Correct Answer
Answer A is correct because Detection means recognition that a potentially security-relevant event has occurred. The requirement maps directly to this function, whereas Preparation is aimed at the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Incorrect Answers
Answer B is incorrect because Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs. The scenario instead requires recognition that a potentially security-relevant event has occurred, which is why Detection is the better answer; this option serves the different function defined above.
Answer C is incorrect because Evidence preservation refers to protection of evidence from alteration, loss, or unauthorized access. The scenario instead requires recognition that a potentially security-relevant event has occurred, which is why Detection is the better answer; this option serves the different function defined above.
Answer D is incorrect because Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data. The scenario instead requires recognition that a potentially security-relevant event has occurred, which is why Detection is the better answer; this option serves the different function defined above.
Question 20
During an incident-response exercise, three requirements must be addressed: (1) removal of malware, attacker persistence, compromised accounts, or root causes from the environment; (2) structured effort to identify the underlying condition that allowed an incident to occur; and (3) proactive search for signs of attackers or compromise not already identified by routine detections. Which THREE choices best satisfy them? Choose THREE.
- Eradication
- Digital forensics
- Root cause analysis
- Detection
- Threat hunting
- Evidence preservation
Correct Answers: A, C, E
Correct Answers
Answer A is correct because Eradication means removal of malware, attacker persistence, compromised accounts, or root causes from the environment. It belongs in the fixed-count answer set because it covers one of the stated requirements. Evidence preservation instead serves protection of evidence from alteration, loss, or unauthorized access and cannot replace this function.
Answer C is correct because Root cause analysis means structured effort to identify the underlying condition that allowed an incident to occur. This option satisfies a specific requirement in the stem; Digital forensics serves disciplined collection, preservation, examination, and reporting of digital evidence and therefore is not interchangeable with it.
Answer E is correct because Threat hunting means proactive search for signs of attackers or compromise not already identified by routine detections. This selection maps directly to one of the named needs. Digital forensics addresses disciplined collection, preservation, examination, and reporting of digital evidence, so it does not satisfy the same slot.
Incorrect Answers
Answer B is incorrect because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence. The fixed-count answer set is Root cause analysis, Threat hunting, Eradication; this option does not fill one of those named functions. For example, Root cause analysis is required for structured effort to identify the underlying condition that allowed an incident to occur.
Answer D is incorrect because Detection means recognition that a potentially security-relevant event has occurred. The required choices are Root cause analysis, Threat hunting, Eradication. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer F is incorrect because Evidence preservation means protection of evidence from alteration, loss, or unauthorized access. Every answer slot must map to a stated requirement. The correct set is Root cause analysis, Threat hunting, Eradication, so this option cannot replace one of those selections.