Tyscorpa Study resources Open the Academy

Incident Response

Incident response lifecycle, playbooks, communication plans, and post-incident activities.

SY0-701 Obj. 4.8 Security Operations 28% of the exam

Incident Response Lifecycle (NIST SP 800-61)

1. Preparation
Build capability before incidents occur
2. Detection & Analysis
Identify and confirm the incident
3. Containment
Limit spread and damage
4. Eradication
Remove threat from environment
5. Recovery
Restore normal operations
6. Lessons Learned
Post-incident review; improve

Phase Details

1. Preparation
Develop IR policy, playbooks, communication plan; train the team; configure SIEM/SOAR; establish relationships with legal, HR, law enforcement; conduct tabletop exercises
2. Detection & Analysis
Monitor SIEM alerts, IDS/IPS, EDR; determine scope and severity; classify the incident; notify appropriate stakeholders; begin documenting evidence and timeline
3. Containment
Short-term: Isolate affected systems (quarantine), block malicious IPs/domains, disable compromised accounts
Long-term: Preserve evidence before fully remedying; consider temporary workarounds to maintain business operations
4. Eradication
Remove malware, backdoors, and attacker tools; patch exploited vulnerabilities; reset compromised credentials; confirm no persistence mechanisms remain
5. Recovery
Restore from clean backups; rebuild from known-good images; re-enable services; monitor closely for re-infection; validate system integrity
6. Lessons Learned
Post-incident review (PIR / AAR — After-Action Report): What happened? What worked? What failed? What improvements are needed? Update playbooks accordingly.

Incident Severity Classification

LevelDescriptionExampleResponse
Critical (P1)Major breach / business-stopping impactRansomware on production systemsImmediate full IR team activation
High (P2)Significant impact; active threatCompromised admin account; active exfiltrationSame-day response
Medium (P3)Potential breach; suspicious activityPhishing email opened but no executionInvestigate within 24 hours
Low (P4)Policy violation; minor eventUser visiting blocked websiteAddress in normal workflow

Communication & Notification

Playbooks & Runbooks

Testing IR Plans

Exercise TypeDescription
Tabletop ExerciseDiscussion-based; no systems involved; team walks through a scenario verbally
WalkthroughTeam reviews the plan step-by-step; verifies documentation accuracy
SimulationMock incident with realistic artifacts; team responds as if real; limited system involvement
Parallel TestDR site activated alongside primary; both run simultaneously — no production impact
Full Interruption TestPrimary site taken offline; DR site takes over; highest realism, highest risk
Red Team / Blue TeamRed team attacks (pen test); Blue team defends and detects; Purple team facilitates learning
Exam Tip: The exam frequently tests the correct order of IR phases. Remember: you must contain before you eradicate. Never begin recovery before eradication — you'll re-infect the restored system. Evidence must be preserved during containment. Lessons Learned is the final phase, not optional.
PreviousAsset Management NextAcronyms - Security Operations

Test yourself on this

Reading is the easy half. The Academy has 1,360 exam-style questions, including performance-based ones, and it keeps pulling from whichever domain you keep getting wrong. Free to create an account.

Open the Academy