StudyToCert

All certifications / Security+ / Lessons

CompTIA Security+ SY0-701 · Domain 4: Security operations

IR process: preparation, detection, analysis, containment, eradication, recovery, lessons learned

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Incident response (IR) is the organized way an organization handles security incidents, from a single infected laptop to a major ransomware attack. A defined process means people know their roles, act quickly, preserve evidence and avoid making things worse under pressure. SY0-701 lists the stages as preparation, detection, analysis, containment, eradication, recovery and lessons learned. Exam questions often describe an action and ask which phase it belongs to, or ask what should happen next, so learn both the order and what belongs in each phase.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 8 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Security+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security+ study plan