Which incident response activity identifies the source of an incident during an investigation?
During an investigation, an incident response team attempts to understand the source of an incident. Which of the following incident response activities describes this process?
Community Votes
81% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your ability to distinguish incident-response phases by timeline; the trap is choosing Lessons Learned for root-cause review when the question specifies 'during an investigation,' which points to Analysis.
This Security+ SY0-701 question asks which incident response activity describes understanding the source of an incident during an investigation. Community consensus favors Analysis, not Lessons Learned, because source identification happens during the investigation phase.
Choosing B. Lessons learned is a post-incident review of what happened, including root cause and improvements; since the question says 'during an investigation,' the current activity is analysis.
Community Discussion (13 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A is correct because analysis is the incident-response activity in which the team examines logs, network traffic, artifacts, and other evidence to understand how an incident occurred, identify the root cause, and determine its scope. As one commenter explains, in the Analysis phase the first responder investigates the data to determine whether a genuine incident has occurred and what priority it should be assigned. The wording "during an investigation" clearly places the activity inside the investigation, not after it.Why the Other Options Are Wrong
B, Lessons learned, is tempting because root-cause review also happens in post-incident activity, but it occurs after the incident has been resolved, not during the investigation (comment [3] makes this point). C, Detection, is the initial identification of potential indicators from monitoring and alerting, not the process of understanding the source once an investigation is underway. D, Containment, follows analysis and focuses on isolating systems to limit damage, not on discovering the source.Community Comment Notes
The majority vote (81-19) supports A. Several commenters correctly emphasize "during an investigation" as the key phrase, ruling out lessons learned because that is a post-incident step. A few comments argue that some IR frameworks do not have a standalone "Analysis" stage, but the option offered by the question is Analysis, and in the CompTIA/NIST model, analysis is the active investigation of indicators and evidence to determine the source and impact. Comment [2] provides a concise breakdown of what analysis examines—logs, network traffic, artifacts, and IOCs—making it the best match.Official Reference
Exam Strategy
Focus on the timeline clues in incident-response questions. Words like 'during an investigation' mean you are in the detection/analysis stage; 'after the incident' or 'post-incident' points to lessons learned. This lets you eliminate options quickly.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →