Which incident response activity identifies the source of an incident during an investigation?

During an investigation, an incident response team attempts to understand the source of an incident. Which of the following incident response activities describes this process?

  1. Analysis Source Reference Answer
  2. Lessons learned
  3. Detection
  4. Containment

Community Votes

A
81%
B
19%

81% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to distinguish incident-response phases by timeline; the trap is choosing Lessons Learned for root-cause review when the question specifies 'during an investigation,' which points to Analysis.

This Security+ SY0-701 question asks which incident response activity describes understanding the source of an incident during an investigation. Community consensus favors Analysis, not Lessons Learned, because source identification happens during the investigation phase.

Choosing B. Lessons learned is a post-incident review of what happened, including root cause and improvements; since the question says 'during an investigation,' the current activity is analysis.

Community Discussion (13 comments)

hasquaati 👍 11 Selected: A
Answer is A because you need to conduct an analysis to find out what the source of the incident was.
darpanne 👍 5 Selected: A
In the Analysis phase, the team examines logs, network traffic, artifacts, and other relevant data to determine: The root cause of the incident How the incident occurred The systems and data affected Indicators of Compromise (IOCs) Possible paths for remediation and prevention
89fdeb4 👍 5 Selected: A
It can't be "Lessons learned" because we're still investigating. "During an Investigation"
racer99_ 👍 1 Selected: B
This q tripped me up for a long time until i looked up the IRP stages. If you look it up you'll see that "Lessons learned" includes finding out what the source of the incident was. There is no such "analysis" stage in IRP. Correct answer here is B
sireyml 👍 2 Selected: A
Emphasis on "During an investigation". During an incident response, analysis refers to the process of investigating and understanding the source of the incident, including determining how the incident occurred, identifying the root cause, and gathering the necessary evidence to support further actions. This is a key part of incident response where the team works to fully comprehend the nature of the incident and its origins. "Lessons learned" is an activity that takes place after the incident has been resolved.
chalaka 👍 1 Selected: A
A. Analysis In the incident response process, analysis involves examining evidence and data to determine the cause and source of an incident. This phase helps the incident response team understand how the incident occurred, who or what caused it, and the extent of its impact.
3dk1 👍 2
Going with A. The problem with B is that it is post incident, this question is "During an investigation". I agree that you will investigate the root cause in the Lessons Learned portion as well, but this is at the END, not during.
c7b3ff0 👍 2 Selected: B
Lessons Learned - Review severe incidents to determine the root cause, whether they were avoidable, and how to avoid them in the future. Analysis - determine if an incident has actually occurred and assign it a priority level.
deejay2 👍 1
I think lessons learned is the right answer. Lesson's learned deals with post recovery(not during the investigation) and meets with everyone that was affected by the incident to get feedback and learn ways to improve to prevent this from happening next time. Analysis deals with the incident while the incident is happening, not after.
nap61 👍 4 Selected: B
From CompTIA Security Guide Analysis - After the detection process reports one or more indicators, in the analysis process, the first responder investigates the data to determine whether a genuine incident has been identified and what level of priority it should be assigned. Conversely, the report might be categorized as a false positive and dismissed. Lessons Learned - The lessons learned process reviews severe security incidents to determine their root cause, whether they were avoidable, and how to avoid them in the future. The lessons learned process should invoke root cause analysis or the effort to determine how the incident was able to occur. A lot of models have been developed to structure root cause analysis. One is the “Five Whys” model. This starts with a statement of the problem and then poses successive “Why” questions to drill down to root causes. So, to understand the source of incident, or root cause, in in LESSONS LEARNED.
cyoncon 👍 1
B, post incident
Sol_tyty 👍 1 Selected: A
GPT!!!
Etc_Shadow28000 👍 4 Selected: A
A. Analysis During an investigation, the incident response team engages in the process of understanding the source of an incident through analysis. This involves examining the data and evidence collected to determine how the incident occurred, its origin, and its impact. Therefore, the correct answer is: A. Analysis

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A is correct because analysis is the incident-response activity in which the team examines logs, network traffic, artifacts, and other evidence to understand how an incident occurred, identify the root cause, and determine its scope. As one commenter explains, in the Analysis phase the first responder investigates the data to determine whether a genuine incident has occurred and what priority it should be assigned. The wording "during an investigation" clearly places the activity inside the investigation, not after it.

Why the Other Options Are Wrong

B, Lessons learned, is tempting because root-cause review also happens in post-incident activity, but it occurs after the incident has been resolved, not during the investigation (comment [3] makes this point). C, Detection, is the initial identification of potential indicators from monitoring and alerting, not the process of understanding the source once an investigation is underway. D, Containment, follows analysis and focuses on isolating systems to limit damage, not on discovering the source.

Community Comment Notes

The majority vote (81-19) supports A. Several commenters correctly emphasize "during an investigation" as the key phrase, ruling out lessons learned because that is a post-incident step. A few comments argue that some IR frameworks do not have a standalone "Analysis" stage, but the option offered by the question is Analysis, and in the CompTIA/NIST model, analysis is the active investigation of indicators and evidence to determine the source and impact. Comment [2] provides a concise breakdown of what analysis examines—logs, network traffic, artifacts, and IOCs—making it the best match.

Official Reference

Exam Strategy

Focus on the timeline clues in incident-response questions. Words like 'during an investigation' mean you are in the detection/analysis stage; 'after the incident' or 'post-incident' points to lessons learned. This lets you eliminate options quickly.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide