Incident response
Know preparation, detection, containment, eradication, recovery, and lessons learned.
SecurePlus | CompTIA Security+™ Prep
Domain 4 tests daily security work: monitoring, incident response, vulnerability management, automation, alert triage, and operational controls.
Know preparation, detection, containment, eradication, recovery, and lessons learned.
Prioritise findings using severity, exposure, exploitability, and business impact.
Use logs, alerts, SIEM data, and baselines to detect suspicious activity.
Review monitoring, incident response, vulnerability management, automation, and investigation terms.
Practise by choosing the next best operational step, not only by memorising a definition.
Question: A SIEM alert shows repeated failed logins followed by one successful login from a new country. What should analysts investigate first?
A. Possible account compromise
B. Certificate pinning
C. Data classification labels
D. Business continuity testing
Answer: A. Possible account compromise
Domain 4 covers security operations such as monitoring, alert triage, incident response, and vulnerability management.
Yes. SecurePlus uses original study material aligned to SY0-701. It is an independent Security+ study tool and is not affiliated with or endorsed by CompTIA.
Use it to review Domain 4 topics, then practise that domain in SecurePlus until weak areas become clearer.