Incident response
Know preparation, detection, containment, eradication, recovery, and lessons learned.
SecurePlus
Domain 4 tests daily security work: monitoring, incident response, vulnerability management, automation, alert triage, and operational controls.
Know preparation, detection, containment, eradication, recovery, and lessons learned.
Prioritise findings using severity, exposure, exploitability, and business impact.
Use logs, alerts, SIEM data, and baselines to detect suspicious activity.
Practise by choosing the next best operational step, not only by memorising a definition.
Question: A SIEM alert shows repeated failed logins followed by one successful login from a new country. What should analysts investigate first?
A. Possible account compromise
B. Certificate pinning
C. Data classification labels
D. Business continuity testing
Answer: A. Possible account compromise
Domain 4 covers security operations such as monitoring, alert triage, incident response, and vulnerability management.
No. SecurePlus uses original scenario-based practice. Not exam dumps. It is an independent Security+ study tool and is not affiliated with or endorsed by CompTIA.
Use it to review Domain 4 topics, then practise that domain in SecurePlus until weak areas become clearer.