Contain without losing the evidence
Security+: Security Operations
Original starter lesson / sources checked 2026-09-30
Follow the incident response plan and establish scope. Preserve relevant evidence and record a timeline without exposing sensitive payloads.
For a suspected compromised endpoint, isolate it using the organization's authorized process while retaining evidence for investigation.
Containment, eradication, and recovery serve different purposes. Validate recovery and monitor for recurrence before declaring the incident closed.
Hands-on lab
- Use a fictional incident. Write an initial report with time, observable evidence, scope, authorized containment, and escalation.
- Do not run malware or simulate attacks against systems you do not own.
Put the lesson to work
Original exam-style practice. Choose the best answer for the stated scenario.
Go deeper
Official CompTIA scope and exam informationWWADD Move: Capture errors with useful contextIndependent practice aligned to selected topics. No endorsement, actual exam items, or pass guarantee. Verify your exam version and use the full official objectives for complete preparation.