shieldCISSP Practice Domain 7 — Security Operations Q103 of 120

Which incident-response phase comes BEFORE detection and analysis?

A CISSP practice question covering Domain 7: Security Operations. Try answering before reading the explanation below.

Show options & answer
A
Containment
B
Preparation
✓ Correct answer
C
Eradication
D
Recovery
Why "Preparation" is the right answer

NIST IR phases: Preparation → Detection & Analysis → Containment, Eradication, Recovery → Post-Incident. Preparation is preventive groundwork (training, tooling, playbooks).

Study videos for this topic

Want to go deeper on Domain 7? Watch the full breakdown — every video is free, no account, no upsell.

Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.
Start full test →