Incident response from detection through recovery
Triage an incident, preserve evidence, contain impact, eradicate causes, recover safely, and evaluate response controls for ISC.
The decision that earns the point
Identify the objective before choosing the control
Incident response coordinates preparation, detection, analysis, containment, eradication, recovery, communication, and improvement after a cybersecurity event. The immediate choice depends on scope, severity, affected assets, evidence needs, legal or contractual duties, and business impact. Containment limits harm, eradication removes the cause, and recovery restores trusted operation. Those objectives should not be collapsed into one step.
Exam use
ISC can test incident criteria, monitoring and escalation, triage, evidence preservation, containment choices, root cause, recovery validation, communications, third parties, and lessons learned.
Your scratch-paper plan
Solve it in three moves
- 1
Validate and triage
Confirm the event, classify severity, identify affected assets and data, preserve volatile evidence, and activate the right roles.
NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations - 2
Contain with intent
Choose isolation, credential action, blocking, or other containment that limits harm without needlessly destroying evidence or critical service.
NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations - 3
Eradicate, recover, improve
Remove the cause, restore from trusted states, test business and security operation, monitor recurrence, and feed lessons into controls.
NIST SP 800-53 Rev. 5.1: Security and Privacy Controls
Worked problem
Work the facts before choosing the answer
Monitoring detects repeated privileged logins from an impossible location and a large database export. The account supports a critical billing process, and responders immediately plan to wipe the administrator laptop.
CPAPass exam analysis using the stated assumptions
Show the work
The team should preserve relevant volatile and log evidence, disable or contain the compromised credentials, determine affected systems and data, and maintain billing through an authorized alternative. Wiping first can destroy evidence without containing server-side access.
Rule source: NIST SP 800-61 Rev. 3: Incident Response Recommendations and ConsiderationsAnswer
Contain the identity and affected connections, preserve evidence, investigate scope, eradicate the access path, then restore and monitor trusted operations before closing the incident.
Rule source: NIST SP 800-61 Rev. 3: Incident Response Recommendations and ConsiderationsDo it now
Test the same decision with a fresh question
Start with free ISC practice. Create an account only when you want the 5-day no-card CPAPass trial and continued section practice.
The trap and the repair
Common trap
Jumping directly from alert to disaster recovery skips validation, evidence, scope, and containment. Restoring a server without removing compromised credentials can recreate the incident on clean infrastructure.
Repair
Write the current response objective beside every action and reject any step that destroys needed evidence or restores an untrusted condition.
Authority and scope boundary
NIST SP 800-61 and SP 800-53 support the response workflow, and the Blueprint controls ISC scope. The IT general controls guide retains broad access, change, and operations control design. The business continuity and disaster recovery guide retains continuity strategy, RTO, RPO, backups, alternate processing, and disaster recovery.
2026 Uniform CPA Examination Blueprints and NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations were reviewed on 2026-08-14. Check a newer authority when the effective date or facts change.
Response decision path
Choose the next action from the current objective
A strong incident answer preserves optionality: limit harm, keep evidence usable, restore trust, and document what changed.
| Response objective | Concrete action | Evidence or completion test | Authority |
|---|---|---|---|
| Detect and analyze | Validate indicators, classify severity, scope assets and data, notify assigned roles | Alert context, timeline, asset and identity inventory, incident record | NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations |
| Preserve and contain | Capture needed evidence, isolate affected paths, revoke compromised access, maintain critical service | Forensic copy or logs, containment approval, blocked connection, alternative operation | NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations |
| Eradicate and recover | Remove root cause, patch or rebuild, restore trusted data, validate functionality and controls | Clean-state proof, test results, reconciliation, enhanced monitoring | NIST SP 800-53 Rev. 5.1: Security and Privacy Controls |
| Learn and govern | Complete root-cause review, update controls and plans, track remediation and reporting duties | After-action report, assigned actions, retest, communication record | NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations |
After a miss
Review incident response by objective
- 1
Rebuild the timeline and label each known fact as alert, confirmed scope, evidence, business impact, or unresolved question.
- 2
Sort proposed actions into containment, eradication, recovery, and improvement, then put them in a defensible order.
- 3
Answer a new ISC incident scenario and explain why the chosen step belongs to response rather than ITGC design or BCDR.
Your exam workflow
- Step 1Identify the requirementConfirm the event, classify severity, identify affected assets and data, preserve volatile evidence, and activate the right roles.NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations
- Step 2Classify the factsChoose isolation, credential action, blocking, or other containment that limits harm without needlessly destroying evidence or critical service.NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations
- Step 3Apply the authorityRemove the cause, restore from trusted states, test business and security operation, monitor recurrence, and feed lessons into controls.NIST SP 800-53 Rev. 5.1: Security and Privacy Controls
- Step 4Check the outputContain the identity and affected connections, preserve evidence, investigate scope, eradicate the access path, then restore and monitor trusted operations before closing the incident.NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations
Keep the next step narrow
Quick questions
What is the key rule?
Incident response coordinates preparation, detection, analysis, containment, eradication, recovery, communication, and improvement after a cybersecurity event. The immediate choice depends on scope, severity, affected assets, evidence needs, legal or contractual duties, and business impact. Containment limits harm, eradication removes the cause, and recovery restores trusted operation. Those objectives should not be collapsed into one step.
How can this topic be tested on the CPA Exam?
ISC can test incident criteria, monitoring and escalation, triage, evidence preservation, containment choices, root cause, recovery validation, communications, third parties, and lessons learned.
What mistake most often changes the result?
Jumping directly from alert to disaster recovery skips validation, evidence, scope, and containment. Restoring a server without removing compromised credentials can recreate the incident on clean infrastructure. Write the current response objective beside every action and reject any step that destroys needed evidence or restores an untrusted condition.
Where should I practice the decision?
After the worked example, open the ISC free-practice link and work a fresh question that tests the same decision. If the miss depends on Business continuity and disaster recovery, review that handoff before trying another set.