Preparation and detection
Preparation is everything done before an alert: the plan, the people and their roles, tooling, logging and training. Items about preparation describe work that happens in calm weeks, so an option that only makes sense once an attacker is inside belongs to a later step. Detection is the moment someone or something notices: a security information and event management (SIEM) correlation rule, an EDR alert, a user report.
Analysis
Analysis decides whether the event is an incident, how far it reaches and how bad it is. CompTIA lists it as its own step, which matters when an item asks what to do between noticing and acting. Scope and severity come out of this step; the frameworks on the attack frameworks page are the vocabulary for describing what you found.
Containment, eradication and recovery
Three separate steps on CS0-004. Containment limits the damage and keeps evidence intact; eradication removes the cause; recovery returns systems to production and watches them. Items in this area turn on the order: a clean rebuild before containment can tip off the attacker and destroy evidence you never collected. The concept page on containment vs eradication vs recovery works through the borderline cases.
Post-incident
The step after recovery is the lessons-learned review: what happened, what the root cause was, what worked, and which changes go back into preparation. The techniques that carry each step out (playbooks, triage, evidence handling, root cause analysis) are objective 3.3, covered in incident response techniques.
What changed from CS0-003
On CS0-003, which English candidates can book until December 22, 2026 (CompTIA CS0-003 page, checked October 2026), detection through recovery formed one objective and preparation with post-incident formed another. CS0-004 puts all seven steps into one ordered objective; the full list of changes is on CS0-004 vs CS0-003.