Domain 4: Operations — What They Really Test
Domain 4 is the single largest domain by weight. It's also the most practical: monitoring, incident response, and day-to-day security operations.
> Domain weightings are set by CompTIA and change with each exam version — confirm the current objectives at comptia.org.
Key Topics
Monitoring and Detection
- SIEM (Security Information and Event Management)
- SOAR (Security Orchestration, Automation, and Response)
- IDS/IPS — know the difference between signature-based and anomaly-based
- Log analysis and event correlation
- Vulnerability scanning vs. penetration testing
Incident Response
- IR phases: preparation, detection, analysis, containment, eradication, recovery, lessons learned
- Chain of custody and evidence preservation
- Communication plans and stakeholder notification
Digital Forensics Basics
- Order of volatility (what to collect first)
- Forensic imaging — write-blockers, hashing for integrity
- Legal hold and e-discovery
Security Tools
- Firewalls (stateful, stateless, next-gen)
- Endpoint detection and response (EDR)
- Data loss prevention (DLP)
- NAC (Network Access Control)
What They Really Test
The exam loves scenario questions like: "A security analyst notices unusual outbound traffic at 2am. The SIEM shows repeated DNS queries to an unfamiliar domain. What should they do FIRST?"
The answer is almost always about the IR process — don't jump to "block the traffic." Think process: detect → analyse → contain.
Study Tips
Domain 4 rewards people who understand process and order. Memorise the IR phases and the order of volatility. For tool questions, know what each tool does — not just its name.