Back to the study

Learning term

Initial response — Incident analysis and recovery

Initial response acknowledges the incident, preserves evidence, limits harm, and assigns ownership. This card shows its role in “Incident analysis and recovery” and a safe diagnostic path.

Incident analysis and recoveryLevel 0–3

Orientation

Initial response acknowledges the incident, preserves evidence, limits harm, and assigns ownership. At this level, separate purpose, input, and visible result. Place Initial response within Incident analysis and recovery before changing settings or files.

Exercise

Try it safely

A previously reachable service fails after a change. For Initial response, preserve the timeline, task history, exit code, latest logs, and resource state; then test the smallest justified correction and confirm recovery with the same request. Open an isolated test environment and run “docker service ps example-service --no-trunc”. Write down the expected output first, do not alter production data, and record one safe next diagnostic step.

docker service ps example-service --no-trunc

Quick check

Can you explain the purpose, observable state, and most common failure source of Initial response — Incident analysis and recovery in one sentence each? Which evidence would you preserve before changing anything, and which repeated test would prove that the correction actually worked?