HomeSubjectsUniversityBlogAbout

Incident Response

Topic in Cyber Security

210 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Incident response is an organization's structured approach to detecting, containing and recovering from security incidents while limiting damage and cost. Most questions follow the NIST lifecycle of preparation, detection and analysis, containment, eradication and recovery, and post-incident activity, or the similar SANS six-step model. You should know why containment comes before eradication, how triage ranks incidents by severity, and what playbooks and CSIRT roles contain. Scenario items ask about out-of-band communication when attackers may be watching, preserving evidence during collection, tabletop exercises for rehearsal, and lessons-learned reviews that feed back into preparation.

Below are 30 practice questions from a pool of 210 Incident Response MCQs, one of 16 topics in Cyber Security. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

Incident ResponseEasy

Q1. What is incident response?

  1. A.An organized approach to addressing and managing a security breach to limit damage✓ Correct
  2. B.Generating redundant backup copies of system data for disaster recovery
  3. C.Installing routine software updates on regularly scheduled maintenance days
  4. D.Ignoring security events and hoping they resolve on their own naturally

Explanation

Incident response is the systematic approach to handling security incidents.

Report an error in this question

Incident ResponseEasy

Q2. What is the first phase of incident response?

  1. A.Recovery
  2. B.Containment
  3. C.Preparation✓ Correct
  4. D.Eradication

Explanation

Preparation involves creating the plan, assembling the team, and ensuring necessary tools are available.

Report an error in this question

Incident ResponseEasy

Q3. What is the purpose of incident documentation?

  1. A.To blame someone specific for causing the incident
  2. B.To delete evidence of the incident from all records
  3. C.To create unnecessary bureaucratic paperwork and overhead
  4. D.To maintain a detailed record of the incident, actions taken, and findings✓ Correct

Explanation

Documentation creates a detailed record supporting analysis, legal proceedings, and improvement.

Report an error in this question

Incident ResponseEasy

Q4. What is an incident in cyber security?

  1. A.A routine patch applied to update system software used in enterprise computing environments
  2. B.An event that threatens the security, confidentiality, integrity, or availability of information assets✓ Correct
  3. C.A physical hardware component used in computing infrastructure
  4. D.A scheduled maintenance within enterprise computing environments

Explanation

A security incident violates or threatens organizational security policies.

Report an error in this question

Incident ResponseEasy

Q5. What is an incident response team?

  1. A.A marketing team managing brand awareness campaigns used in enterprise computing environments
  2. B.Trained personnel responsible for detecting, analyzing, and responding to security incidents✓ Correct
  3. C.A software application used for enterprise computing operations
  4. D.A group of malicious hackers targeting an organization used in enterprise computing environments

Explanation

An incident response team handles security incidents from detection through resolution.

Report an error in this question

Incident ResponseEasy

Q6. Why is having an incident response plan important?

  1. A.It ensures quick, organized, and effective response to security incidents✓ Correct
  2. B.Continuous monitoring is not important for security
  3. C.It eliminates all threats regardless of the specific situation or context
  4. D.It replaces security tools within enterprise security environments

Explanation

An incident response plan ensures effective response, minimizing damage and recovery time.

Report an error in this question

Incident ResponseEasy

Q7. What is the difference between an event and an incident?

  1. A.Events are worse than incidents in terms of damage across computing environments
  2. B.They are fundamentally identical concepts with no meaningful differences
  3. C.Incidents are planned events scheduled by the security team
  4. D.An event is any observable occurrence; an incident negatively impacts security or violates policy✓ Correct

Explanation

An event is any observable occurrence, while an incident specifically threatens security.

Report an error in this question

Incident ResponseEasy

Q8. What is the purpose of the containment phase?

  1. A.To ignore the incident and let it resolve on its own
  2. B.To limit the scope and damage by isolating affected systems✓ Correct
  3. C.To start a new project unrelated to the current incident
  4. D.To spread and propagate the incident to other systems

Explanation

Containment stops the incident from spreading by isolating affected systems.

Report an error in this question

Incident ResponseEasy

Q9. What should you do if you suspect a security incident?

  1. A.Report it immediately to the appropriate security team✓ Correct
  2. B.Try to fix it yourself without informing anyone
  3. C.Delete all files to eliminate any potential evidence
  4. D.Ignore it and continue with normal operations as usual

Explanation

Suspected incidents should be immediately reported following established procedures.

Report an error in this question

Incident ResponseMedium

Q10. What is threat hunting?

  1. A.A recreational entertainment application for consumer devices
  2. B.Hunting animals within enterprise security environments
  3. C.Proactively searching through networks to detect threats that evaded existing controls✓ Correct
  4. D.Installing antivirus software on the development machine

Explanation

Threat hunting proactively searches for advanced threats that have bypassed automated controls.

Report an error in this question

Incident ResponseMedium

Q11. What is the role of a CISO during a major incident?

  1. A.To write code within enterprise computing infrastructure and management
  2. B.To provide strategic leadership, coordinate response, and make critical containment decisions✓ Correct
  3. C.To fix computers within enterprise computing infrastructure and management
  4. D.To design websites for enterprise computing environments and management

Explanation

The CISO provides executive leadership, coordinates response, and manages disclosure requirements.

Report an error in this question

Incident ResponseEasy

Q12. What is a security alert?

  1. A.A fire alarm system installed in a physical building
  2. B.A notification indicating a potential security event requiring investigation✓ Correct
  3. C.A performance warning about high system resource usage
  4. D.A software update notification from the operating system

Explanation

A security alert indicates a potential security event requiring attention.

Report an error in this question

Incident ResponseMedium

Q13. What is triage in incident response?

  1. A.A network tool used in enterprise network infrastructure
  2. B.Prioritizing incidents based on severity, impact, and urgency to allocate resources✓ Correct
  3. C.A strain of self-replicating malicious software programs
  4. D.Medical treatment within enterprise security environments

Explanation

Triage assesses and categorizes incidents by severity to prioritize response efforts.

Report an error in this question

Incident ResponseMedium

Q14. What is a lessons learned review?

  1. A.A post-incident analysis of what happened, what worked, what failed, and how to improve✓ Correct
  2. B.A security audit deployed across enterprise environments used in enterprise computing environments
  3. C.A training course within enterprise computing environments
  4. D.A school exam within enterprise computing environments

Explanation

A lessons learned review identifies improvements for policies, procedures, and tools.

Report an error in this question

Incident ResponseHard

Q15. How does the SANS incident response framework differ from NIST?

  1. A.SANS has only 3 steps within enterprise security environments without additional considerations
  2. B.SANS emphasizes Identification vs. NIST's Detection and Analysis, and is more practitioner-oriented✓ Correct
  3. C.They are fundamentally identical concepts with no meaningful differences between them at all
  4. D.NIST has 10 distinct steps within enterprise security environments for incident handling

Explanation

SANS emphasizes Identification over Detection and Analysis and is more practitioner-oriented.

Report an error in this question

Incident ResponseHard

Q16. What is a CSIRT and its key functions?

  1. A.A specialized team handling incident monitoring, triage, analysis, coordination, and advisory services✓ Correct
  2. B.A software application used for enterprise computing operations
  3. C.A user account type with specifically assigned access permissions
  4. D.A network administration team managing infrastructure used in enterprise computing environments

Explanation

A CSIRT provides incident monitoring, triage, technical analysis, and coordination.

Report an error in this question

Incident ResponseMedium

Q17. What is the recovery phase?

  1. A.Restoring affected systems to normal operation and monitoring for recurrence✓ Correct
  2. B.Recovering deleted emails within enterprise security environments
  3. C.A data backup process for managing enterprise data resources
  4. D.Finding lost items within enterprise security environments

Explanation

Recovery restores systems from clean backups, verifies functionality, and watches for recurrence.

Report an error in this question

Incident ResponseMedium

Q18. What is the purpose of incident classification?

  1. A.To categorize incidents by type and severity for appropriate response and resource allocation✓ Correct
  2. B.To file paperwork within the data management framework and management
  3. C.To rank team members within enterprise computing infrastructure and management
  4. D.To organize files within the data management framework and management

Explanation

Classification determines appropriate response procedures, resources, and escalation.

Report an error in this question

Incident ResponseMedium

Q19. What is the importance of communication during incident response?

  1. A.Communication should wait until after resolution
  2. B.Clear, timely communication with stakeholders is essential for effective coordination✓ Correct
  3. C.Only technical communication matters without any additional considerations needed
  4. D.Communication is not needed in any deployment scenario or context

Explanation

Effective communication ensures coordination, stakeholder awareness, and regulatory compliance.

Report an error in this question

Incident ResponseMedium

Q20. What is the eradication phase?

  1. A.Deleting the incident report within enterprise security environments
  2. B.Removing the root cause including malware, compromised accounts, and exploited vulnerabilities✓ Correct
  3. C.Erasing all data regardless of the specific situation or context
  4. D.Shutting down all systems regardless of the specific situation or context

Explanation

Eradication removes the root cause from the environment.

Report an error in this question

Incident ResponseMedium

Q21. What are the six phases of the NIST incident response lifecycle?

  1. A.Design, Develop, Test, Release, Maintain, Retire across computing environments
  2. B.Preparation, Detection and Analysis, Containment, Eradication, Recovery, Post-Incident Activity✓ Correct
  3. C.None of these in any deployment scenario or context across computing environments
  4. D.Plan, Build, Test, Deploy, Monitor, Retire within enterprise security environments

Explanation

NIST SP 800-61 defines: Preparation, Detection/Analysis, Containment, Eradication, Recovery, Post-Incident Activity.

Report an error in this question

Incident ResponseMedium

Q22. What is a playbook in incident response?

  1. A.A game manual within modern computing environments
  2. B.A software manual used in enterprise computing environments
  3. C.A children's book within modern computing environments
  4. D.Predefined procedures for responding to specific types of security incidents✓ Correct

Explanation

Playbooks provide step-by-step procedures for handling specific incident types.

Report an error in this question

Incident ResponseHard

Q23. What is cyber insurance?

  1. A.An automated backup solution designed for enterprise data recovery and restoration needs
  2. B.Insurance covering financial losses from cyber incidents including forensics, legal fees, and notification✓ Correct
  3. C.Car insurance for covering vehicle damage and repair costs resulting from accidents
  4. D.Health insurance covering IT staff medical expenses, benefits, and wellness programs

Explanation

Cyber insurance covers financial losses from security incidents including forensics and legal costs.

Report an error in this question

Incident ResponseHard

Q24. What is the role of digital forensics in incident response?

  1. A.An activity reserved only for law enforcement investigators used in enterprise computing environments
  2. B.A separate unrelated discipline with no connection within modern computing environments
  3. C.Completely replacing incident response with alternatives across computing environments
  4. D.Providing scientific examination of evidence to understand attack vector, scope, timeline, and attribution✓ Correct

Explanation

Digital forensics determines attack methods, scope, timeline, and attribution to support response and legal action.

Report an error in this question

Incident ResponseHard

Q25. What is the difference between an incident and a data breach?

  1. A.They are functionally identical frameworks with no differences in any deployment scenario or context
  2. B.A breach is less serious than a standard incident within modern computing environments
  3. C.An incident only involves malware and no other threats designed for compromising system integrity
  4. D.An incident is any event threatening security; a breach specifically involves confirmed unauthorized access to sensitive data✓ Correct

Explanation

A data breach is a specific incident type where sensitive data has been confirmed to be accessed or disclosed.

Report an error in this question

Incident ResponseHard

Q26. What is the role of threat intelligence in incident response?

  1. A.A type of self-replicating malicious software designed for system infiltration attacks
  2. B.Generating and distributing threats against specifically targeted computing systems
  3. C.Providing context about threat actors, TTPs, and IOCs to accelerate detection and guide response✓ Correct
  4. D.A compliance reporting tool designed for generating audit documentation and reports

Explanation

Threat intelligence provides actionable information about adversary tactics to improve detection and response.

Report an error in this question

Incident ResponseHard

Q27. What is the purpose of tabletop exercises?

  1. A.Playing board games for team building recreation purposes across computing environments
  2. B.Discussion-based exercises to test plans, identify gaps, and improve coordination without operational impact✓ Correct
  3. C.A physical security measure for protecting building infrastructure
  4. D.Testing table strength and durability for furniture quality across computing environments

Explanation

Tabletop exercises simulate scenarios to test plans and identify gaps without operational disruption.

Report an error in this question

Incident ResponseHard

Q28. What are the legal considerations during incident response?

  1. A.Evidence preservation, regulatory notification requirements, privacy laws, and law enforcement coordination✓ Correct
  2. B.Only criminal law applies without any specific legislation across computing environments
  3. C.Only privacy laws matter during incident response without any additional considerations needed
  4. D.No legal considerations exist during incident response regardless of the deployment context or scenario

Explanation

Legal considerations include evidence preservation, regulatory notifications, and law enforcement coordination.

Report an error in this question

Incident ResponseHard

Q29. What is the 'assume breach' concept?

  1. A.Accepting all risks without any mitigation efforts across computing environments
  2. B.Planning with the assumption that breaches will occur, focusing on detection, response, and recovery✓ Correct
  3. C.Disabling all security controls for maximum performance across computing environments
  4. D.Ignoring security entirely without any protective measures

Explanation

Assume breach shifts focus to strong detection, response, and recovery alongside prevention.

Report an error in this question

Incident ResponseHard

Q30. What is SOAR?

  1. A.A next-generation firewall security appliance deployed across enterprise environments
  2. B.A software application used for enterprise computing operations
  3. C.A technology stack integrating security tools, automating response tasks, and orchestrating workflows✓ Correct
  4. D.A music platform for streaming and listening to audio used in enterprise computing environments

Explanation

SOAR integrates tools, automates repetitive tasks, and orchestrates workflows for efficient response.

Report an error in this question

Ready to test yourself on Incident Response?

Take a timed quiz drawn from 210+ questions on this topic. No signup required — your progress saves in your browser.

Start Incident Response Quiz