Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.
Incident ResponseEasy
Q1. What is incident response?
- A.An organized approach to addressing and managing a security breach to limit damage✓ Correct
- B.Generating redundant backup copies of system data for disaster recovery
- C.Installing routine software updates on regularly scheduled maintenance days
- D.Ignoring security events and hoping they resolve on their own naturally
Explanation
Incident response is the systematic approach to handling security incidents.
Report an error in this question
Incident ResponseEasy
Q2. What is the first phase of incident response?
- A.Recovery
- B.Containment
- C.Preparation✓ Correct
- D.Eradication
Explanation
Preparation involves creating the plan, assembling the team, and ensuring necessary tools are available.
Report an error in this question
Incident ResponseEasy
Q3. What is the purpose of incident documentation?
- A.To blame someone specific for causing the incident
- B.To delete evidence of the incident from all records
- C.To create unnecessary bureaucratic paperwork and overhead
- D.To maintain a detailed record of the incident, actions taken, and findings✓ Correct
Explanation
Documentation creates a detailed record supporting analysis, legal proceedings, and improvement.
Report an error in this question
Incident ResponseEasy
Q4. What is an incident in cyber security?
- A.A routine patch applied to update system software used in enterprise computing environments
- B.An event that threatens the security, confidentiality, integrity, or availability of information assets✓ Correct
- C.A physical hardware component used in computing infrastructure
- D.A scheduled maintenance within enterprise computing environments
Explanation
A security incident violates or threatens organizational security policies.
Report an error in this question
Incident ResponseEasy
Q5. What is an incident response team?
- A.A marketing team managing brand awareness campaigns used in enterprise computing environments
- B.Trained personnel responsible for detecting, analyzing, and responding to security incidents✓ Correct
- C.A software application used for enterprise computing operations
- D.A group of malicious hackers targeting an organization used in enterprise computing environments
Explanation
An incident response team handles security incidents from detection through resolution.
Report an error in this question
Incident ResponseEasy
Q6. Why is having an incident response plan important?
- A.It ensures quick, organized, and effective response to security incidents✓ Correct
- B.Continuous monitoring is not important for security
- C.It eliminates all threats regardless of the specific situation or context
- D.It replaces security tools within enterprise security environments
Explanation
An incident response plan ensures effective response, minimizing damage and recovery time.
Report an error in this question
Incident ResponseEasy
Q7. What is the difference between an event and an incident?
- A.Events are worse than incidents in terms of damage across computing environments
- B.They are fundamentally identical concepts with no meaningful differences
- C.Incidents are planned events scheduled by the security team
- D.An event is any observable occurrence; an incident negatively impacts security or violates policy✓ Correct
Explanation
An event is any observable occurrence, while an incident specifically threatens security.
Report an error in this question
Incident ResponseEasy
Q8. What is the purpose of the containment phase?
- A.To ignore the incident and let it resolve on its own
- B.To limit the scope and damage by isolating affected systems✓ Correct
- C.To start a new project unrelated to the current incident
- D.To spread and propagate the incident to other systems
Explanation
Containment stops the incident from spreading by isolating affected systems.
Report an error in this question
Incident ResponseEasy
Q9. What should you do if you suspect a security incident?
- A.Report it immediately to the appropriate security team✓ Correct
- B.Try to fix it yourself without informing anyone
- C.Delete all files to eliminate any potential evidence
- D.Ignore it and continue with normal operations as usual
Explanation
Suspected incidents should be immediately reported following established procedures.
Report an error in this question
Incident ResponseMedium
Q10. What is threat hunting?
- A.A recreational entertainment application for consumer devices
- B.Hunting animals within enterprise security environments
- C.Proactively searching through networks to detect threats that evaded existing controls✓ Correct
- D.Installing antivirus software on the development machine
Explanation
Threat hunting proactively searches for advanced threats that have bypassed automated controls.
Report an error in this question
Incident ResponseMedium
Q11. What is the role of a CISO during a major incident?
- A.To write code within enterprise computing infrastructure and management
- B.To provide strategic leadership, coordinate response, and make critical containment decisions✓ Correct
- C.To fix computers within enterprise computing infrastructure and management
- D.To design websites for enterprise computing environments and management
Explanation
The CISO provides executive leadership, coordinates response, and manages disclosure requirements.
Report an error in this question
Incident ResponseEasy
Q12. What is a security alert?
- A.A fire alarm system installed in a physical building
- B.A notification indicating a potential security event requiring investigation✓ Correct
- C.A performance warning about high system resource usage
- D.A software update notification from the operating system
Explanation
A security alert indicates a potential security event requiring attention.
Report an error in this question
Incident ResponseMedium
Q13. What is triage in incident response?
- A.A network tool used in enterprise network infrastructure
- B.Prioritizing incidents based on severity, impact, and urgency to allocate resources✓ Correct
- C.A strain of self-replicating malicious software programs
- D.Medical treatment within enterprise security environments
Explanation
Triage assesses and categorizes incidents by severity to prioritize response efforts.
Report an error in this question
Incident ResponseMedium
Q14. What is a lessons learned review?
- A.A post-incident analysis of what happened, what worked, what failed, and how to improve✓ Correct
- B.A security audit deployed across enterprise environments used in enterprise computing environments
- C.A training course within enterprise computing environments
- D.A school exam within enterprise computing environments
Explanation
A lessons learned review identifies improvements for policies, procedures, and tools.
Report an error in this question
Incident ResponseHard
Q15. How does the SANS incident response framework differ from NIST?
- A.SANS has only 3 steps within enterprise security environments without additional considerations
- B.SANS emphasizes Identification vs. NIST's Detection and Analysis, and is more practitioner-oriented✓ Correct
- C.They are fundamentally identical concepts with no meaningful differences between them at all
- D.NIST has 10 distinct steps within enterprise security environments for incident handling
Explanation
SANS emphasizes Identification over Detection and Analysis and is more practitioner-oriented.
Report an error in this question
Incident ResponseHard
Q16. What is a CSIRT and its key functions?
- A.A specialized team handling incident monitoring, triage, analysis, coordination, and advisory services✓ Correct
- B.A software application used for enterprise computing operations
- C.A user account type with specifically assigned access permissions
- D.A network administration team managing infrastructure used in enterprise computing environments
Explanation
A CSIRT provides incident monitoring, triage, technical analysis, and coordination.
Report an error in this question
Incident ResponseMedium
Q17. What is the recovery phase?
- A.Restoring affected systems to normal operation and monitoring for recurrence✓ Correct
- B.Recovering deleted emails within enterprise security environments
- C.A data backup process for managing enterprise data resources
- D.Finding lost items within enterprise security environments
Explanation
Recovery restores systems from clean backups, verifies functionality, and watches for recurrence.
Report an error in this question
Incident ResponseMedium
Q18. What is the purpose of incident classification?
- A.To categorize incidents by type and severity for appropriate response and resource allocation✓ Correct
- B.To file paperwork within the data management framework and management
- C.To rank team members within enterprise computing infrastructure and management
- D.To organize files within the data management framework and management
Explanation
Classification determines appropriate response procedures, resources, and escalation.
Report an error in this question
Incident ResponseMedium
Q19. What is the importance of communication during incident response?
- A.Communication should wait until after resolution
- B.Clear, timely communication with stakeholders is essential for effective coordination✓ Correct
- C.Only technical communication matters without any additional considerations needed
- D.Communication is not needed in any deployment scenario or context
Explanation
Effective communication ensures coordination, stakeholder awareness, and regulatory compliance.
Report an error in this question
Incident ResponseMedium
Q20. What is the eradication phase?
- A.Deleting the incident report within enterprise security environments
- B.Removing the root cause including malware, compromised accounts, and exploited vulnerabilities✓ Correct
- C.Erasing all data regardless of the specific situation or context
- D.Shutting down all systems regardless of the specific situation or context
Explanation
Eradication removes the root cause from the environment.
Report an error in this question
Incident ResponseMedium
Q21. What are the six phases of the NIST incident response lifecycle?
- A.Design, Develop, Test, Release, Maintain, Retire across computing environments
- B.Preparation, Detection and Analysis, Containment, Eradication, Recovery, Post-Incident Activity✓ Correct
- C.None of these in any deployment scenario or context across computing environments
- D.Plan, Build, Test, Deploy, Monitor, Retire within enterprise security environments
Explanation
NIST SP 800-61 defines: Preparation, Detection/Analysis, Containment, Eradication, Recovery, Post-Incident Activity.
Report an error in this question
Incident ResponseMedium
Q22. What is a playbook in incident response?
- A.A game manual within modern computing environments
- B.A software manual used in enterprise computing environments
- C.A children's book within modern computing environments
- D.Predefined procedures for responding to specific types of security incidents✓ Correct
Explanation
Playbooks provide step-by-step procedures for handling specific incident types.
Report an error in this question
Incident ResponseHard
Q23. What is cyber insurance?
- A.An automated backup solution designed for enterprise data recovery and restoration needs
- B.Insurance covering financial losses from cyber incidents including forensics, legal fees, and notification✓ Correct
- C.Car insurance for covering vehicle damage and repair costs resulting from accidents
- D.Health insurance covering IT staff medical expenses, benefits, and wellness programs
Explanation
Cyber insurance covers financial losses from security incidents including forensics and legal costs.
Report an error in this question
Incident ResponseHard
Q24. What is the role of digital forensics in incident response?
- A.An activity reserved only for law enforcement investigators used in enterprise computing environments
- B.A separate unrelated discipline with no connection within modern computing environments
- C.Completely replacing incident response with alternatives across computing environments
- D.Providing scientific examination of evidence to understand attack vector, scope, timeline, and attribution✓ Correct
Explanation
Digital forensics determines attack methods, scope, timeline, and attribution to support response and legal action.
Report an error in this question
Incident ResponseHard
Q25. What is the difference between an incident and a data breach?
- A.They are functionally identical frameworks with no differences in any deployment scenario or context
- B.A breach is less serious than a standard incident within modern computing environments
- C.An incident only involves malware and no other threats designed for compromising system integrity
- D.An incident is any event threatening security; a breach specifically involves confirmed unauthorized access to sensitive data✓ Correct
Explanation
A data breach is a specific incident type where sensitive data has been confirmed to be accessed or disclosed.
Report an error in this question
Incident ResponseHard
Q26. What is the role of threat intelligence in incident response?
- A.A type of self-replicating malicious software designed for system infiltration attacks
- B.Generating and distributing threats against specifically targeted computing systems
- C.Providing context about threat actors, TTPs, and IOCs to accelerate detection and guide response✓ Correct
- D.A compliance reporting tool designed for generating audit documentation and reports
Explanation
Threat intelligence provides actionable information about adversary tactics to improve detection and response.
Report an error in this question
Incident ResponseHard
Q27. What is the purpose of tabletop exercises?
- A.Playing board games for team building recreation purposes across computing environments
- B.Discussion-based exercises to test plans, identify gaps, and improve coordination without operational impact✓ Correct
- C.A physical security measure for protecting building infrastructure
- D.Testing table strength and durability for furniture quality across computing environments
Explanation
Tabletop exercises simulate scenarios to test plans and identify gaps without operational disruption.
Report an error in this question
Incident ResponseHard
Q28. What are the legal considerations during incident response?
- A.Evidence preservation, regulatory notification requirements, privacy laws, and law enforcement coordination✓ Correct
- B.Only criminal law applies without any specific legislation across computing environments
- C.Only privacy laws matter during incident response without any additional considerations needed
- D.No legal considerations exist during incident response regardless of the deployment context or scenario
Explanation
Legal considerations include evidence preservation, regulatory notifications, and law enforcement coordination.
Report an error in this question
Incident ResponseHard
Q29. What is the 'assume breach' concept?
- A.Accepting all risks without any mitigation efforts across computing environments
- B.Planning with the assumption that breaches will occur, focusing on detection, response, and recovery✓ Correct
- C.Disabling all security controls for maximum performance across computing environments
- D.Ignoring security entirely without any protective measures
Explanation
Assume breach shifts focus to strong detection, response, and recovery alongside prevention.
Report an error in this question
Incident ResponseHard
Q30. What is SOAR?
- A.A next-generation firewall security appliance deployed across enterprise environments
- B.A software application used for enterprise computing operations
- C.A technology stack integrating security tools, automating response tasks, and orchestrating workflows✓ Correct
- D.A music platform for streaming and listening to audio used in enterprise computing environments
Explanation
SOAR integrates tools, automates repetitive tasks, and orchestrates workflows for efficient response.
Report an error in this question