WorksheetsIncident Handling
Total questions: 20
Worksheet time: 10mins
What is the primary focus of Day 1 in cyber security incident handling?
a) Incident Analysis
b) Legal and Regulatory Considerations
c) Introduction to Cyber Security Incident Handling
d) Incident Recovery
Which sector faces unique challenges in incident handling?
a) Private Sector
b) Healthcare Sector
c) Government Organizations
d) Education Sector
What is the purpose of incident response frameworks in the public sector?
a) Identifying hackers
b) Handling physical security
c) Providing legal assistance
d) Guiding incident response efforts
Incident response frameworks are not important in the public sector.
True
False
What does Day 2 primarily focus on?
a) Strengthening Cyber Security
b) Incident Analysis and Response
c) Incident Recovery
d) Network Monitoring
Incident triage and prioritization are based on what criteria?
a) The time of day
b) Incident severity and criticality
c) The number of incidents
d) Random selection
Incident triage involves assessing the severity and criticality of incidents.
True
False
Threat intelligence does not play a significant role in incident response.
True
False
What is the role of threat intelligence in incident response?
a) Providing legal counsel
b) Identifying vulnerabilities
c) Enhancing incident response
d) Handling business continuity
What is the primary goal of incident containment?
a) Identifying attackers
b) Eradicating all incidents
c) Preventing further damage
d) Reporting incidents to authorities
What is the focus of Day 3 in cyber security incident handling?
a) Incident Analysis
b) Strengthening Cyber Security
c) Incident Recovery
d) Legal Considerations
The primary goal of incident containment is to eradicate all incidents.
True
False
Vulnerability management is crucial for identifying and addressing potential threats.
True
False
Secure configuration and access controls are not relevant in the public sector.
True
False
What is the purpose of vulnerability management in the public sector?
a) Identifying potential threats
b) Enhancing patching strategies
c) Investigating incidents
d) Legal compliance
What does "incident recovery" refer to?
a) Identifying threats
b) Restoring normal operations
c) Investigating incidents
d) Legal actions
Network monitoring is not necessary for public sector IT infrastructure.
True
False
Business continuity planning is related to incident recovery.
True
False
Incident reporting is not specific or necessary to the public sector. Government offices would just rely on DRP.
True
False
Post-incident analysis is a valuable part of incident handling in the public sector.
True
False
