WorksheetsIncident Response
Total questions: 30
Worksheet time: 15mins
Name
Class
Date
1.
The main purpose of a hot site in disaster recovery is to:
a)
Provide a secure location for storing sensitive data.
b)
Offer a temporary workspace for displaced employees.
c)
Enable a rapid switch-over to a fully operational backup environment.
d)
Facilitate communication with stakeholders during a crisis.
2.
The "Identify" function in the NIST framework involves understanding:
a)
The best methods for data encryption.
b)
The types of antivirus software available.
c)
Your organization's critical assets and vulnerabilities.
d)
The latest cyberattack trends worldwide.
3.
Which of the following is an example of an incident containment strategy?
a)
Installing new hardware
b)
Blocking malicious IP addresses
c)
Updating user passwords regularly
d)
Conducting a security awareness program
4.
During which phase are lessons learned documented and analyzed?
a)
Preparation
b)
Detection and Analysis
c)
Containment, Eradication, and Recovery
d)
Post-Incident Activity
5.
A tool like Splunk is primarily used for:
a)
Vulnerability scanning
b)
Security information and event management
c)
Endpoint detection
d)
Malware analysis
6.
Which phase of incident response includes conducting regular training and awareness programs for employees?
a)
Preparation
b)
Detection and Analysis
c)
Containment, Eradication, and Recovery
d)
Post-Incident Activity
7.
In the context of incident response, what is the purpose of conducting a Business Impact Analysis (BIA)?
a)
To detect security incidents
b)
To establish communication channels
c)
To understand the impact of disruptions on business functions
d)
To automate incident response tasks
8.
What is the main function of a SIEM system?
a)
To provide endpoint detection and response capabilities
b)
To collect and analyze security event data
c)
To automate incident response tasks
d)
To aggregate threat intelligence data
9.
Which of the following is considered an indicator of compromise?
a)
Regularly scheduled backup
b)
Unusual outbound network traffic
c)
Software update notification
d)
System reboot
10.
Unauthorized login attempts are an indicator of what type of security incident?
a)
Data exfiltration
b)
Phishing attack
c)
Brute-force attack
d)
Denial-of-service attack
11.
What does the presence of a new, unexpected user account on a system likely indicate?
a)
Normal user activity
b)
Security breach
c)
System update
d)
Backup restoration
12.
Which phase of incident response involves removing malicious elements from affected systems?
a)
Phase 1
b)
Phase 2
c)
Phase 3
d)
Phase 4
13.
What is a common goal during the containment phase of incident response?
a)
To improve system performance
b)
To isolate affected systems to prevent further damage
c)
To install new software
d)
To conduct user training
14.
The process of restoring IT systems and data after a major disruption is known as:
a)
Incident Response
b)
Business Continuity
c)
Disaster Recovery
d)
Threat Intelligence
15.
Which term refers to the ability to maintain essential functions during and after a disaster?
a)
Incident Response
b)
Business Continuity
c)
Disaster Recovery
d)
Vulnerability Management
16.
What does RTO stand for in the context of disaster recovery?
a)
Recovery Time Operation
b)
Recovery Time Objective
c)
Response to Outage
d)
Restoration Time Order
17.
A key component of IR preparedness includes:
a)
Implementing multi-factor authentication.
b)
Investigating suspicious network activity during an ongoing incident.
c)
Restoring data from backups after a security breach.
d)
Isolating compromised systems to prevent further damage.
18.
Which of the following is NOT typically included in an IR plan?
a)
Procedures for identifying and reporting security incidents.
b)
Roles and responsibilities for IR team members.
c)
Communication protocols for notifying stakeholders during an incident.
d)
Recommendations for specific software programs to purchase.
19.
The primary goal of the containment phase of an IR incident is to:
a)
Identify the root cause of the security incident.
b)
Restore critical business functions to minimize downtime.
c)
Stop the ongoing incident and prevent further damage.
d)
Train employees on how to prevent similar incidents in the future.
20.
What does the acronym IOC stand for in the context of cybersecurity?
a)
Information on Cyberthreats
b)
Indicator of Compromise
c)
Incident of Concern
d)
Initial Operating Condition
21.
Which of the following describes a Zero-Day vulnerability?
a)
A known vulnerability that has a patch available
b)
A vulnerability that is exploited before it is known to the vendor
c)
A previously patched vulnerability that reappears
d)
A minor vulnerability with no significant impact
22.
Which of the following is a proactive security measure that can help prevent incidents?
a)
Performing regular backups
b)
Responding to alerts
c)
Conducting a post-incident review
d)
Using honeypots
23.
Which type of incident typically involves sending a large volume of traffic to a network or website to overwhelm it?
a)
Phishing
b)
Man-in-the-Middle
c)
Denial-of-Service (DoS)
d)
Data Exfiltration
24.
Which of the following best describes the "eradication" step in the incident response process?
a)
Monitoring systems for unusual activity
b)
Removing the root cause of the incident
c)
Containing the incident to prevent further spread
d)
Analyzing logs and alerts
25.
Which tool is specifically designed to detect and prevent unauthorized access to a network?
a)
SIEM
b)
IDS/IPS
c)
EDR
d)
TIP
26.
Which of the following tools is primarily used for vulnerability scanning and management?
a)
SIEM
b)
IDS/IPS
c)
Nessus
d)
Volatility
27.
Which of the following activities is least likely to occur during the Preparation phase?
a)
Developing an incident response policy
b)
Conducting regular security awareness training
c)
Deploying patches to affected systems
d)
Establishing an incident response team
28.
Which phase of the incident response lifecycle includes verifying that systems are clean and monitoring for any signs of the threat returning?
a)
Preparation
b)
Detection and Analysis
c)
Containment
d)
Eradication and Recovery
29.
During which phase of the incident response lifecycle might an organization conduct a risk assessment to identify potential threats?
a)
Detection and Analysis
b)
Containment, Eradication, and Recovery
c)
Preparation
d)
Post-Incident Activity
30.
Vulnerability scanners are used to:
a)
Identify weaknesses and misconfigurations in IT systems.
b)
Collect and preserve digital evidence for investigations.
c)
Isolate compromised systems to prevent lateral movement.
d)
Train employees on cybersecurity best practices
100 %
