WorksheetsCybersecurity Incident Response Quiz
Total questions: 20
Worksheet time: 10mins
You notice unusual user behavior on your network, such as multiple failed login attempts. What's your first action?
Eradicate the threat immediately
Restore normal system operations
Investigate and classify it as a potential cyber incident
Skip monitoring and wait for an alert
While investigating a recent cyberattack, you realize the attacker exploited a vulnerability your team was unaware of. What could have been done earlier to reduce this risk?
Wait for the vulnerability to be exploited before addressing it
Regular vulnerability assessments and proactive mitigation
Focus on responding quickly to active threats only
Avoid making changes to existing systems
Your team is debating which tool is best to monitor unusual user behavior. Which one should you recommend?
A password manager
A vulnerability scanner
A SIEM tool
A firewall
Imagine you're tracking an ongoing cyber incident. You decide to isolate one server to prevent the attack from spreading. What kind of strategy are you implementing?
Communication
Threat elimination
Isolation as part of damage control
Restoring operations
A colleague shares an alert about unusual network activity, but it's unclear if it's a cyberattack. What would be your first step to manage this situation?
Start restoring systems immediately
Investigate and confirm the nature of the activity
Notify all stakeholders about a confirmed breach
Perform a system-wide reboot
During a cybersecurity simulation, you are asked to prioritize tasks. Which action would you perform first if your team identifies an active threat?
Begin restoring affected systems
Notify external stakeholders
Take immediate steps to stop the threat's spread
Document the incident
A team member suggests completely shutting down all servers during a cyberattack to stop the spread of the threat. What's a potential downside to this approach?
It disrupts operations unnecessarily
It accelerates incident containment
It eradicates the threat completely
It improves team efficiency
Your manager wants to prevent phishing incidents in the future. What would be the best proactive step to recommend?
Focus only on system monitoring tools
Implement stricter access controls for all users
Conduct company-wide phishing awareness training
Rely solely on antivirus tools
Your company's system shows signs of a potential data breach. What's the most important reason to classify the severity of the incident?
To allocate resources based on urgency
To decide on the recovery timeline
To immediately notify law enforcement
To avoid reporting minor incidents
An employee reports their account has been locked due to suspicious login attempts. What should be your team's next step?
Reset the user's password immediately
Wait for the user to regain access and report further issues
Investigate the source of the suspicious activity
Notify all users about the incident
A new hire on your team asks why incident reviews are necessary after every response. How would you explain their value?
They are required for compliance
They help improve future response efforts
They reduce the need for communication
They speed up recovery in ongoing incidents
A recent ransomware attack has left your organization's servers encrypted. Which immediate action will prevent the ransomware from spreading further?
Isolate affected servers
Begin paying the ransom
Notify external stakeholders
Focus on lessons learned
Your team discovers that the attack originated from a phishing email. To prevent this in the future, which step should you prioritize?
Avoid using email as a communication tool
Monitor all employee inboxes in real-time
Train employees to recognize phishing indicators
Focus on antivirus upgrades
During a mock incident, your team accidentally communicated incomplete information to stakeholders. What is one way to avoid this mistake in real incidents?
Limit communication to internal teams only
Create clear templates for incident communication
Delay communication until all facts are confirmed
Avoid external communication entirely
You're reviewing a recent incident where a system was fully restored but later found to have residual vulnerabilities. What step was likely missed?
Documentation of the incident
Classification of the incident
Verification of system integrity post-recovery
Isolating the affected system
A company policy requires that all incidents are reviewed to identify potential gaps in the response plan. What is the main goal of this process?
Reduce the time spent on containment
Classify incidents more efficiently
Improve the organization's readiness for future incidents
Minimize external communication
You've successfully removed malware from a compromised server, but employees still report slow system performance. What's the likely cause?
Overuse of server resources
Incorrect malware removal techniques
Residual threats or undetected vulnerabilities
Employee error
You're tasked with improving your company's cybersecurity defenses. Which measure would best prevent incidents before they occur?
Focus only on eradication strategies
Implement preventive measures like patch management
Prioritize recovery tools over preparation
Avoid investing in user training programs
An executive is concerned about the downtime caused by past incidents. What improvement should you propose to address this?
Use lessons learned to reduce future recovery time
Invest in communication templates
Update the Incident Response Plan with faster containment strategies
Focus solely on detection tools
During an annual review, your company considers adopting a SOAR tool. What's the key benefit of this tool?
Detecting phishing emails
Simplifying password management
Automating incident response workflows
Encrypting sensitive data
