wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Module 19 CSEC

Total questions: 74

Worksheet time: 37mins

Name
Class
Date
1.

What is the primary purpose of Incident Response (IR)?

a)

To create new security policies

b)

To take organized and careful steps when reacting to a security incident

c)

To develop software applications

d)

To train new employees

2.

What is the first step in the sequence of steps involved in Incident Response?

a)

Implementing new security measures

b)

Identifying and reporting an incident

c)

Conducting employee training

d)

Shutting down all systems

3.

How do IR processes vary between organizations?

a)

They are the same for all organizations

b)

They differ according to their business and operating environment

c)

They depend on the size of the organization

d)

They are based on the number of employees

4.

What is the role of the Incident Handling and Response Team?

a)

To develop marketing strategies

b)

To collectively respond, remediate, mitigate, recover, and communicate the impact of incidents involving computer security breaches

c)

To manage financial accounts

d)

To oversee human resources

5.

What does the IH&R team work on when dealing with a security incident?

a)

A marketing plan

b)

An incident response plan

c)

A financial report

d)

A training manual

6.

Who in the IH&R team is responsible for leadership and decision-making authority?

a)

Information Security Team

b)

IT Staff

c)

Management

d)

Attorney

7.

Which role in the IH&R team is tasked with discovering and containing incidents?

a)

Physical Security Staff

b)

Information Security Team

c)

Attorney

d)

IT Staff

8.

Who is responsible for providing legal advice in the IH&R team?

a)

IT Staff

b)

Management

c)

Physical Security Staff

d)

Attorney

9.

Which team member is aware of the information system and network areas?

a)

IT Staff

b)

Attorney

c)

Management

d)

Physical Security Staff

10.

Who is responsible for physical security and identifying the extent of any damage in the IH&R team?

a)

Information Security Team

b)

Physical Security Staff

c)

Management

d)

Attorney

11.

Who is responsible for handling employee issues for an employee involved in an incident?

a)

PR Specialist

b)

Financial Auditor

c)

HR Representative

d)

IR Officer

12.

Which role is responsible for conveying company details after an incident?

a)

IR Manager

b)

PR Specialist

c)

Financial Auditor

d)

IR Custodians

13.

Who assesses the financial loss to a company from an incident?

a)

IR Officer

b)

HR Representative

c)

Financial Auditor

d)

IR Assessment Team

14.

What is the responsibility of the IR Officer?

a)

Handling employee issues

b)

Conveying company details

c)

Leading the IH&R team

d)

Responsible for all actions of the IR Team and IR Function

15.

Who leads the IH&R team in all IR activities?

a)

IR Manager

b)

PR Specialist

c)

Financial Auditor

d)

IR Custodians

16.

What is the role of the IR Assessment Team?

a)

Handling employee issues

b)

Making decisions on classifications and severity of incidents

c)

Conveying company details

d)

Assessing financial loss

17.

Who is responsible for the remediation and resolution of the incident that occurred?

a)

HR Representative

b)

PR Specialist

c)

IR Custodians

d)

Financial Auditor

18.

Who is a first responder?

a)

An individual who arrives first at the crime scene and brings the incident to the attention of others

b)

A person who investigates crimes after they occur

c)

A bystander who witnesses a crime

d)

A police officer who patrols the streets

19.

What role does a first responder play in incident response?

a)

They are responsible for the entire investigation process

b)

They provide great help in early detection of incidents and evidence collection

c)

They only secure the crime scene

d)

They handle all media communications

20.

Which of the following is NOT a responsibility of a first responder?

a)

Familiarity with network traffic and security policy

b)

Conducting the entire forensic investigation

c)

Early detection of incidents

d)

Evidence collection and preservation

21.

What is the first step in the roles and responsibilities of a first responder?

a)

Containing the incident

b)

Reporting the incident

c)

Identifying the crime scene

d)

Documenting all the findings

22.

Which role involves alerting the management and incidence response teams?

a)

Protecting the crime scene

b)

Collecting information

c)

Alerting

d)

Preserving evidence

23.

What does the 'Preserving' role focus on in first responder responsibilities?

a)

Preserving temporary and fragile evidence

b)

Packaging electronic evidence

c)

Containing the incident

d)

Identifying the crime scene

24.

Which responsibility involves packaging and transporting electronic evidence?

a)

Documenting findings

b)

Packaging and transporting

c)

Collecting information

d)

Reporting the incident

25.

What should a first responder review as part of the organization's incident response plan?

a)

Names and contact information of the local IH&R team

b)

Financial reports of the organization

c)

Marketing strategies

d)

Employee satisfaction surveys

26.

Which of the following is included in the escalation procedures for a first responder?

a)

Procedures for reporting and handling a suspected incident

b)

Daily work schedules

c)

Vacation policies

d)

Office decoration guidelines

27.

What type of actions are included in the incident response plan for various types of incidents?

a)

Containment actions

b)

Hiring processes

c)

Training programs

d)

Budget planning

28.

What is one of the main purposes of the IH&R process?

a)

To increase financial profits

b)

To protect networks and systems

c)

To reduce employee workload

d)

To enhance customer satisfaction

29.

Why has the need for effective and structured incident handling and response become mandatory for organizations?

a)

Due to a decrease in business data

b)

Due to a rapid increase in threats and incidents

c)

Due to a decline in technology use

d)

Due to a reduction in financial losses

30.

What can incidents compromise, leading to heavy losses?

a)

Employee morale

b)

Crucial business data

c)

Marketing strategies

d)

Customer feedback

31.

What is the first step in the IH&R Process Flow?

a)

Notification

b)

Incident Recording

c)

Preparation for IH&R

d)

Containment

32.

In the IH&R Process Flow, what happens if an incident is not classified as a security incident?

a)

IH&R Team Assigned

b)

Incident Recording

c)

Notification

d)

Not Classified as Security Incident

33.

Which department is involved in the Evidence Gathering and Forensic Analysis step?

a)

IT Support

b)

Management and Other Depts.

c)

Forensics Dept.

d)

Incident Disclosure

34.

What is the final step in the Post-Incident Activities?

a)

Recovery

b)

Incident Documentation

c)

Close Incident

d)

Review and Revise Policies

35.

What is the first step in the preparation for incident handling and response?

a)

Implement IR Plan

b)

Define IR Vision and Mission

c)

Evaluate Current IR Processes

d)

Obtain Management Approval and Funding

36.

Which of the following is NOT involved in the preparation phase for incident handling and response?

a)

Defining the mission, vision, and scope

b)

Implementing the IR Plan

c)

Gathering systems, hardware, and software tools

d)

Creating a plan for smooth communication

37.

What is required to prioritize assets and services during the preparation phase?

a)

Obtain Management Approval and Funding

b)

Define Incident Response Criteria

c)

Create IRT and Organize Resources

d)

Gather systems, hardware, and software tools

38.

What is one of the primary purposes of an Incident Response (IR) plan?

a)

To address the mission and vision statements

b)

To increase sales revenue

c)

To improve customer satisfaction

d)

To develop new products

39.

Which of the following is a goal of an IR plan?

a)

To meet the goals of incident response initiative

b)

To expand the marketing team

c)

To launch a new advertising campaign

d)

To reduce employee turnover

40.

What should an IR plan include to achieve its objectives?

a)

Strategies to achieve set goals and timelines

b)

Plans to increase market share

c)

Methods to reduce production costs

d)

Techniques to enhance customer loyalty

41.

How does an IR plan add value to an organization?

a)

By adding value to other organizational processes

b)

By increasing the number of employees

c)

By reducing the number of meetings

d)

By cutting down on office supplies

42.

What is the purpose of maintaining sufficient overall staff in IH&R training?

a)

To reduce costs

b)

To ensure team members have uninterrupted work time

c)

To increase competition

d)

To limit resources

43.

What should be provided to the team to enhance their technical knowledge?

a)

Financial incentives

b)

Appropriate technical references

c)

Vacation time

d)

Marketing materials

44.

What is the goal of rotating team members through incident response tasks?

a)

To increase salaries

b)

To build confidence in various roles

c)

To reduce team size

d)

To limit communication

45.

What is the focus of developing a mentoring program for senior technical staff?

a)

To train less experienced staff regarding the incident handling process

b)

To increase paperwork

c)

To limit team interaction

d)

To reduce training time

46.

What is the purpose of conducting training and incident handling mock drills?

a)

To confuse the team

b)

To make the teams familiar with the process

c)

To reduce team morale

d)

To limit team growth

47.

What is the first step when an incident occurs according to the flowchart?

a)

Close the incident report

b)

End users call the help desk

c)

IT department detects security alerts

d)

IH&R team analyzes the incident

48.

If an incident requires a response and was closed previously, what is the next step?

a)

Close the incident report

b)

Reopen previously closed incident

c)

Record/update incident record

d)

Assign IR team

49.

What happens if an incident does not require a response?

a)

Close the incident report

b)

Reopen previously closed incident

c)

Record/update incident record

d)

Assign IR team

50.

What is the purpose of incident analysis and validation?

a)

To classify incidents based on severity

b)

To determine affected resources and impact on the business

c)

To prioritize incidents based on technical impact

d)

To develop new security protocols

51.

Which factors are considered in incident classification?

a)

Business profits and losses

b)

Employee performance and satisfaction

c)

Severity, affected resources, and attack methodology

d)

Customer feedback and reviews

52.

What does incident prioritization determine?

a)

The order of responding to security incidents

b)

The cost of security measures

c)

The number of incidents per month

d)

The effectiveness of security training

53.

What is the purpose of communicating an incident to stakeholders?

a)

To increase the complexity of the incident

b)

To reduce the impact by facilitating better coordination

c)

To delay the response time

d)

To avoid involving external agencies

54.

Who should be notified first according to the notification process?

a)

External agencies

b)

The management

c)

The public

d)

Internal staff only

55.

What is the primary goal of incident containment?

a)

To prevent future incidents

b)

To control the effect of the incident immediately after its occurrence

c)

To identify the cause of the incident

d)

To punish those responsible for the incident

56.

At what phase are evidence of the incident collected and sent to the forensics department?

a)

During the initial response

b)

During incident containment

c)

After the incident is resolved

d)

Before the incident occurs

57.

What should be done to ensure security when dealing with compromised code?

a)

Ignore the code and continue operations

b)

Maintain caution

c)

Delete the code immediately

d)

Share the code with others

58.

What is a recommended action for data during an incident?

a)

Delete all data

b)

Create forensic backups to appropriate media

c)

Share data with unauthorized users

d)

Ignore data security

59.

Where should data be stored to ensure safety during an incident?

a)

In a public folder

b)

On a personal device

c)

In a safe location

d)

On a shared network

60.

What should be done with system logs and router logs during an incident?

a)

Delete them immediately

b)

Ignore them

c)

Acquire and review them

d)

Share them publicly

61.

What should administrators and system owners be informed about during a security incident?

a)

The latest information on the security incident

b)

Irrelevant company news

c)

Personal opinions

d)

Unrelated technical updates

62.

What is a crucial step regarding passwords during an incident?

a)

Keep the same passwords

b)

Change all necessary passwords and implement a strong password policy

c)

Share passwords with others

d)

Use simple passwords for convenience

63.

What should be done to ensure proper documentation during an incident?

a)

Avoid creating documents

b)

Create documents and maintain records for every action

c)

Only document major actions

d)

Document actions after the incident is resolved

64.

What is the first step in the evidence gathering and forensic analysis process?

a)

Analyze the Evidence

b)

Collect Evidence

c)

Create a Forensic Investigation Report

d)

Close the Investigation

65.

Why is it important to create a chain of custody document during evidence gathering?

a)

To ensure evidence is not lost

b)

To track who has handled the evidence

c)

To speed up the investigation process

d)

To avoid involving law enforcement

66.

What can organizations do with the evidence collected during the incident response process?

a)

Ignore it

b)

Use it to prosecute attackers

c)

Discard it after analysis

d)

Share it publicly

67.

When is law enforcement required in the forensic analysis process?

a)

When the perpetrator is not identified

b)

When external investigation is not required

c)

When the perpetrator is identified

d)

When the investigation is closed

68.

What is the primary goal of the eradication phase in incident handling and response?

a)

To escalate the problem

b)

To determine the cause of the incident

c)

To remove or eliminate the root cause of the incident

d)

To start recovery processes

69.

Which of the following is a possible countermeasure during the eradication phase?

a)

Install outdated software

b)

Disable necessary services

c)

Update antivirus software

d)

Ignore security audits

70.

What is the first step in the recovery process after an incident?

a)

Restart Services and Processes

b)

Recover Data from Backup

c)

Eliminate the Cause of the Incident

d)

Check if Data is Lost

71.

What does the IH&R team do after eliminating the cause of the incident?

a)

Shut down all systems

b)

Restore affected systems, services, resources, and data

c)

Ignore the incident

d)

Create a new backup

72.

What is the primary purpose of post-incident activities according to Step 9?

a)

To celebrate the resolution of the incident

b)

To improve the response against future attacks

c)

To ignore the incident and move on

d)

To document the incident for legal purposes

73.

How do post-incident activities help responders according to the document?

a)

By providing entertainment

b)

By assessing lags in security posture, settings, and configurations

c)

By reducing the number of team members

d)

By increasing the budget for security

74.

What is one of the outcomes of performing post-incident activities?

a)

Ignoring security policies

b)

Suggesting measures to harden security

c)

Reducing the effectiveness of response processes

d)

Increasing the number of incidents