wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Core Functions-IR TEAM

Total questions: 90

Worksheet time: 2hrs 5mins

Name
Class
Date
1.

CIA, an acronym for cybersecurity, determines when to escalate a cyber event to cyber incident. What does is stand for?

a)

Counter

Intelligence

Agency

b)

Compromise

infiltrate

Access

c)

Confidentiality

Integrity

Availablilty

d)

Corporate

Internal

Access controls

2.

What does WISP stand for?

a)

Wireless Internet Service Provider

b)

Wide Internet Service Protocol

c)

Wiritten information Security plan

d)

Wide Information Service Provider

3.

You have a confirmed CIA incident. Correctly order the Response Plan :

a)

Start Response Log

b)

Initiate IR team communications logging

c)

determine origin, examine all logs with SOC

d)

document all response measures taken

e)

preserve evidence

1)
2)
3)
4)
5)
4.

What are the key security measures in the Protect function of NIST?

a)

Access Control, Awareness and Training, Data Security, Information Protection Processes and Procedures, Maintenance, and Protective Technology

b)

Risk Assessment, Risk Management Strategy, Supply Chain Risk Management

c)

Anomalies and Events, Security Continuous Monitoring, Detection Processes

d)

Response Planning, Communications, Analysis, Mitigation, Improvements

5.

"Ground zero" has been identified and neutralized.

Please order the objectives of Phase 4 "Response" to Cyber Incident

a)

Creating a secured and safe channel to restore external communications

b)

Begin prioritized restoration of mission critical services

c)

Remediation: deploy devices cleared for use. begin cleaning affected devices

d)

Update and complete the Incident Summary Report (ISR)

e)

Complete restoration of network functionality

1)
2)
3)
4)
5)
6.

Match the Log with the Correct Phase of an Incident response

a)

Phase 1

1.

Event Report

b)

Phase 2

2.

Threat Level assessment

c)

Phase 3

3.

Response Log

d)

Phase 4

4.

Restore functionality of Critical System

e)

Phase 5

5.

Post Incident Review Log

7.

Put the content in order as it would be included in a public communication regarding a breach

a)
Incident Description
b)
Affected Data
c)
Actions Taken
d)
Communication and Support
e)
Transparency and Accountability
1)
2)
3)
4)
5)
8.

Where could I find a Business Continuity Plan (BCP)?

a)

In the company's written information security plan

b)

On the company's public website

c)

In a local library

d)

In a personal email

9.

Minimum needed to effectively respond to a Cyber Incident:

​ ​​ ​ ​ (a)   (b)   ​ (c)   (d)   ​ (e)  

Choose from the below words
Prepared Post incident review
Daily IR team meetings
Process Improvement Plan
bi-annual tabletop exercises
Acessible IR Contacts and RACI forms
Prioritized order of Critical Services restoration
"Clean" HW inventory
Accessible WISP
Be able to do everything
10.

Your MDR detects unusual outbound network traffic that could indicate data exfiltration. Organize actions by category

Categorize the following

Utilize Google Investigate tool to review user actions

shutdown firewall ports to destination

identify Destination address

disable user/computer account

confidentiality

Integrity

Availability

Activate full IR team

Alert Security Official

Activate MDR/BOCES security operations teams

Review Logs-MDR/Boces SOC

identify user/computer/data type

Implement Full IR Breach Plan

Alert
Investigate/Mitigate
Event or Incident? Criteria met?
Confirmed CIA breach
11.

The MDR team has confirmed confidential Data has been exfiltrated. What next?

a)

Stop Exfiltration: Partial/complete shutdown of corporate external/internal traffic

b)

SOC teams identify / neutralize source of breach.

c)

implementation of IR restore plans

d)

Security/Public Official notifies stakeholders, and makes official Public announcement

1)
2)
3)
4)
12.

How could I find more information on how the district data network is engineered?

a)

By contacting the district's IT department

b)

In the WISP, section Secure Engineering and Architecture

c)

By attending a district board meeting

d)

By reading the district's annual report

13.

What considerations should be taken when communicating to Stake holders about a cyber incident?

a)

Transparency

b)

Not revealing information that might compromise the investigation

c)

Protection of privacy of those who are directly affected by the data breach

d)

recommendations of legal counsel

14.

An Incident Response plan includes:

​ (a)   ​ (b)   ​ (c)   ​ ​ (d)  

Choose from the below words
Escalation processes
IR team members and contact info
RACI
Media contacts
completed PIP
Report to SED
Restore Order of  Critical Services
15.

The Network Security (NET) section in the WISP includes: (a)  

Choose from the below words
Boundary configurations
Guest networks
Intrusion Detection and prevention
All of the above
16.

An unreported phishing attack compromised employee credentials. The network monitoring system detects unusual activity on the user account. What order should these steps be in?

a)

Inform the Security Offical of unfolding event

b)

Reset: affected user credentials and sign in cookies. Change MFA notification method

c)

determine if CIA breach occurred, update Security Official

1)
2)
3)
17.

Organize Resources by Category

Categorize the following

Syscloud/Google DLP

Firewall

Network appliance

BR/DRAAS

Syscloud Recovery

AD Logs

Pondurance MDR Threat Intelligence SOC

Google Vault

Imaging software

"Clean" Computer reserve

Sentinel One Endpoint

isolate device

Disable user/computer account

Google Investigation Tool

Disable Firewall ports

network monitor logs

Firewall Logs

Umbrella Logs

Disconnect access to external networks

isolate networks

SOC Investigation
Early Detect
Respond (SOC Teams )
Recover
18.

What considerations must be a part of restoration of critical systems after a breach?

(a)   (b)   (c)   (d)  

Choose from the below words
"ground zero" identified to prevent re-infection
creating a separate secure network external comm
having on hand "Known Clean" computers on hand fo
having a document that outlines the order of missi
strenghtening identified weakness
notifying affected parties of the breach
sending non-critical staff home
19.

Prioritize the order of Restoration of District Core Systems

a)

Internal/External communications (servers, network(s), phones)

b)

Access to HR and finance applications

c)

Access to HVAC system

d)

Food and Transportation applications

e)

Security Systems (doors, cameras)

1)
2)
3)
4)
5)
20.
  1. A user reports that their files have disappeared, and they cannot access shared drives. What should the helpdesk do first?

a)

Escalate immediately to the Incidence Response team

b)

Verify if it is a computer or user issue before escalating to IR Team

c)

shut down the affected system

d)

ask if any other users are having the same experience

21.

What doe RACI stand for?

(a)  

Choose from the below words
Responsible Accountable Consulted Informed
Refined Access Control Instructions
Retained account contaiment implementation
Reasonable Access control implementation
22.

Which phase would Legal and/or Insurance be contacted?

a)

Phase 1-Event Reported

b)

Phase 2-Threat assessment

c)

Phase 3 -

Response Log

d)

Phase 4 - Incident Summary Report

23.

(Match the strategy to the correct NIST category.)

a)
  • Documenting critical business services

1.

IDENTIFY

b)
  • Monitoring abnormal network traffic spikes.

2.

DETECT

c)
  • Evaluating strategies to manage fuutre DDOS attacks

3.

RECOVER

d)
  • Blocking malicious IP addresses and rerouting traffic

4.

RESPOND

e)
  • Increasing firewall protections and traffic filtering

5.

PROTECT

24.

What information is found in the Identification and Authentication (IAC) section of the WISP?

a)

data access controls

b)

Corporate employee access management strategies

c)

ID badge picture options

d)

employee break policy

25.

The tech department learns an employee lost a company-issued laptop with sensitive customer data. what do you do?

a)

Report incident to the Security Official

b)

Log the device out of any cloud sessions

remotely disable

stop cloud storage sync

c)

ask where they saw it last, and go look for it

d)

Look on the dark web and report to the FBI

26.

What is a Supply chain document and where can in be found in the WISP

a)

Supply chain is a chain of supplies ordered in past 30 days found under Assets section of the WISP

b)

The Supply Chain document is found in the Incident Response Plan (IRO) it contains all the contacts for 3rd party vendor purchases

c)

The Supply Chain document is found in the Detection Section (DT) it contains all the contacts for party vendors in the area

d)

The Supply Chain document is found in the Recovery Section (RSK) contains all the vaccination records

27.

IDENTIFY: Why is asset management critical in the Identify function of NIST?

a)

The Corporate Balance Sheet

b)

The logistical management of company resources

c)

To identify critical systems that need risk management

d)

Asset management is simply inventory control.

28.

A third-party vendor informs the company of a possible data exposure but provides limited details. What should be the next step?

a)

Gather more information before taking further action

b)

Terminate the contract with the vendor

c)

Contact the Incidence Response team immediatly

d)

Immediately inform all customers

29.

Determining Escalation Paths Scenario: A department reports repeated malware infections on different machines. What should the cybersecurity team do?

a)

Investigate the source of the malware and apply necessary patches to the endpoint protection software

b)

check monitoring logs for any spikes in data exports

c)

isolate the machines until the endpoint software is updated and to recognize the malware

d)

determine and block the source of the malware from being accessed by the network

30.

What does Risk Management (RSK) cover in the WISP

a)

Risk identification

Risk assessments

Risk Ranking

b)

Risk Remediation

31.

The main activities in the Recover function of NIST are:

a)

developing and improving recovery plans

b)

Identifying clear procedures to restore mission critical applications

c)

communicate updates to stakeholders

d)

Monitoring and analyzing threats

32.

Analysis is what phase of an Incident Response? It is the (a)   phase.

Choose from the below words
Identify
Protect
Detect
Response
33.

Where could I find a history of changes made to the network?

a)

Change Management Section (CHG)

b)

Governance (GOV)

c)

Compliance (CPL)

d)

Asset management (AST)

34.

Why have Continuous network monitoring?

(a)   (b)   (c)  

Choose from the below words
Early detection/recording of anomalous activity.
Catch insider threats
useful to identify the "ground zero" patient

see what people are up to

AI is smarter than humans
35.

What does NIST stand for?

a)

National Institute of Standards and Technology

b)

National Information Security Team

c)

Network Information Systems Technology

d)

National Institute of Science and Technology

36.

Multiple system become inaccssible; ransome note appears on HR computers.

Prioritize next steps

Categorize the following

Isolate affected systems

Alert IR Security Official

Get SOC/MDR logs analysis

USE CIA to decide whether to disconnect Internet

First
Second
Third
Fourth
37.

Data Classification and Handling protections in the WISP includes information on​​​ (a)   , and ​​ (b)   , and ​ (c)  

Choose from the below words
Spam managment
type of data stored
data retention information
data encryption methods
email filters
internet filters
38.

Would the WISP include information on Corporate assets: (a)   ?

Choose from the below words
Yes, it would include information o
No, it would not include informatio
39.

An asset is comprised of:

a)

Liabilities and equity

b)

Only cash

c)

Only physical goods

d)

Corporate hardware and software

40.

IDENTIFY: What is the primary purpose of a risk assessment?

a)

To identify vulnerabilites of corporate data systems

b)

To satisfy auditors needs and reduce liability costs

c)

To find out Monica has too much access

d)

To develop a comprehensive response plan

41.

Where would I go to find out what systems we have in place for monitoring our network?

a)

Check the IT department's documentation

b)

Visit the company's website

c)

WISP, Continous Monitoring section

d)

Look in the employee handbook

42.

Identify ways to add additional layers of security

a)

enforcing 14 character complex password

b)

requiring facial recognition

c)

requiring Captcha

d)

notifying a second device at login

43.

What is the primary role of security awareness training in the Protect function?

a)

To test the patience of the Data Privacy Officer

b)

To educate staff to identify, and report social engineering attacks

c)

To educate staff where the Acceptable use policy can be found.

d)

To identify staff who click on everything

44.

Where could I get detailed information on Data Backup systems in place

a)

Data Classification Handling (DCH)

b)

Incident Response Plan (IRP)

c)

Businesss Continuity Plan (BCP)

d)

Configuration Management (CHG)

45.

Real World Reporting: Marriott Hotel Data Breach (2018) - 📌 Incident: After acquiring Starwood Hotels, Marriott discovered a long-running breach in Starwood’s system. Hackers had been exfiltrating guest data for years before Marriott realized the security flaw had been inherited.

where was the failure?

a)

Identify: lack of review of business critical Hardware and software

b)

The purchase price was to high!

c)


Protect: No internal review of the protection plan for business critical applications

d)

Detect: No system in place to monitor sensitive data movement

46.

RECOVER: Why is a business continuity plan important in cybersecurity recovery?

a)

To ensure the organization can continue operations during and after a cyber attack

b)

To increase the company's profit margins

c)

To reduce the number of employees needed in the IT department

d)

To eliminate the need for cybersecurity measures

47.

IDENTIFY: What are the five core functions of the NIST Cybersecurity Framework?

a)

Identify, Protect, Detect, Respond, Recover

b)

Plan, Execute, Monitor, Control, Close

c)

Identify, Project, Deter, React, Recoup

d)

Analyze, Design, Develop, Test, Deploy

48.

Auditors are looking for security polciies for terminated personnel. Where would you direct them?

a)

The board docs website

b)

The Human Resources security section of the WISP

c)

The Asset management section of the WISP

d)

The Risk Management section of the WISP

49.

The purpose of forensic analysis in the response process is to:

a)

Identify the cause of an incident

b)

Improve system performance

c)

Enhance user experience

d)

Increase network speed

50.

The best practice policy for data access is (a)  

Choose from the below words
Most restrictive, permissions grant by request
Least restrictive, based on software
Least privileges needed to do ones job
Access based on trust and education
51.

Why is it important to have a pre-defined communication plan in the Respond function?

a)

To ensure clear and efficient communication during a response

b)

To allow for spontaneous decision-making

c)

To avoid any form of communication

d)

To ensure only one person is responsible for communication

52.

During a cybersecurity class, Abigail and William are discussing the Recovery Phase of Incident Response. They mention that this phase includes:

a)

identify vulnerabilities

b)

update security policies

c)

review and improve response strategies

d)

communications process

53.

(a)   , ​ (b)   and ​ (c)   are all utilized for early detection.

Choose from the below words
intrusion/prevention systems
SIEM
computers
complex passwords
endpoint monitoring
54.

"Detection tools" include:

​ (a)   ​ (b)   ​ (c)  

Choose from the below words
diagnostics
analytical
monitoring
keyloggers
eavesdropping
55.

Which NIST function includes activities related to security awareness?

a)

Identify

b)

Protect

c)

Detect

d)

Respond

56.

What is the difference between Phishing and Social Engineering?

a)

Phishing and Social engineering can be used interchangeably

b)

Social Engineering is a general cybercrime technique and phishing is specialized form of social engineering

c)

Phishing is a general cybercrime technique and Social engineering is a specific form of phishing

d)

Social Engineering is a psychological attack dependent upon email phishing skills

57.

How to Identify a Deep Fake

(Check all that apply)

a)

eyes and eybrows don't track in unison

b)

shadows on opposite sides of the body?

inconsitencies in the background

c)

audio and lips don't quite sync

d)

facial expression don't match emotions

58.

What does "Zero Trust" security mean?

a)

No data can be accessible from the network

b)

no user or device should be trusted until verified

c)

assumes a hacker could be inside your network

d)

requires all data be encrypted at work

59.

What steps do you take to determine if an email is real or a phishing email?

a)

Verify the receivers address is yours

click any links, but dont fill in data right away

b)

Verify the sender address, and any links by hovering over with mouse

Observe time sent. Is it odd?

Content is suspicious and has an alarming sense of urgent action needed

c)

Reply back asking them to answer a question only that peson could answer

d)

Hover over the sender email

click the link just to see where it goes

reply back and ask "really?"

60.

A staff member recieves a questionable voice mail that sounds like the company president is requesting sensitive data. What should they do?

a)

Forward the audio clip to IT to run deep fake detection software on it

b)

That's the boss! Do what is asked. Now!

c)

Contact the president in person or by phone to confirm they sent the message

d)

Just act like they didn't recieve the voice mail.

61.

Is it safe to email a PDF that contains confidential information?

a)

Absolutely

b)

Absolutely not

c)

yes, but only if you type #secure in the subject line

d)

Yes, but only if you type # tar in the subject line

62.

What is the first Category of NIST?

a)

Identify

b)

Protect

c)

Detect

d)

Respond

63.

What lessons should be learned from a cybersecurity incident recovery?

a)

where to implement stronger security measures

b)

where preparation was lacking

c)

where to improve remediation procedures

d)

determine is logging is adequate

64.

n the Target POS Breach (2013) 📌 Incident: Attackers breached Target’s payment system by compromising an HVAC vendor with weak security. This allowed them to install malware on point-of-sale (POS) terminals, stealing 40 million credit card numbers before detection.

Which core Cybersecurity preparations were insufficient?

a)

Identify: Critical system software vulnerabilites

b)

Detect: lack of monitoring devices to detect data being taken off network

c)

Protect: Install sufficient end point protection

d)

Recover: Critical software vulnerabilities

65.

Handling Critical Escalations: Scenario: IT discovers that an active attacker has gained administrator access to key servers. What should be done?

a)

Inform the IR team

b)

disable security groups wth administrator access immediately

c)

Contact MDR and WSWHEBOCE security teams

evaluate if CIA breach occurred

d)

require all users with administrative system access to change passwords immediatly

66.

The Colonial Pipeline Ransomware Attack (2021)

📌 Incident: A ransomware attack on Colonial Pipeline in 2021 disrupted fuel supplies across the U.S. The attackers gained access through a compromised VPN password that lacked multi-factor authentication. Once inside, ransomware encrypted key systems, forcing Colonial Pipeline to halt operations and pay a $4.4 million ransom.
What was the root cause?

a)

Identify:

Poor access control

b)

Protect:

Access authentication methods were inadequate

c)

Protect: Lack of network segmentation

d)

Identify:

Unpatched software vulnerabilities

67.

SolarWinds Supply Chain Attack (2020)

📌 Incident: Attackers compromised the widely used SolarWinds Orion software, injecting malware into updates that were installed by U.S. government agencies and Fortune 500 companies. This sophisticated breach remained undetected for months, allowing attackers deep network access.

What steps could have caught this much earlier

a)

Protect: enable security logging on all network servers

b)

Recover: Weak employee awareness

c)

Identify: Review of third-party applications for security vulnerabilities

d)

Detect: installing a network appliance to monitor for anamolous activity accross the network

68.
a)

District data is completely

inaccessible

b)

you are locked out of your account

c)
Parent did not get school closed notice
d)

The clock on the computer is off

69.

HR finance system flashes a message on employee desktop "unknown access to confidential data"

What happens first?

a)

Alert IR Security Official

b)

verify time and date information was accessed

c)

Report to the FBI

d)

click it and move on

70.

The Equifax Data Breach (2017)

📌Incident: In 2017, Equifax, one of the largest credit reporting agencies, suffered a breach exposing personal data of 147 million Americans. The attackers exploited a known vulnerability in Apache Struts, a web application framework, which Equifax failed to patch. Once inside, hackers exfiltrated sensitive data over several months before being detected.

What was the root cause?

a)

Respond: Equifax was quick to shut down data loss

b)

Detect: Equifax successfully detected all data exfiltrated

c)

Identify:

Equifax failed to assess and manage software vulnerabilities.

d)


Equifax improved its software vulnerability management.

71.

(a)   is typically responsible for publically declaring a cyber incident as an official data breach.

Choose from the below words
Coprorate Security Official
Anyone who see it
The IT guys
The Department head
72.

According to Kevin Mitnick. What is the hardest cybercrime to defend against?

a)

Ransomware

b)

Malware

c)

social engineering

d)

Brute force password attacks

73.

What is the best practice during the Recovery phase of an incident?

a)

Avoid shutting down critical systems at all costs

b)

identify root cause, isolate and eliminate it, patch systems before bringing back on line

c)

Providing new "clean" equipment with out determining the cause of the breach

d)

Re-image everything and open for buisness

74.

Who conducts a cybersecurity risk assessment?

a)

3rd party auditor

b)

IT staff

c)

BOCES

d)

NYSED

75.

In the role of an incident responder, you meticulously recorded every step and choice during a security event. This chronological record is particularly valuable for which component of the incident response report?

a)

Executive summary

b)

Recovery and Review

c)

Scope

d)

Impact

76.

Handling Critical Escalations: Scenario: A data breach affecting customer records is confirmed. What actions should be taken?

a)

Delete all customer records to prevent further issues.

b)


Wait for customer complaints before taking action

c)

Notify affected customers and regulatory bodies immediately.

d)

Ignore the breach and continue operations as usual.

77.

Can multi-factor authentication (MFA) be compromised?

a)

Yes, if the user approves a fraudulent login request on their secondary device

b)

No, MFA is completely secure

c)

Yes, if the user is deceived by a phishing scam and clicks a malicious link

d)

Yes, if an unauthorized person gains access to the secondary authentication device

78.

Which document in the District Doc's Admin identifies which IR team member roles as the scope of an unfolding incident escalates?

a)

RACI: Roles and Responsibilities spreadsheet

b)

Incident Response Team

c)

**Revised** Response Plan

d)

2024 WISP-updated 10-2-24

79.

A breach of Confidentiality is:

(a)  

Choose from the below words
unathorized disclosure of info
alteration of data
disruption of access to data
80.

What is the type of breach that involves the alteration or destruction of data is

(a)  

81.

The entire business office reports they have no access to the online finance system.

If this were a Cybersecurity incident, what principle of data protection has been compromised?

a)

Confidentialtiy

b)

Integrity

c)

Availability

d)

The Hosting site is down for repair

82.

IT detects unusual login activity from a staff account during off hours. What if anything should be done next?

a)

Disable the staff account

b)

contact staff member as soon as possible for confirmation

c)

Imediately alert IR team

d)

Contact Pondurance MDR for more log analysis

83.

District shuts down internet due to Ransomware attack. Outlets start reporting on the attack.

Who is responsible for communications and what information is shared publicly?

a)

Security Official

b)

Director of Technology

c)

Pubic Information Officer

d)

Lega counsel

84.

Which if any communication templates should be created and stored before a confirmed cyber incident occurs?

a)

Public

b)

Staff

c)

Students

d)

Parents

85.

Who should be part of generating prepared communication statements to Stake hol​ders?​ ​ (a)   ​ (b)  

​ (c)  

Choose from the below words
Security Official
Legal Counsel
Public Information Officer
Affected Staff member
MDR Staff
Incident Handler
Tech Support
Facilities
86.

Attackers demand payment to prevent further data leaks. What do you do?

(a)   (b)   (c)  

Choose from the below words
Consult with FBI
Consult with Legal Counsel
Consult with Cybersecurity liability insurance Car

Consult with Public Information Officer

87.

In the RACI Roles and Responsibilities spreadsheet, what does the R refer to?

a)

Recovery

b)

Responsible

c)

Review

d)

Retain

88.

In the RACI Roles and Responsibilities spreadsheet what does the C stand for?

(a)  

89.

In the RACI Roles and Responsibilities spreadsheet what does the I stand for? (a)  

Choose from the below words
Informed
Interview
Interpret
Investigate
90.

In the RACI Roles and Responsibilities spreadsheet what does the A stand for?

a)

Accountable

b)

Action needed

c)

Assess

d)

Activate