Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Incident Response and Security Quiz 3

Total questions: 19

Worksheet time: 10mins

Name
Class
Date
1.

The (a)   of an organization defines the roles and responsibilities for incident response for the CSIRT and others who will be mobilized in the activation of the plan.

2.

Organizing the incident response planning process begins with staffing the disaster recovery committee.

a)

True

b)

False

3.

The committees of the CPMT follow a set of general stages to develop their subordinate plans. In the case of incident planning, the first stage is to ____.

a)

integrate the BIA

b)

form the IR planning committee

c)

identify preventive controls

d)

develop the IR planning policy

4.

The responsibility for creating an organization’s IR plan often falls to the ____.

a)

project manager

b)

forensic expert

c)

database administrator

d)

chief information security officer

5.

E-mail spoofing attacks require an immediate response, typically no more than 30 minutes to one hour.

a)

True

b)

False

6.

General users require training on the technical details of how to do their jobs securely, including good security practices, ____ management, specialized access controls, and violation reporting.

a)

war gaming

b)

“before action”

c)

organization

d)

password

7.

A recommended practice for the implementation of the physical IR plan document is to organize the contents so that the first page contains the ____ actions.

a)

“before attack”

b)

training

c)

testing

d)

“during attack”

8.

One of the primary responsibilities of the IRP team is to ensure that the ____ is prepared to respond to each incident it may face.

a)

Semtex

b)

IR plan

c)

CSIRT

d)

Catalyst

9.

A(n) ____ is a detailed examination of the events that occurred, from first detection of an incident to final recovery.

a)

after-action review

b)

reactive review

c)

proactive review

d)

audit review

10.

The Southeast Collegiate Cyber Defense Competition is unique in that it focuses on the operational aspect of managing and protecting an existing network infrastructure. Unlike “capture-the-flag ” exercises, this competition is exclusively a real-world ____ competition.

a)

defensive

b)

end-user training

c)

offensive

d)

hacking

11.

A single trainer works with multiple trainees in a formal setting

a)

After-action review

b)

Distance learning

c)

Formal class

d)

Self-paced training

12.

Can serve as a training case for future staff

a)

Incident log

b)

After-action review

c)

Full-interruption test

d)

Risk assessment

13.

Defines roles and responsibilities for information security

a)

Disaster recovery plan

b)

Organization chart

c)

Business continuity plan

d)

IR policy

14.

Too risky for most businesses

a)

Distance learning

b)

Full-interruption testing

c)

Tabletop exercise

d)

Simulation drill

15.

Trainees receive a seminar presentation at their computers

a)

Formal class

b)

Distance learning

c)

Self-paced course

d)

On-site training

16.

A source of information for developing IR policy

a)

Website logs

b)

Risk matrix

c)

Organization charts

d)

Firewall reports

17.

An online resource for IR

a)

CERT Coordination Center

b)

Wikipedia

c)

Company intranet

d)

Cybersecurity helpdesk

18.

A review of an unusual pattern of entries in a system log

a)

Full audit

b)

Signature scan

c)

Trigger

d)

Alert notice

19.

Usually activated when an incident causes minimal damage with little or no disruption to business operations

a)

Contingency plan

b)

BIA

c)

IR plan

d)

DRP