wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Incident Management Training

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Which of the following best describes “Incident Management” in a banking environment?

a)

A set of processes for detecting and preventing cybercrime.

b)

The structured approach to identifying, managing, and resolving service disruptions.

c)

The process of conducting quarterly IT audits.

d)

A security awareness program for employees.

2.

Which term refers to the ability to absorb, adapt, and recover from disruptions while maintaining essential operations?

a)

Incident Handling

b)

Cybersecurity

c)

Resilience

d)

Disaster Testing

3.

In the Incident Management Lifecycle, which phase involves assigning severity and urgency to incidents?

a)

 Identification

b)

Prioritization

c)

Closure

d)

Logging

4.

What is the main objective of the “Post-Incident Review” (PIR)?

a)

To punish the team responsible for the incident.

b)

To document lessons learned and improve processes.

c)

To report incidents to law enforcement.

d)

To restore services after a disruption.

5.

Which of these is a key metric for measuring resilience in incident management?

a)

RPO (Recovery Point Objective)

b)

MTTR (Mean Time to Respond/Recover)

c)

CapEx ratio

d)

ROI (Return on Investment)

6.

In the context of First Response, who is typically the first responder in a bank’s IT environment?

a)

CEO

b)

SOC analyst or IT helpdesk staff

c)

Branch manager

d)

Internal audit officer

7.

Which of the following is a “Do” for a first responder?

a)

Delete suspicious files immediately.

b)

Share incident details with a friend for advice.

c)

Preserve evidence for investigation.

d)

Wait until the next day to escalate.

8.

Which of the following is a “Don’t” for a first responder?

a)

Isolate affected systems.

b)

Document actions taken.

c)

Escalate promptly.

d)

Attempt unapproved fixes that may destroy evidence.

9.

In incident detection, which tool category provides centralized visibility of security events?

a)

SIEM

b)

CRM

c)

ERP

d)

CMS

10.

Which statement best describes the relationship between Incident Management and Incident Response?

a)

Incident Response is broader than Incident Management.

b)

Incident Management is a subset of Incident Response.

c)

Incident Response is a subset of Incident Management.

d)

They are completely unrelated.

11.

During an incident, the SOC receives alerts from multiple systems showing unusual outbound traffic. The first responder isolates the affected segment but fails to capture volatile memory before shutdown. Which aspect of resilience was most impacted?

a)

Containment effectiveness

b)

Evidence preservation

c)

Recovery speed

d)

SLA compliance

12.

In a high-severity incident, a banking core application goes down. The incident management team is following the lifecycle process. At which point should they engage the Post-Incident Review (PIR) process?

a)

Immediately after the first responder isolates the issue

b)

Only after service restoration is confirmed

c)

When customer complaints are received

d)

As soon as the incident is logged

13.

The bank’s incident log shows several critical incidents being escalated late because SOC analysts waited for “full confirmation.” Which resilience principle is being violated?

a)

Minimizing Mean Time to Detect (MTTD)

b)

Avoiding false positives

c)

Categorization accuracy

d)

SLA alignment

14.

During a ransomware attack, the bank’s DRP (Disaster Recovery Plan) is invoked. The recovery site is operational within the RTO, but some customer transaction logs are missing. Which metric was likely not met?

a)

MTTR

b)

 RPO

c)

MTTD

d)

 SLA

15.

In incident management, why might automating certain first response tasks (e.g., isolating infected endpoints via SOAR) actually improve resilience?

a)

It allows human responders to focus on strategic decisions.

b)

It removes the need for categorization.

c)

It ensures all incidents are escalated directly to senior management.

d)

It eliminates the need for logging low-severity incidents.

16.

A phishing email compromises a senior bank executive’s credentials. The first responder follows the playbook and resets the account but fails to notify compliance within the CBN’s stipulated window. Which risk is now introduced?

a)

Regulatory non-compliance

b)

Service downtime

c)

Data integrity failure

d)

SLA breach

17.

The SOC team detects abnormal fund transfer patterns at 2:00 AM. Logs indicate the issue started at 1:40 AM, but the alert system only triggered at 1:59 AM. Which control improvement would most directly reduce the impact of this type of incident?

a)

Lowering detection thresholds in SIEM

b)

Increasing backup frequency

c)

Updating escalation flowcharts

d)

Enhancing RPO in the DRP

18.

During an incident, the IT operations team restores service without informing the forensics team, who were still gathering evidence. Which resilience factor has been undermined?

a)

Containment speed

b)

Post-incident review accuracy

c)

SLA compliance

d)

Recovery time

19.

While handling a DDoS attack, the incident manager prioritizes service restoration for the bank’s public website but delays internal system recovery. This decision aligns with which resilience principle?

a)

Impact-based prioritization

b)

Equal resource allocation

c)

Avoiding false positives

d)

SLA standardization

20.

A critical incident occurs in the bank’s core payment switch. The team follows escalation protocols, but the delay in resolving the issue is traced to outdated contact information for the vendor in the incident response plan. Which aspect of resilience planning failed?

a)

Keeping incident management documentation current

b)

Ensuring automation readiness

c)

Categorizing incidents correctly

d)

Training first responders on technical containment