NEW
Font size
WorksheetsIncident Management Training
Total questions: 20
Worksheet time: 10mins
Which of the following best describes “Incident Management” in a banking environment?
A set of processes for detecting and preventing cybercrime.
The structured approach to identifying, managing, and resolving service disruptions.
The process of conducting quarterly IT audits.
A security awareness program for employees.
Which term refers to the ability to absorb, adapt, and recover from disruptions while maintaining essential operations?
Incident Handling
Cybersecurity
Resilience
Disaster Testing
In the Incident Management Lifecycle, which phase involves assigning severity and urgency to incidents?
Identification
Prioritization
Closure
Logging
What is the main objective of the “Post-Incident Review” (PIR)?
To punish the team responsible for the incident.
To document lessons learned and improve processes.
To report incidents to law enforcement.
To restore services after a disruption.
Which of these is a key metric for measuring resilience in incident management?
RPO (Recovery Point Objective)
MTTR (Mean Time to Respond/Recover)
CapEx ratio
ROI (Return on Investment)
In the context of First Response, who is typically the first responder in a bank’s IT environment?
CEO
SOC analyst or IT helpdesk staff
Branch manager
Internal audit officer
Which of the following is a “Do” for a first responder?
Delete suspicious files immediately.
Share incident details with a friend for advice.
Preserve evidence for investigation.
Wait until the next day to escalate.
Which of the following is a “Don’t” for a first responder?
Isolate affected systems.
Document actions taken.
Escalate promptly.
Attempt unapproved fixes that may destroy evidence.
In incident detection, which tool category provides centralized visibility of security events?
SIEM
CRM
ERP
CMS
Which statement best describes the relationship between Incident Management and Incident Response?
Incident Response is broader than Incident Management.
Incident Management is a subset of Incident Response.
Incident Response is a subset of Incident Management.
They are completely unrelated.
During an incident, the SOC receives alerts from multiple systems showing unusual outbound traffic. The first responder isolates the affected segment but fails to capture volatile memory before shutdown. Which aspect of resilience was most impacted?
Containment effectiveness
Evidence preservation
Recovery speed
SLA compliance
In a high-severity incident, a banking core application goes down. The incident management team is following the lifecycle process. At which point should they engage the Post-Incident Review (PIR) process?
Immediately after the first responder isolates the issue
Only after service restoration is confirmed
When customer complaints are received
As soon as the incident is logged
The bank’s incident log shows several critical incidents being escalated late because SOC analysts waited for “full confirmation.” Which resilience principle is being violated?
Minimizing Mean Time to Detect (MTTD)
Avoiding false positives
Categorization accuracy
SLA alignment
During a ransomware attack, the bank’s DRP (Disaster Recovery Plan) is invoked. The recovery site is operational within the RTO, but some customer transaction logs are missing. Which metric was likely not met?
MTTR
RPO
MTTD
SLA
In incident management, why might automating certain first response tasks (e.g., isolating infected endpoints via SOAR) actually improve resilience?
It allows human responders to focus on strategic decisions.
It removes the need for categorization.
It ensures all incidents are escalated directly to senior management.
It eliminates the need for logging low-severity incidents.
A phishing email compromises a senior bank executive’s credentials. The first responder follows the playbook and resets the account but fails to notify compliance within the CBN’s stipulated window. Which risk is now introduced?
Regulatory non-compliance
Service downtime
Data integrity failure
SLA breach
The SOC team detects abnormal fund transfer patterns at 2:00 AM. Logs indicate the issue started at 1:40 AM, but the alert system only triggered at 1:59 AM. Which control improvement would most directly reduce the impact of this type of incident?
Lowering detection thresholds in SIEM
Increasing backup frequency
Updating escalation flowcharts
Enhancing RPO in the DRP
During an incident, the IT operations team restores service without informing the forensics team, who were still gathering evidence. Which resilience factor has been undermined?
Containment speed
Post-incident review accuracy
SLA compliance
Recovery time
While handling a DDoS attack, the incident manager prioritizes service restoration for the bank’s public website but delays internal system recovery. This decision aligns with which resilience principle?
Impact-based prioritization
Equal resource allocation
Avoiding false positives
SLA standardization
A critical incident occurs in the bank’s core payment switch. The team follows escalation protocols, but the delay in resolving the issue is traced to outdated contact information for the vendor in the incident response plan. Which aspect of resilience planning failed?
Keeping incident management documentation current
Ensuring automation readiness
Categorizing incidents correctly
Training first responders on technical containment
