wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Incident Response Quiz

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

What is incident response?

a)

A way to stop all cyberattacks permanently

b)

A criminal investigation process

c)

A method used only after physical theft

d)

A structured approach to managing the aftermath of a cyberattack

2.

Why is effective incident response important?

a)

It improves company branding

b)

It increases staff productivity

c)

It guarantees attacks will never happen

d)

It reduces financial and operational damage

3.

What is the first phase of the incident response lifecycle?

a)

Containment

b)

Recovery

c)

Eradication

d)

Preparation

4.

Which phase focuses on detecting that an incident has occurred?

a)

Recovery

b)

Lessons Learned

c)

Preparation

d)

Identification & Detection

5.

Which technology helps detect unusual or malicious activity?

a)

Power Supply Systems

b)

Backup Servers

c)

Employee Handbooks

d)

Intrusion Detection Systems (IDS)

6.

What is the main purpose of short-term containment?

a)

Document lessons learned

b)

Fully restore systems

c)

Rebuild the network architecture

d)

Stop the attack from spreading immediately

7.

What is the goal of long-term containment?

a)

Avoid reporting the incident

b)

Shut down all digital operations

c)

Fire the IT staff

d)

Maintain business operations while preparing recovery

8.

What occurs during the eradication phase?

a)

Write public statements

b)

Notify customers first

c)

Install new hardware

d)

Remove malware and attacker access

9.

What happens in the recovery phase?

a)

Identifying the original attack vector

b)

Planning training sessions

c)

Shutting all systems down

d)

Restoring systems from clean backups

10.

What happens during lessons learned?

a)

The network is rebuilt

b)

Law enforcement automatically gets involved

c)

The breach is permanently erased

d)

The incident is reviewed to improve future response

11.

Who leads the incident response effort?

a)

Marketing director

b)

Chief Financial Officer

c)

Junior analyst

d)

Incident Response Manager

12.

Who investigates and analyses technical aspects of the attack?

a)

Communications manager

b)

Human resources

c)

Legal department

d)

Security Analysts

13.

Who manages public and internal messaging during an incident?

a)

System administrators

b)

Cyber criminals

c)

Customers

d)

Communications / PR staff

14.

Under GDPR, when must a breach be reported to the ICO?

a)

Within 7 days

b)

Immediately

c)

Only if customers complain

d)

Within 72 hours

15.

What is a common issue that leads to late breach detection?

a)

Overstaffing

b)

Too many firewalls

c)

Excessive monitoring

d)

Lack of 24/7 threat monitoring

16.

What major question is asked during post-incident review?

a)

Who should be fired?

b)

Which employee is to blame?

c)

Whether the company should delete logs

d)

What improvements can be made to prevent future incidents?

17.

Which UK law deals with unauthorised access to computer systems?

a)

Freedom of Information Act

b)

Online Safety Act

c)

Communications Act

d)

Computer Misuse Act 1990

18.

What is a requirement under Data Protection Act / GDPR?

a)

Never store customer data

b)

Delete all security logs immediately

c)

Never communicate breaches

d)

Protect personal data and report breaches

19.

Which regulation applies to essential services such as energy and healthcare?

a)

Highway Code

b)

Copyright Law

c)

Export Control Regulations

d)

Network and Information Systems (NIS) Regulations

20.

What is a key role of forensic specialists during incident response?

a)

Write marketing materials

b)

Approve business budgets

c)

Install office equipment

d)

Analyse evidence to understand the attack