NEW
Font size
WorksheetsIncident Response Quiz
Total questions: 20
Worksheet time: 10mins
What is incident response?
A way to stop all cyberattacks permanently
A criminal investigation process
A method used only after physical theft
A structured approach to managing the aftermath of a cyberattack
Why is effective incident response important?
It improves company branding
It increases staff productivity
It guarantees attacks will never happen
It reduces financial and operational damage
What is the first phase of the incident response lifecycle?
Containment
Recovery
Eradication
Preparation
Which phase focuses on detecting that an incident has occurred?
Recovery
Lessons Learned
Preparation
Identification & Detection
Which technology helps detect unusual or malicious activity?
Power Supply Systems
Backup Servers
Employee Handbooks
Intrusion Detection Systems (IDS)
What is the main purpose of short-term containment?
Document lessons learned
Fully restore systems
Rebuild the network architecture
Stop the attack from spreading immediately
What is the goal of long-term containment?
Avoid reporting the incident
Shut down all digital operations
Fire the IT staff
Maintain business operations while preparing recovery
What occurs during the eradication phase?
Write public statements
Notify customers first
Install new hardware
Remove malware and attacker access
What happens in the recovery phase?
Identifying the original attack vector
Planning training sessions
Shutting all systems down
Restoring systems from clean backups
What happens during lessons learned?
The network is rebuilt
Law enforcement automatically gets involved
The breach is permanently erased
The incident is reviewed to improve future response
Who leads the incident response effort?
Marketing director
Chief Financial Officer
Junior analyst
Incident Response Manager
Who investigates and analyses technical aspects of the attack?
Communications manager
Human resources
Legal department
Security Analysts
Who manages public and internal messaging during an incident?
System administrators
Cyber criminals
Customers
Communications / PR staff
Under GDPR, when must a breach be reported to the ICO?
Within 7 days
Immediately
Only if customers complain
Within 72 hours
What is a common issue that leads to late breach detection?
Overstaffing
Too many firewalls
Excessive monitoring
Lack of 24/7 threat monitoring
What major question is asked during post-incident review?
Who should be fired?
Which employee is to blame?
Whether the company should delete logs
What improvements can be made to prevent future incidents?
Which UK law deals with unauthorised access to computer systems?
Freedom of Information Act
Online Safety Act
Communications Act
Computer Misuse Act 1990
What is a requirement under Data Protection Act / GDPR?
Never store customer data
Delete all security logs immediately
Never communicate breaches
Protect personal data and report breaches
Which regulation applies to essential services such as energy and healthcare?
Highway Code
Copyright Law
Export Control Regulations
Network and Information Systems (NIS) Regulations
What is a key role of forensic specialists during incident response?
Write marketing materials
Approve business budgets
Install office equipment
Analyse evidence to understand the attack
