WorksheetsDay 3- Digital Forensics & Incident Response Bootcamp
Total questions: 5
Worksheet time: 3mins
Name
Class
Date
1.
Behavioral detection focuses on identifying attacker actions rather than relying on known malware signatures
a)
True
b)
False
2.
MITRE ATT&CK only maps initial access techniques and does not include persistence or defense evasion
a)
True
b)
False
3.
Which MITRE ATT&CK tactic involves attackers trying to maintain access even after the system restarts?
a)
Execution
b)
Defense Evasion
c)
Persistence
d)
Exfiltration
4.
Which tool is specifically designed to query endpoints at scale to hunt for indicators and artifacts?
a)
CyberChef
b)
Sigma
c)
Velociraptor
d)
Suricata
5.
What is the purpose of mapping findings in an incident report to MITRE ATT&CK?
a)
To encrypt evidence
b)
To replace SIEM alerts
c)
To connect observed behavior with known attacker techniques
d)
To delete false positives
100 %
