Skip to content

Security Incident Creation and Threat Intelligence Questions

Practice questions for Security Incident Creation and Threat Intelligence topic in Certified Implementation Specialist - Security Incident Response. 28 questions covering this domain.

28 questions8 easy14 medium6 hard
Q1
medium

A service desk agent is reviewing a Security Request that should become a security incident. Which action supports that conversion?

Q2
medium

An organization wants to avoid creating duplicate security incidents from Incident Management. Which setting should be enabled?

Q3
hard

A security incident was created from network monitoring data ingested through CrowdStrike. Which field identifies CrowdStrike on the incident?

Q4
medium

An analyst runs an IoC lookup request for an observable, but the lookup does not find a security incident observable. What appears in the Finding colu...

Q5
easy

Which item is an example of an observable in Security Incident Response?

Q6
medium

A responder selects a Category on a new security incident and saves the record. What happens because of that Category selection?

Q7
easy

When a security incident is first created, what is its default State?

Q8
medium

A lookup request finds a matching security incident observable. What should the Finding column show in Threat Lookup Results?

Q9
medium

A security team wants Event Management to create incidents without analyst intervention when certain conditions are met. What should they use?

Q10
easy

An incident shows McAfee in the alert ingestion details. Which field is that value most likely populating?

Q11
hard

Which statement about Threat Intelligence data inside a security incident is correct?

Q12
hard

Which set correctly describes the information stored with an observable in SIR?

Q13
easy

If Vulnerability Response is activated, which source can create a security incident directly?

Q14
medium

On a security incident form, what does the Source field identify?

Q15
easy

Which field identifies whether a security incident came from email, a phone call, or network monitoring?

Q16
easy

Immediately after a security incident is created, what is its default State?

Q17
medium

Which set lists the metadata included for an observable?

Q18
medium

What is the effect of enabling the system property sn_si.disable_duplicate_security_incident?

Q19
medium

On the Details tab, an analyst selects a Category and saves the record. What happens?

Q20
medium

A security request should be turned into a security incident. Which action supports that path?

Sign in to see all 28 questions

Create a free account to browse all questions — completely free during our launch phase.