Skip to content

Security Incident Response Management Questions

Practice questions for Security Incident Response Management topic in Certified Implementation Specialist - Security Incident Response. 30 questions covering this domain.

30 questions7 easy16 medium7 hard
Q1
hard

A team decides to directly promote a security incident to a major security incident. What is required?

Q2
hard

What is a key capability of Major Security Incident Management for complex events with many related incidents?

Q3
medium

A responder wants to flag an incident as a possible major security incident without promoting it yet. Which combination is required?

Q4
medium

An admin reviews Process Selection and sees invalid states after changing definitions. What does Process Selection handle in this situation?

Q5
medium

How does the NIST Open process definition differ from NIST Stateful?

Q6
easy

What does the Review state mean in the default NIST Stateful process definition?

Q7
medium

An analyst is ready to close a security incident in the NIST Stateful process. What must be completed first?

Q8
easy

Which value is a valid security incident task state?

Q9
hard

Which capability is available to a user with sn_si.analyst and oc_read in On-Call Scheduling?

Q10
hard

Which combination of actions is supported directly in the Response Tasks section of a security incident?

Q11
medium

A response task has been taken by an owner but work has not started yet. Which task state best fits?

Q12
medium

Which MSIM feature gives investigators shared file access tied to the major incident effort?

Q13
medium

Which option shows the correct default NIST Stateful sequence for a security incident?

Q14
medium

An analyst determines that one incident should be tracked under a major security incident already in progress. Which MSI capability should be used?

Q15
easy

Which statement accurately describes the default NIST Stateful process definition?

Q16
medium

Where do administrators configure handover templates and create shifts for shift handover?

Q17
medium

Before a security incident can move to Closed, what must be completed?

Q18
easy

In the default NIST Stateful process, what does the Review state mean?

Q19
medium

An analyst proposes an incident as a major security incident candidate. What is required and what tag is applied?

Q20
medium

Which statement correctly compares the default NIST process definitions?

Sign in to see all 30 questions

Create a free account to browse all questions — completely free during our launch phase.