Skip to content

Incident Response Management Questions

Practice questions for Incident Response Management topic in CompTIA CySA+. 20 questions covering this domain.

20 questions6 easy8 medium6 hard
Q1
easy

Which phase of the incident response lifecycle involves identifying and limiting the spread of an active attack?

Q2
medium

A security analyst is building an incident response playbook for ransomware events. Which element is most critical to include for business continuity ...

Q3
hard

A large organization experiences a ransomware outbreak affecting 40% of its endpoints. The CISO asks the incident response team lead what the immediat...

Q4
medium

During an incident investigation, a forensic analyst needs to collect volatile data from a compromised Windows server before it is shut down. Which da...

Q5
easy

What does the MITRE ATT&CK framework's 'Kill Chain' concept describe in the context of incident response?

Q6
medium

What is the primary purpose of a root cause analysis (RCA) after a security incident?

Q7
hard

During forensic analysis of a compromised endpoint, an analyst discovers a malicious binary in the Windows Temp directory that was executed by a sched...

Q8
easy

What is the purpose of a tabletop exercise in incident response?

Q9
hard

During a post-incident review following a data breach, the team finds that the attacker used a compromised vendor VPN account for initial access. The ...

Q10
medium

An incident has been detected where an attacker accessed an administrative account using stolen credentials. After containing the incident, what is th...

Q11
easy

What is the purpose of an incident response plan (IRP)?

Q12
hard

A security analyst is performing memory forensics on a compromised endpoint and discovers an injected DLL running in the context of a legitimate Windo...

Q13
medium

An incident response team has successfully contained and eradicated malware from a compromised server. Before returning the server to production, whic...

Q14
hard

During incident response to a confirmed insider threat, legal counsel informs the IR team that evidence may be needed for legal proceedings. Which evi...

Q15
easy

What does the term 'eradication' mean in the context of the incident response lifecycle?

Q16
medium

A security analyst is performing forensic analysis on a potentially compromised system and needs to preserve a bit-for-bit copy of the hard drive. Whi...

Q17
hard

A CISO is reviewing the organization's incident response capability and finds there is no defined criteria for when an analyst should escalate an inci...

Q18
medium

After completing eradication of malware from a compromised server, the incident response team determines the server's OS needs to be rebuilt from scra...

Q19
medium

A security operations center receives a threat intelligence report indicating a specific adversary group is actively targeting organizations in their ...

Q20
easy

What is the Diamond Model of Intrusion Analysis used for?

Sign in to see all 20 questions

Create a free account to browse all questions — completely free during our launch phase.