Skip to content

Report and respond to security incidents Questions

Practice questions for Report and respond to security incidents topic in Microsoft Certified: Cybersecurity Business Professional. 26 questions covering this domain.

26 questions8 easy12 medium6 hard
Q1
medium

An employee clicked a suspicious link and now believes a device may be compromised. What should the employee do first?

Q2
medium

Which situation most clearly requires escalation rather than only routine incident logging?

Q3
easy

Which piece of information belongs in a basic security incident report?

Q4
easy

Which situation should be reported as a security incident?

Q5
hard

A sales employee loses a tablet that syncs customer files and email. What is the best response?

Q6
medium

If an organization provides a help desk, a dedicated security email address, and an incident form, how should an employee choose where to report a phi...

Q7
medium

Why is it still useful to document false positives after an investigation?

Q8
easy

Which event should an employee report even if no damage has been confirmed yet?

Q9
medium

What information should be included when reporting a lost company laptop or phone?

Q10
hard

A shared folder suddenly fills with encrypted files and ransom notes. What is the best immediate response?

Q11
easy

Which is an example of an approved channel an organization might provide for incident reporting?

Q12
hard

An employee accidentally emails a customer list to an unauthorized external recipient. When is escalation required?

Q13
medium

Which details are most useful when reporting a phishing email?

Q14
medium

Why should a user stop sharing data immediately after a suspected breach is discovered?

Q15
medium

When sensitive data exposure is suspected, who may need to become involved according to escalation procedures?

Q16
medium

A suspicious text message asks a user to sign in through an unfamiliar link. Which details would be most useful in the report?

Q17
easy

Which event should be reported right away as a possible security issue?

Q18
hard

A user sees possible malware symptoms but assumes it is probably a false positive and worries about overreacting. What is the best response?

Q19
easy

Which detail should be included in a security report when relevant?

Q20
medium

A user realizes sensitive data was sent to the wrong recipient. What is the right first reaction?

Sign in to see all 26 questions

Create a free account to browse all questions — completely free during our launch phase.