Incident Response Technician Level II Exam
Questions and Correct Answers Verified
Answers) Plus Rationales 2026 Q&A | Instant
Download Pdf
1. What is the primary goal of incident response?
A. Eliminate all system vulnerabilities
B. Restore normal operations quickly
C. Identify attackers publicly
D. Increase system complexity
Answer: B
Rationale: The main objective is to contain damage and restore
operations as quickly and safely as possible.
2. Which phase follows detection in the incident response lifecycle?
A. Recovery
B. Eradication
C. Containment
,D. Preparation
Answer: C
Rationale: After detection, the next step is to contain the incident to
prevent further damage.
3. What is a common indicator of compromise (IOC)?
A. Updated antivirus software
B. Unusual outbound network traffic
C. Regular backups
D. Strong passwords
Answer: B
Rationale: Unexpected outbound traffic often signals data exfiltration or
malware activity.
4. Which tool is commonly used for log analysis?
A. Wireshark
B. Splunk
C. Metasploit
D. Nmap
,Answer: B
Rationale: Splunk is widely used for indexing and analyzing log data.
5. What is the purpose of a forensic image?
A. Improve system speed
B. Backup user data
C. Preserve evidence integrity
D. Remove malware
Answer: C
Rationale: Forensic imaging ensures evidence is preserved without
alteration.
6. What does SIEM stand for?
A. Security Incident Event Management
B. System Integrity Event Monitor
C. Security Information and Event Management
D. Secure Information Encryption Model
Answer: C
Rationale: SIEM systems aggregate and analyze security data from
multiple sources.
, 7. What is the first step in evidence handling?
A. Analysis
B. Collection
C. Documentation
D. Destruction
Answer: B
Rationale: Evidence must first be collected before it can be analyzed.
8. Which type of malware spreads without user interaction?
A. Trojan
B. Worm
C. Virus
D. Spyware
Answer: B
Rationale: Worms self-propagate across networks.
9. What is containment designed to do?
A. Identify vulnerabilities
B. Limit damage
Questions and Correct Answers Verified
Answers) Plus Rationales 2026 Q&A | Instant
Download Pdf
1. What is the primary goal of incident response?
A. Eliminate all system vulnerabilities
B. Restore normal operations quickly
C. Identify attackers publicly
D. Increase system complexity
Answer: B
Rationale: The main objective is to contain damage and restore
operations as quickly and safely as possible.
2. Which phase follows detection in the incident response lifecycle?
A. Recovery
B. Eradication
C. Containment
,D. Preparation
Answer: C
Rationale: After detection, the next step is to contain the incident to
prevent further damage.
3. What is a common indicator of compromise (IOC)?
A. Updated antivirus software
B. Unusual outbound network traffic
C. Regular backups
D. Strong passwords
Answer: B
Rationale: Unexpected outbound traffic often signals data exfiltration or
malware activity.
4. Which tool is commonly used for log analysis?
A. Wireshark
B. Splunk
C. Metasploit
D. Nmap
,Answer: B
Rationale: Splunk is widely used for indexing and analyzing log data.
5. What is the purpose of a forensic image?
A. Improve system speed
B. Backup user data
C. Preserve evidence integrity
D. Remove malware
Answer: C
Rationale: Forensic imaging ensures evidence is preserved without
alteration.
6. What does SIEM stand for?
A. Security Incident Event Management
B. System Integrity Event Monitor
C. Security Information and Event Management
D. Secure Information Encryption Model
Answer: C
Rationale: SIEM systems aggregate and analyze security data from
multiple sources.
, 7. What is the first step in evidence handling?
A. Analysis
B. Collection
C. Documentation
D. Destruction
Answer: B
Rationale: Evidence must first be collected before it can be analyzed.
8. Which type of malware spreads without user interaction?
A. Trojan
B. Worm
C. Virus
D. Spyware
Answer: B
Rationale: Worms self-propagate across networks.
9. What is containment designed to do?
A. Identify vulnerabilities
B. Limit damage