SOUND THE ALARM: DETECTION AND
RESPONSE/ TEST QUESTIONS MODULE 1
Questions & answers Latest Update 2026.
EST YOUR KNOWLEDGE: THE INCIDENT RESPONSE LIFECYCLE
1. The first phase of the NIST Incident Response Lifecycle is Preparation. What are the
other phases? Select three answers.
T
Detection and Analysis (CORRECT)
Identify
Containment, Eradication, and Recovery (CORRECT)
Post-Incident Activity (CORRECT)
The three other phases of the NIST Incident Response Lifecycle are: Detection and
Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity.
What type of process is the NIST Incident Response Lifecycle?
Cyclical (CORRECT)
Synchronous
Linear
Observable
The NIST Incident Response Lifecycle is a cyclical process. This means that phases in the
lifecycle can be revisited or repeated as incident investigations progress.
,Fill in the blank: An _____ is an observable occurrence on a network, system, or device.
investigation
incident
event (CORRECT)
analysis
An event is an observable occurrence on a network, system, or device. All incidents are
considered events, but not all events are considered incidents.
A security professional investigates an incident. Their goal is to gain information about the
5 W's, which include what happened and why. What are the other W's? Select three
answers.
When the incident took place (CORRECT)
Which type of incident it was
Who triggered the incident (CORRECT)
Where the incident took place (CORRECT)
The other W’s are: who triggered the incident, when the incident took place, and where the
incident took place.
TEST YOUR KNOWLEDGE: INCIDENT RESPONSE OPERATIONS
1. What are the goals of a computer security incident response team (CSIRT)? Select three
answers.
, To prevent future incidents from occurring (CORRECT)
To manage incidents (CORRECT)
To handle the public disclosure of an incident
To provide services and resources for response and recovery (CORRECT)
The goals of CSIRTs are to effectively and efficiently manage incidents, prevent future
incidents from occurring, and provide services and resources for response and recovery.
Which document outlines the procedures to follow after an organization experiences a
ransomware attack?
A contact list
A network diagram
An incident response plan (CORRECT)
A security policy
An incident response plan outlines the procedures to follow after an organization
experiences a ransomware attack.
Fill in the blank: The job of _____ is to investigate alerts and determine whether an
incident has occurred.
incident coordinators
security analysts (CORRECT)
public relations representative
RESPONSE/ TEST QUESTIONS MODULE 1
Questions & answers Latest Update 2026.
EST YOUR KNOWLEDGE: THE INCIDENT RESPONSE LIFECYCLE
1. The first phase of the NIST Incident Response Lifecycle is Preparation. What are the
other phases? Select three answers.
T
Detection and Analysis (CORRECT)
Identify
Containment, Eradication, and Recovery (CORRECT)
Post-Incident Activity (CORRECT)
The three other phases of the NIST Incident Response Lifecycle are: Detection and
Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity.
What type of process is the NIST Incident Response Lifecycle?
Cyclical (CORRECT)
Synchronous
Linear
Observable
The NIST Incident Response Lifecycle is a cyclical process. This means that phases in the
lifecycle can be revisited or repeated as incident investigations progress.
,Fill in the blank: An _____ is an observable occurrence on a network, system, or device.
investigation
incident
event (CORRECT)
analysis
An event is an observable occurrence on a network, system, or device. All incidents are
considered events, but not all events are considered incidents.
A security professional investigates an incident. Their goal is to gain information about the
5 W's, which include what happened and why. What are the other W's? Select three
answers.
When the incident took place (CORRECT)
Which type of incident it was
Who triggered the incident (CORRECT)
Where the incident took place (CORRECT)
The other W’s are: who triggered the incident, when the incident took place, and where the
incident took place.
TEST YOUR KNOWLEDGE: INCIDENT RESPONSE OPERATIONS
1. What are the goals of a computer security incident response team (CSIRT)? Select three
answers.
, To prevent future incidents from occurring (CORRECT)
To manage incidents (CORRECT)
To handle the public disclosure of an incident
To provide services and resources for response and recovery (CORRECT)
The goals of CSIRTs are to effectively and efficiently manage incidents, prevent future
incidents from occurring, and provide services and resources for response and recovery.
Which document outlines the procedures to follow after an organization experiences a
ransomware attack?
A contact list
A network diagram
An incident response plan (CORRECT)
A security policy
An incident response plan outlines the procedures to follow after an organization
experiences a ransomware attack.
Fill in the blank: The job of _____ is to investigate alerts and determine whether an
incident has occurred.
incident coordinators
security analysts (CORRECT)
public relations representative