Incident Response Technician Level II
Certification Questions And Correct
Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant Download
Pdf
1. What is the primary goal of incident response?
• A. Prevent all attacks
• B. Eliminate users
• C. Minimize damage and recover quickly
• D. Increase system downtime
Rationale: The main objective of incident response is to limit the impact of a
security incident and restore normal operations as efficiently as possible.
2. Which phase follows identification in the incident response lifecycle?
• A. Preparation
• B. Containment
• C. Recovery
• D. Lessons learned
Rationale: After identifying an incident, containment is performed immediately to
stop its spread and prevent further damage to systems and data.
,3. What tool is commonly used to capture network traffic?
• A. Antivirus
• B. SIEM
• C. Packet sniffer
• D. Firewall
Rationale: Packet sniffers like Wireshark capture and analyze network packets
traversing a network, making them essential for network traffic analysis during
incident response.
4. What does SIEM stand for?
• A. System Internal Event Monitor
• B. Security Incident Email Manager
• C. Security Information and Event Management
• D. Secure Internal Encryption Module
Rationale: SIEM aggregates and analyzes security data from multiple sources in real
time, providing centralized visibility into security events.
5. Which type of attack floods a network with traffic to overwhelm resources?
• A. Phishing
• B. Malware
• C. DDoS
• D. Spoofing
,Rationale: Distributed Denial of Service (DDoS) attacks overwhelm systems with
massive volumes of traffic, rendering services unavailable to legitimate users.
6. What is the purpose of creating a forensic image?
• A. Backup storage
• B. Preserve evidence integrity
• C. Speed up systems
• D. Encrypt files
Rationale: Forensic imaging ensures that data is preserved exactly as it existed at
the time of acquisition, without alteration, to maintain evidentiary integrity.
7. Which protocol is commonly used for secure remote access?
• A. FTP
• B. HTTP
• C. SSH
• D. Telnet
Rationale: SSH (Secure Shell) encrypts remote communication securely, protecting
credentials and data from interception during remote administrative access.
8. What is an IOC in cybersecurity?
• A. Internal Operation Code
• B. Indicator of Compromise
• C. Internet Operating Console
• D. Integrated Output Channel
, Rationale: Indicators of Compromise (IOCs) are forensic artifacts or pieces of
evidence that suggest a system has been compromised or is under attack.
9. What is data exfiltration?
• A. Internal Operation Code verification
• B. Data backup creation
• C. Unauthorized data transfer
• D. Data deletion
Rationale: Exfiltration involves the unauthorized transfer of data from an
organization's systems to an external destination, typically by an attacker.
10. Which tool correlates logs from multiple sources to identify security incidents?
• A. IDS
• B. Firewall
• C. SIEM
• D. VPN
Rationale: SIEM platforms aggregate and correlate logs from diverse sources,
enabling security teams to identify patterns and detect potential incidents.
11. What is a zero-day vulnerability?
• A. Patched flaw
• B. Known exploit
• C. Unknown vulnerability
• D. Expired certificate
Certification Questions And Correct
Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant Download
1. What is the primary goal of incident response?
• A. Prevent all attacks
• B. Eliminate users
• C. Minimize damage and recover quickly
• D. Increase system downtime
Rationale: The main objective of incident response is to limit the impact of a
security incident and restore normal operations as efficiently as possible.
2. Which phase follows identification in the incident response lifecycle?
• A. Preparation
• B. Containment
• C. Recovery
• D. Lessons learned
Rationale: After identifying an incident, containment is performed immediately to
stop its spread and prevent further damage to systems and data.
,3. What tool is commonly used to capture network traffic?
• A. Antivirus
• B. SIEM
• C. Packet sniffer
• D. Firewall
Rationale: Packet sniffers like Wireshark capture and analyze network packets
traversing a network, making them essential for network traffic analysis during
incident response.
4. What does SIEM stand for?
• A. System Internal Event Monitor
• B. Security Incident Email Manager
• C. Security Information and Event Management
• D. Secure Internal Encryption Module
Rationale: SIEM aggregates and analyzes security data from multiple sources in real
time, providing centralized visibility into security events.
5. Which type of attack floods a network with traffic to overwhelm resources?
• A. Phishing
• B. Malware
• C. DDoS
• D. Spoofing
,Rationale: Distributed Denial of Service (DDoS) attacks overwhelm systems with
massive volumes of traffic, rendering services unavailable to legitimate users.
6. What is the purpose of creating a forensic image?
• A. Backup storage
• B. Preserve evidence integrity
• C. Speed up systems
• D. Encrypt files
Rationale: Forensic imaging ensures that data is preserved exactly as it existed at
the time of acquisition, without alteration, to maintain evidentiary integrity.
7. Which protocol is commonly used for secure remote access?
• A. FTP
• B. HTTP
• C. SSH
• D. Telnet
Rationale: SSH (Secure Shell) encrypts remote communication securely, protecting
credentials and data from interception during remote administrative access.
8. What is an IOC in cybersecurity?
• A. Internal Operation Code
• B. Indicator of Compromise
• C. Internet Operating Console
• D. Integrated Output Channel
, Rationale: Indicators of Compromise (IOCs) are forensic artifacts or pieces of
evidence that suggest a system has been compromised or is under attack.
9. What is data exfiltration?
• A. Internal Operation Code verification
• B. Data backup creation
• C. Unauthorized data transfer
• D. Data deletion
Rationale: Exfiltration involves the unauthorized transfer of data from an
organization's systems to an external destination, typically by an attacker.
10. Which tool correlates logs from multiple sources to identify security incidents?
• A. IDS
• B. Firewall
• C. SIEM
• D. VPN
Rationale: SIEM platforms aggregate and correlate logs from diverse sources,
enabling security teams to identify patterns and detect potential incidents.
11. What is a zero-day vulnerability?
• A. Patched flaw
• B. Known exploit
• C. Unknown vulnerability
• D. Expired certificate