___________________________________________________________________
Incident Response Technician Level I
Questions And Correct Answers
(Verified Answers) Plus Rationales 2026
Q&A Instant Download Pdf
___________________________________________________________________
1. What is the primary goal of incident response?
A. Eliminate all network traffic
B. Identify, contain, eradicate, and recover from security incidents
C. Replace all compromised computers
D. Prevent employees from accessing the internet
Rationale: Incident response is a structured process for detecting incidents,
limiting their impact, removing the threat, and restoring normal operations.
2. Which phase typically comes first in the incident response lifecycle?
A. Eradication
B. Recovery
C. Preparation
D. Lessons learned
Rationale: Preparation establishes policies, tools, personnel, procedures, and
resources needed to respond effectively.
3. What is considered a security incident?
A. A routine software update
B. An event that threatens the confidentiality, integrity, or availability of
information or systems
,C. A scheduled system reboot
D. A normal user login
Rationale: A security incident involves an actual or suspected event that could
compromise organizational information or systems.
4. Which principle is most important when collecting digital evidence?
A. Modify the evidence to make analysis easier
B. Preserve evidence integrity
C. Delete unnecessary files immediately
D. Restart the affected system
Rationale: Evidence must remain reliable and unchanged so that investigative
conclusions can be supported.
5. What does the term "chain of custody" describe?
A. A password management procedure
B. The documented history of evidence collection, handling, transfer, and
storage
C. The order of incident severity
D. A network routing process
Rationale: Chain-of-custody documentation demonstrates who handled
evidence and helps establish its integrity and accountability.
6. Which action should generally be avoided when investigating a powered-on
compromised computer?
A. Photographing the screen
B. Recording system information
C. Immediately shutting it down without considering volatile evidence
D. Documenting the system state
Rationale: Shutting down a system can destroy volatile information such as
RAM contents, active connections, and running processes.
, 7. Which type of evidence is most volatile?
A. Archived logs
B. Hard-drive data
C. RAM contents
D. Printed reports
Rationale: RAM contains temporary information that is generally lost when
power is removed.
8. What is the purpose of incident containment?
A. Determine employee salaries
B. Limit the spread and impact of an incident
C. Permanently delete evidence
D. Replace the organization's security policy
Rationale: Containment prevents an incident from causing additional damage
while investigators determine the appropriate response.
9. Which containment method can be appropriate for an infected
workstation?
A. Publish its IP address publicly
B. Isolate it from the network
C. Delete all organizational logs
D. Disable all security controls
Rationale: Network isolation can prevent malware or an attacker from
communicating with other systems.
10.What is eradication?
A. Detecting an incident
B. Removing the root cause and malicious components of an incident
C. Creating a backup
D. Writing an incident report
Incident Response Technician Level I
Questions And Correct Answers
(Verified Answers) Plus Rationales 2026
Q&A Instant Download Pdf
___________________________________________________________________
1. What is the primary goal of incident response?
A. Eliminate all network traffic
B. Identify, contain, eradicate, and recover from security incidents
C. Replace all compromised computers
D. Prevent employees from accessing the internet
Rationale: Incident response is a structured process for detecting incidents,
limiting their impact, removing the threat, and restoring normal operations.
2. Which phase typically comes first in the incident response lifecycle?
A. Eradication
B. Recovery
C. Preparation
D. Lessons learned
Rationale: Preparation establishes policies, tools, personnel, procedures, and
resources needed to respond effectively.
3. What is considered a security incident?
A. A routine software update
B. An event that threatens the confidentiality, integrity, or availability of
information or systems
,C. A scheduled system reboot
D. A normal user login
Rationale: A security incident involves an actual or suspected event that could
compromise organizational information or systems.
4. Which principle is most important when collecting digital evidence?
A. Modify the evidence to make analysis easier
B. Preserve evidence integrity
C. Delete unnecessary files immediately
D. Restart the affected system
Rationale: Evidence must remain reliable and unchanged so that investigative
conclusions can be supported.
5. What does the term "chain of custody" describe?
A. A password management procedure
B. The documented history of evidence collection, handling, transfer, and
storage
C. The order of incident severity
D. A network routing process
Rationale: Chain-of-custody documentation demonstrates who handled
evidence and helps establish its integrity and accountability.
6. Which action should generally be avoided when investigating a powered-on
compromised computer?
A. Photographing the screen
B. Recording system information
C. Immediately shutting it down without considering volatile evidence
D. Documenting the system state
Rationale: Shutting down a system can destroy volatile information such as
RAM contents, active connections, and running processes.
, 7. Which type of evidence is most volatile?
A. Archived logs
B. Hard-drive data
C. RAM contents
D. Printed reports
Rationale: RAM contains temporary information that is generally lost when
power is removed.
8. What is the purpose of incident containment?
A. Determine employee salaries
B. Limit the spread and impact of an incident
C. Permanently delete evidence
D. Replace the organization's security policy
Rationale: Containment prevents an incident from causing additional damage
while investigators determine the appropriate response.
9. Which containment method can be appropriate for an infected
workstation?
A. Publish its IP address publicly
B. Isolate it from the network
C. Delete all organizational logs
D. Disable all security controls
Rationale: Network isolation can prevent malware or an attacker from
communicating with other systems.
10.What is eradication?
A. Detecting an incident
B. Removing the root cause and malicious components of an incident
C. Creating a backup
D. Writing an incident report