Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 36 pages
Exam (elaborations)

Incident Response Technician Level II Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A Instant Download Pdf

Document preview thumbnail
Preview 4 out of 36 pages

Incident Response Technician Level II Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A Instant Download Pdf

Content preview

Incident Response Technician Level II
Questions And Correct Answers
(Verified Answers) Plus Rationales 2026
Q&A Instant Download Pdf

1. During an incident, what is the primary purpose of establishing a timeline of
events?

A. To identify the least expensive response option
B. To reconstruct the sequence and progression of attacker activity
C. To determine which employee should be disciplined
D. To immediately delete malicious files

Answer: To reconstruct the sequence and progression of attacker activity

Rationale: A well-developed timeline correlates evidence from endpoints,
network devices, authentication systems, and applications to determine what
happened and when.

2. Which principle is most important when collecting digital evidence for
potential legal proceedings?

A. Speed over accuracy
B. Evidence preservation and integrity
C. Immediate system reimaging
D. Avoiding documentation

Answer: Evidence preservation and integrity

,Rationale: Digital evidence must be collected, preserved, documented, and
handled in a manner that maintains its integrity and supports its admissibility.

3. A workstation is suspected of being compromised and is currently powered
on. Which evidence is generally most volatile?

A. Installed applications
B. Registry files
C. RAM contents
D. Archived backups

Answer: RAM contents

Rationale: Volatile memory can contain running processes, network
connections, credentials, encryption keys, and other information that disappears
when the system loses power.

4. Which activity is most appropriate before making significant changes to a
compromised system?

A. Delete suspicious files
B. Document the system's current state
C. Install security updates
D. Run a disk cleanup utility

Answer: Document the system's current state

Rationale: Initial documentation preserves important observations and helps
investigators understand the system before evidence is altered.

5. What is the primary purpose of a cryptographic hash when handling
forensic evidence?

A. To encrypt the evidence
B. To compress the evidence
C. To verify evidence integrity
D. To remove malware

,Answer: To verify evidence integrity

Rationale: Hash values provide a repeatable fingerprint that can be compared
later to determine whether evidence has changed.

6. Which Windows artifact can provide valuable information about recently
executed programs?

A. Prefetch files
B. Hosts file only
C. Wallpaper settings
D. Printer configuration only

Answer: Prefetch files

Rationale: Windows Prefetch data can provide evidence that programs were
executed and may contain useful execution-related timestamps and metadata.

7. What is the primary objective of containment?

A. Permanently eliminate every vulnerability
B. Prevent the incident from spreading or causing additional damage
C. Complete the post-incident report
D. Restore all systems immediately

Answer: Prevent the incident from spreading or causing additional damage

Rationale: Containment limits the scope and impact of an incident while
allowing responders to investigate and plan eradication and recovery.

8. Which containment strategy is generally considered more targeted than
disconnecting an entire network?

A. Blocking a known malicious IP address or domain
B. Shutting down every server
C. Deleting all firewall rules
D. Removing all user accounts

, Answer: Blocking a known malicious IP address or domain

Rationale: Targeted blocking can disrupt known malicious communication while
minimizing unnecessary operational disruption.

9. What is the purpose of an incident severity classification?

A. To determine employee salaries
B. To prioritize response activities according to impact and risk
C. To replace forensic analysis
D. To identify the operating system

Answer: To prioritize response activities according to impact and risk

Rationale: Severity ratings help organizations allocate appropriate personnel,
resources, escalation, and response urgency.

10.Which log source is particularly useful for investigating suspicious
authentication activity?

A. Authentication and identity-provider logs
B. Monitor brightness settings
C. Desktop wallpaper logs
D. Keyboard layout settings

Answer: Authentication and identity-provider logs

Rationale: Authentication logs can reveal failed logins, successful logins,
unusual locations, MFA activity, privilege changes, and other identity-related
events.

11.What does lateral movement describe?

A. Moving evidence to another storage device
B. An attacker moving from one compromised system or account to another
C. Moving a server between data centers
D. Reinstalling an operating system

Document information

Uploaded on
August 18, 2026
Number of pages
36
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$26.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
1
Followers
1
Items
901
Last sold
1 month ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions