Incident Response Technician Level II
Questions And Correct Answers
(Verified Answers) Plus Rationales 2026
Q&A Instant Download Pdf
1. During an incident, what is the primary purpose of establishing a timeline of
events?
A. To identify the least expensive response option
B. To reconstruct the sequence and progression of attacker activity
C. To determine which employee should be disciplined
D. To immediately delete malicious files
Answer: To reconstruct the sequence and progression of attacker activity
Rationale: A well-developed timeline correlates evidence from endpoints,
network devices, authentication systems, and applications to determine what
happened and when.
2. Which principle is most important when collecting digital evidence for
potential legal proceedings?
A. Speed over accuracy
B. Evidence preservation and integrity
C. Immediate system reimaging
D. Avoiding documentation
Answer: Evidence preservation and integrity
,Rationale: Digital evidence must be collected, preserved, documented, and
handled in a manner that maintains its integrity and supports its admissibility.
3. A workstation is suspected of being compromised and is currently powered
on. Which evidence is generally most volatile?
A. Installed applications
B. Registry files
C. RAM contents
D. Archived backups
Answer: RAM contents
Rationale: Volatile memory can contain running processes, network
connections, credentials, encryption keys, and other information that disappears
when the system loses power.
4. Which activity is most appropriate before making significant changes to a
compromised system?
A. Delete suspicious files
B. Document the system's current state
C. Install security updates
D. Run a disk cleanup utility
Answer: Document the system's current state
Rationale: Initial documentation preserves important observations and helps
investigators understand the system before evidence is altered.
5. What is the primary purpose of a cryptographic hash when handling
forensic evidence?
A. To encrypt the evidence
B. To compress the evidence
C. To verify evidence integrity
D. To remove malware
,Answer: To verify evidence integrity
Rationale: Hash values provide a repeatable fingerprint that can be compared
later to determine whether evidence has changed.
6. Which Windows artifact can provide valuable information about recently
executed programs?
A. Prefetch files
B. Hosts file only
C. Wallpaper settings
D. Printer configuration only
Answer: Prefetch files
Rationale: Windows Prefetch data can provide evidence that programs were
executed and may contain useful execution-related timestamps and metadata.
7. What is the primary objective of containment?
A. Permanently eliminate every vulnerability
B. Prevent the incident from spreading or causing additional damage
C. Complete the post-incident report
D. Restore all systems immediately
Answer: Prevent the incident from spreading or causing additional damage
Rationale: Containment limits the scope and impact of an incident while
allowing responders to investigate and plan eradication and recovery.
8. Which containment strategy is generally considered more targeted than
disconnecting an entire network?
A. Blocking a known malicious IP address or domain
B. Shutting down every server
C. Deleting all firewall rules
D. Removing all user accounts
, Answer: Blocking a known malicious IP address or domain
Rationale: Targeted blocking can disrupt known malicious communication while
minimizing unnecessary operational disruption.
9. What is the purpose of an incident severity classification?
A. To determine employee salaries
B. To prioritize response activities according to impact and risk
C. To replace forensic analysis
D. To identify the operating system
Answer: To prioritize response activities according to impact and risk
Rationale: Severity ratings help organizations allocate appropriate personnel,
resources, escalation, and response urgency.
10.Which log source is particularly useful for investigating suspicious
authentication activity?
A. Authentication and identity-provider logs
B. Monitor brightness settings
C. Desktop wallpaper logs
D. Keyboard layout settings
Answer: Authentication and identity-provider logs
Rationale: Authentication logs can reveal failed logins, successful logins,
unusual locations, MFA activity, privilege changes, and other identity-related
events.
11.What does lateral movement describe?
A. Moving evidence to another storage device
B. An attacker moving from one compromised system or account to another
C. Moving a server between data centers
D. Reinstalling an operating system
Questions And Correct Answers
(Verified Answers) Plus Rationales 2026
Q&A Instant Download Pdf
1. During an incident, what is the primary purpose of establishing a timeline of
events?
A. To identify the least expensive response option
B. To reconstruct the sequence and progression of attacker activity
C. To determine which employee should be disciplined
D. To immediately delete malicious files
Answer: To reconstruct the sequence and progression of attacker activity
Rationale: A well-developed timeline correlates evidence from endpoints,
network devices, authentication systems, and applications to determine what
happened and when.
2. Which principle is most important when collecting digital evidence for
potential legal proceedings?
A. Speed over accuracy
B. Evidence preservation and integrity
C. Immediate system reimaging
D. Avoiding documentation
Answer: Evidence preservation and integrity
,Rationale: Digital evidence must be collected, preserved, documented, and
handled in a manner that maintains its integrity and supports its admissibility.
3. A workstation is suspected of being compromised and is currently powered
on. Which evidence is generally most volatile?
A. Installed applications
B. Registry files
C. RAM contents
D. Archived backups
Answer: RAM contents
Rationale: Volatile memory can contain running processes, network
connections, credentials, encryption keys, and other information that disappears
when the system loses power.
4. Which activity is most appropriate before making significant changes to a
compromised system?
A. Delete suspicious files
B. Document the system's current state
C. Install security updates
D. Run a disk cleanup utility
Answer: Document the system's current state
Rationale: Initial documentation preserves important observations and helps
investigators understand the system before evidence is altered.
5. What is the primary purpose of a cryptographic hash when handling
forensic evidence?
A. To encrypt the evidence
B. To compress the evidence
C. To verify evidence integrity
D. To remove malware
,Answer: To verify evidence integrity
Rationale: Hash values provide a repeatable fingerprint that can be compared
later to determine whether evidence has changed.
6. Which Windows artifact can provide valuable information about recently
executed programs?
A. Prefetch files
B. Hosts file only
C. Wallpaper settings
D. Printer configuration only
Answer: Prefetch files
Rationale: Windows Prefetch data can provide evidence that programs were
executed and may contain useful execution-related timestamps and metadata.
7. What is the primary objective of containment?
A. Permanently eliminate every vulnerability
B. Prevent the incident from spreading or causing additional damage
C. Complete the post-incident report
D. Restore all systems immediately
Answer: Prevent the incident from spreading or causing additional damage
Rationale: Containment limits the scope and impact of an incident while
allowing responders to investigate and plan eradication and recovery.
8. Which containment strategy is generally considered more targeted than
disconnecting an entire network?
A. Blocking a known malicious IP address or domain
B. Shutting down every server
C. Deleting all firewall rules
D. Removing all user accounts
, Answer: Blocking a known malicious IP address or domain
Rationale: Targeted blocking can disrupt known malicious communication while
minimizing unnecessary operational disruption.
9. What is the purpose of an incident severity classification?
A. To determine employee salaries
B. To prioritize response activities according to impact and risk
C. To replace forensic analysis
D. To identify the operating system
Answer: To prioritize response activities according to impact and risk
Rationale: Severity ratings help organizations allocate appropriate personnel,
resources, escalation, and response urgency.
10.Which log source is particularly useful for investigating suspicious
authentication activity?
A. Authentication and identity-provider logs
B. Monitor brightness settings
C. Desktop wallpaper logs
D. Keyboard layout settings
Answer: Authentication and identity-provider logs
Rationale: Authentication logs can reveal failed logins, successful logins,
unusual locations, MFA activity, privilege changes, and other identity-related
events.
11.What does lateral movement describe?
A. Moving evidence to another storage device
B. An attacker moving from one compromised system or account to another
C. Moving a server between data centers
D. Reinstalling an operating system