• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 30 pages
Exam (elaborations)

Incident Response and Management – Practice Questions with Verified Answers (Cybersecurity, 2024)

Document preview thumbnail
Preview 3 out of 30 pages

This document contains 90+ multiple-choice questions on incident response and digital forensics, each with a clearly marked correct answer. Topics include NIST incident response phases, forensic imaging techniques, chain of custody, evidence handling, malware analysis, and key concepts from frameworks like MITRE ATT&CK and the Cyber Kill Chain. Ideal for cybersecurity students and professionals preparing for certifications or internal assessments.

Content preview

Incident response and management - 3 questions
with accurate answers
100. While reviewing the actions taken during an incident response
process , Mei is informed by the local desktop support staff person that
the infected machine was returned to service by using a Windows
System Restore point . Which of the following items will a Windows
System Restore return to a previous state ? A. Personal files B. Malware
C. Windows system files D. All installed apps Ans✓✓✓A


101. During a major incident response effort , Kobe discovers evidence
that a critical application server may have been the data repository and
egress point in the compromise he is investigating . If he is unable to
take the system offline , which of the following options will provide him
with the best forensic data ? A. Reboot the server and mount the system
drive using a USB - bootable forensic suite . B. Create an image using a
tool like FTK Imager Lite . C. Capture the system memory using a tool
like Volatility . D. Install and run an imaging tool on the live server .
Ans✓✓✓A


104. During the preparation phase of his organization's incident response
process , Oscar gathers a laptop with useful software including a sniffer
and forensics tools , thumb drives and external hard drives , networking
equipment , and a variety of cables . What is this type of preprepared
equipment commonly called ? A. A grab bag B. A jump kit C. A crash
cart D. A first responder kit Ans✓✓✓A


105. As John proceeds with a forensic investigation involving numerous
images , he finds a directory labeled Downloaded from Facebook . The
images appear relevant to his investigation , so he processes them for

,metadata using exiftool . The following image shows the data provided .
What forensically useful information can John gather from this output
Ans✓✓✓A


106. Which of the following properly lists the order of volatility from
least to most volatile ? A. Printouts , swap files , CPU cache , RAM B.
Hard drives , USB media , DVDs , CD - RWS C. DVDs , hard drives ,
virtual memory , caches D. RAM , swap files , SSDs , printouts
Ans✓✓✓A


107. While conducting a forensic review of a system involved in a data
breach , Alex discovers a number of Microsoft Word files including files
with filenames like critical_data.docx and sales_estimates_2023.docx .
When he attempts to review the files using a text editor for any useful
information , he finds only unreadable data . What has occurred ? A.
Microsoft Word files are stored in ZIP format . B. Microsoft Word files
are encrypted . C. Microsoft Word files can be opened only by Microsoft
Word . D. The user has used antiforensic techniques to scramble the data
. Ans✓✓✓A


107. While conducting a forensic review of a system involved in a data
breach , Alex discovers a number of Microsoft Word files including files
with filenames like critical_data.docx and sales_estimates_2023.docx .
When he attempts to review the files using a text editor for any useful
information , he finds only unreadable data . What has occurred ? A.
Microsoft Word files are stored in ZIP format . B. Microsoft Word files
are encrypted . C. Microsoft Word files can be opened only by Microsoft
Word . D. The user has used antiforensic techniques to scramble the data
. Ans✓✓✓A

, 108. Lukas believes that one of his users has attempted to use built - in
Windows commands to probe servers on the network he is responsible
for . How can he recover the command history for that user if the system
has been rebooted since the reconnaissance has occurred ? A. Check the
Bash history . B. Open a command prompt window and press F7 . C.
Manually open the command history from the user's profile directory .
D. The Windows command prompt does not store command history .
Ans✓✓✓A


108. Lukas believes that one of his users has attempted to use built - in
Windows commands to probe servers on the network he is responsible
for . How can he recover the command history for that user if the system
has been rebooted since the reconnaissance has occurred ? A. Check the
Bash history . B. Open a command prompt window and press F7 . C.
Manually open the command history from the user's profile directory .
D. The Windows command prompt does not store command history .
Ans✓✓✓A


109. Angela is conducting an incident response exercise and needs to
assess the economic impact on her organization of a $ 500,000 expense
related to an information security incident . How should she categorize
this ? A. Low impact . B. Medium impact . C. High impact . D. Angela
cannot assess the impact with the data given . Ans✓✓✓A


110. What step follows sanitization of media according to NIST
guidelines for secure media handling ? A. Reuse . B. Validation C.
Destruction . D.Documentation . Ans✓✓✓A

Document information

Uploaded on
June 26, 2025
Number of pages
30
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$18.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
cracker
3.8
(401)
Sold
2168
Followers
1346
Items
50099
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions