Incident Response Technician Level I
Exam With Actual Questions & Verified
Answers, Plus Explained
Rationales/Expert Verified For
Guaranteed 100% Pass 2026/Latest
Update/Instant Download Pdf
1. Which of the following is the first step in the incident response
process?
A. Containment
B. Eradication
C. Identification
D. Recovery
Identification is the first step in incident response, as it involves
detecting and recognizing that an incident has occurred.
2. Which type of incident involves unauthorized access to sensitive
data?
A. Denial of service
B. Data breach
C. Malware infection
D. Phishing attack
A data breach specifically refers to the unauthorized access or
disclosure of sensitive information.
, 3. What is the primary purpose of a containment strategy?
A. To remove malware completely
B. To recover lost data
C. To limit the scope and impact of an incident
D. To notify stakeholders
Containment focuses on stopping the incident from spreading and
minimizing its impact.
4. Which tool is commonly used for network traffic analysis during
an incident?
A. Word processor
B. Spreadsheet
C. Wireshark
D. Photoshop
Wireshark captures and analyzes network packets, which helps in
investigating network incidents.
5. When should evidence be collected during an incident?
A. Only after recovery
B. Only if the system is offline
C. As soon as possible, following proper procedures
D. Only if law enforcement requests it
Prompt evidence collection ensures that critical data is preserved for
analysis and potential legal proceedings.
6. Which of the following is an example of an internal threat?
A. Malware from the internet
B. Phishing email from an external source
C. A disgruntled employee accessing sensitive data
D. SQL injection from a remote attacker
, Internal threats originate from within the organization, such as
employees or contractors.
7. What does RTO stand for in incident response planning?
A. Recovery Time Objective
B. Recovery Time Objective
C. Risk Tolerance Overview
D. Remote Threat Operation
RTO defines the maximum acceptable time for restoring a system
after an incident.
8. Which type of malware is designed to lock users out of their
system until a ransom is paid?
A. Spyware
B. Ransomware
C. Worm
D. Rootkit
Ransomware encrypts or locks files and demands payment to restore
access.
9. Which of the following is considered a best practice for
documenting incidents?
A. Use informal notes
B. Maintain a detailed, chronological log
C. Record only successful mitigations
D. Only document high-severity incidents
A detailed, chronological log ensures accurate tracking, reporting, and
future reference.
10. Which incident response phase focuses on restoring affected
systems to normal operation?
A. Identification
Exam With Actual Questions & Verified
Answers, Plus Explained
Rationales/Expert Verified For
Guaranteed 100% Pass 2026/Latest
Update/Instant Download Pdf
1. Which of the following is the first step in the incident response
process?
A. Containment
B. Eradication
C. Identification
D. Recovery
Identification is the first step in incident response, as it involves
detecting and recognizing that an incident has occurred.
2. Which type of incident involves unauthorized access to sensitive
data?
A. Denial of service
B. Data breach
C. Malware infection
D. Phishing attack
A data breach specifically refers to the unauthorized access or
disclosure of sensitive information.
, 3. What is the primary purpose of a containment strategy?
A. To remove malware completely
B. To recover lost data
C. To limit the scope and impact of an incident
D. To notify stakeholders
Containment focuses on stopping the incident from spreading and
minimizing its impact.
4. Which tool is commonly used for network traffic analysis during
an incident?
A. Word processor
B. Spreadsheet
C. Wireshark
D. Photoshop
Wireshark captures and analyzes network packets, which helps in
investigating network incidents.
5. When should evidence be collected during an incident?
A. Only after recovery
B. Only if the system is offline
C. As soon as possible, following proper procedures
D. Only if law enforcement requests it
Prompt evidence collection ensures that critical data is preserved for
analysis and potential legal proceedings.
6. Which of the following is an example of an internal threat?
A. Malware from the internet
B. Phishing email from an external source
C. A disgruntled employee accessing sensitive data
D. SQL injection from a remote attacker
, Internal threats originate from within the organization, such as
employees or contractors.
7. What does RTO stand for in incident response planning?
A. Recovery Time Objective
B. Recovery Time Objective
C. Risk Tolerance Overview
D. Remote Threat Operation
RTO defines the maximum acceptable time for restoring a system
after an incident.
8. Which type of malware is designed to lock users out of their
system until a ransom is paid?
A. Spyware
B. Ransomware
C. Worm
D. Rootkit
Ransomware encrypts or locks files and demands payment to restore
access.
9. Which of the following is considered a best practice for
documenting incidents?
A. Use informal notes
B. Maintain a detailed, chronological log
C. Record only successful mitigations
D. Only document high-severity incidents
A detailed, chronological log ensures accurate tracking, reporting, and
future reference.
10. Which incident response phase focuses on restoring affected
systems to normal operation?
A. Identification