Incident Response Technician Level II Exam
With Actual Questions & Verified Answers,
Plus Explained Rationales/Expert Verified
For Guaranteed 100% Pass 2026/Latest
Update/Instant Download Pdf
1. Which type of malware is designed to gain unauthorized
administrative access to a system while remaining undetected?
A. Virus
B. Rootkit
C. Worm
D. Adware
B. Rootkit
Rationale: Rootkits operate at a low level to hide their presence
and provide attackers with privileged access, making them
difficult to detect and remove.
2. What is the first step in the incident response process?
A. Containment
B. Detection and identification
C. Recovery
D. Eradication
B. Detection and identification
Rationale: Identifying and detecting an incident is the initial
step, as it allows the response team to assess the scope and
severity before taking action.
,3. Which of the following best describes a “zero-day” vulnerability?
A. A vulnerability that has been patched immediately
B. A vulnerability known to the public for over 30 days
C. A previously unknown vulnerability exploited before a patch is
available
D. A vulnerability that only affects legacy systems
C. A previously unknown vulnerability exploited before a patch
is available
Rationale: Zero-day vulnerabilities are unpatched flaws
unknown to vendors and security teams, making them highly
valuable to attackers.
4. During an incident, which method helps prevent further spread of
malware in a network?
A. Monitoring network traffic
B. Containment
C. Performing forensics
D. Logging all activity
B. Containment
Rationale: Containment isolates affected systems to prevent the
malware from spreading while the response team investigates
and remediates the incident.
5. Which type of attack involves sending numerous requests to
overwhelm a system, making it unavailable to users?
A. Phishing
B. Denial-of-Service (DoS)
C. Man-in-the-Middle
D. SQL Injection
B. Denial-of-Service (DoS)
Rationale: DoS attacks flood a system with traffic to exhaust
resources and disrupt legitimate access.
,6. In incident response, what is the main purpose of creating an
evidence chain of custody?
A. To ensure malware is removed
B. To maintain legal integrity of collected evidence
C. To speed up recovery
D. To restore system functionality
B. To maintain legal integrity of collected evidence
Rationale: A documented chain of custody ensures evidence is
admissible in legal proceedings and prevents tampering or loss.
7. Which of the following is a common indicator of compromise (IoC)
on a host system?
A. Normal CPU usage
B. Unknown processes running
C. Regular system updates
D. Approved software installed
B. Unknown processes running
Rationale: Unexpected processes, especially those running with
elevated privileges, are often signs of compromise.
8. What does the term “pivoting” refer to in incident response?
A. Shutting down a compromised system
B. Using a compromised system to attack other systems
C. Restoring a system from backup
D. Encrypting data to prevent access
B. Using a compromised system to attack other systems
Rationale: Attackers often pivot from one compromised system
to other connected systems to expand access.
9. Which logging standard is commonly used for collecting security-
related events from network devices?
A. ISO 27001
, B. Syslog
C. NIST SP 800-61
D. PCI DSS
B. Syslog
Rationale: Syslog provides a standard protocol for logging
messages from various network devices and security systems.
10. What is the primary goal of post-incident analysis?
A. Eradicate malware
B. Restore operations
C. Identify lessons learned and improve security posture
D. Contain the incident
C. Identify lessons learned and improve security posture
Rationale: Post-incident analysis evaluates what occurred,
identifies weaknesses, and implements improvements to prevent
future incidents.
11. Which method is used to detect malicious activity within
encrypted traffic without decrypting it?
A. Signature-based scanning
B. Heuristic analysis
C. Flow analysis
D. Full packet capture
C. Flow analysis
Rationale: Flow analysis monitors traffic patterns for anomalies
without requiring decryption, reducing performance impact and
preserving privacy.
12. What is the main difference between Level I and Level II
incident response technicians?
A. Level I handles physical security incidents, Level II handles
digital only
With Actual Questions & Verified Answers,
Plus Explained Rationales/Expert Verified
For Guaranteed 100% Pass 2026/Latest
Update/Instant Download Pdf
1. Which type of malware is designed to gain unauthorized
administrative access to a system while remaining undetected?
A. Virus
B. Rootkit
C. Worm
D. Adware
B. Rootkit
Rationale: Rootkits operate at a low level to hide their presence
and provide attackers with privileged access, making them
difficult to detect and remove.
2. What is the first step in the incident response process?
A. Containment
B. Detection and identification
C. Recovery
D. Eradication
B. Detection and identification
Rationale: Identifying and detecting an incident is the initial
step, as it allows the response team to assess the scope and
severity before taking action.
,3. Which of the following best describes a “zero-day” vulnerability?
A. A vulnerability that has been patched immediately
B. A vulnerability known to the public for over 30 days
C. A previously unknown vulnerability exploited before a patch is
available
D. A vulnerability that only affects legacy systems
C. A previously unknown vulnerability exploited before a patch
is available
Rationale: Zero-day vulnerabilities are unpatched flaws
unknown to vendors and security teams, making them highly
valuable to attackers.
4. During an incident, which method helps prevent further spread of
malware in a network?
A. Monitoring network traffic
B. Containment
C. Performing forensics
D. Logging all activity
B. Containment
Rationale: Containment isolates affected systems to prevent the
malware from spreading while the response team investigates
and remediates the incident.
5. Which type of attack involves sending numerous requests to
overwhelm a system, making it unavailable to users?
A. Phishing
B. Denial-of-Service (DoS)
C. Man-in-the-Middle
D. SQL Injection
B. Denial-of-Service (DoS)
Rationale: DoS attacks flood a system with traffic to exhaust
resources and disrupt legitimate access.
,6. In incident response, what is the main purpose of creating an
evidence chain of custody?
A. To ensure malware is removed
B. To maintain legal integrity of collected evidence
C. To speed up recovery
D. To restore system functionality
B. To maintain legal integrity of collected evidence
Rationale: A documented chain of custody ensures evidence is
admissible in legal proceedings and prevents tampering or loss.
7. Which of the following is a common indicator of compromise (IoC)
on a host system?
A. Normal CPU usage
B. Unknown processes running
C. Regular system updates
D. Approved software installed
B. Unknown processes running
Rationale: Unexpected processes, especially those running with
elevated privileges, are often signs of compromise.
8. What does the term “pivoting” refer to in incident response?
A. Shutting down a compromised system
B. Using a compromised system to attack other systems
C. Restoring a system from backup
D. Encrypting data to prevent access
B. Using a compromised system to attack other systems
Rationale: Attackers often pivot from one compromised system
to other connected systems to expand access.
9. Which logging standard is commonly used for collecting security-
related events from network devices?
A. ISO 27001
, B. Syslog
C. NIST SP 800-61
D. PCI DSS
B. Syslog
Rationale: Syslog provides a standard protocol for logging
messages from various network devices and security systems.
10. What is the primary goal of post-incident analysis?
A. Eradicate malware
B. Restore operations
C. Identify lessons learned and improve security posture
D. Contain the incident
C. Identify lessons learned and improve security posture
Rationale: Post-incident analysis evaluates what occurred,
identifies weaknesses, and implements improvements to prevent
future incidents.
11. Which method is used to detect malicious activity within
encrypted traffic without decrypting it?
A. Signature-based scanning
B. Heuristic analysis
C. Flow analysis
D. Full packet capture
C. Flow analysis
Rationale: Flow analysis monitors traffic patterns for anomalies
without requiring decryption, reducing performance impact and
preserving privacy.
12. What is the main difference between Level I and Level II
incident response technicians?
A. Level I handles physical security incidents, Level II handles
digital only