Incident Response Technician Level II Exam
Questions With Correct Answers (Verified
Answers) Plus Rationales 2026 Q&A | Instant
Download Pdf
1. Which phase of the incident response lifecycle focuses on
identifying whether an event is a true security incident?
A. Containment
B. Detection and Analysis
C. Recovery
D. Post-Incident Review
Answer: B
Rationale: Detection and analysis involves reviewing alerts, logs, and
events to determine whether suspicious activity constitutes a real
security incident and assessing its severity.
2. What is the primary purpose of a chain of custody document?
A. To encrypt evidence during transport
B. To record all individuals who handle evidence
,C. To delete duplicate forensic images
D. To restore compromised systems
Answer: B
Rationale: Chain of custody ensures accountability by documenting
every person who collects, transfers, analyzes, or stores digital
evidence.
3. Which tool is most commonly used for centralized log analysis in
incident response?
A. SIEM
B. FTP
C. DNS
D. DHCP
Answer: A
Rationale: Security Information and Event Management (SIEM)
systems aggregate and analyze logs from multiple sources for threat
detection.
4. What is the first step when handling a suspected compromised
workstation?
A. Immediately wipe the disk
,B. Power off the system
C. Preserve volatile data if possible
D. Reinstall the operating system
Answer: C
Rationale: Volatile data such as RAM contents should be preserved
first because it is lost when power is removed.
5. Which of the following best describes malware persistence?
A. Malware that deletes itself after execution
B. Malware that remains active after reboot
C. Malware that only affects memory
D. Malware that requires user interaction each time
Answer: B
Rationale: Persistent malware is designed to survive reboots and
continue operating on the system.
6. What does IOC stand for in incident response?
A. Internal Operations Control
B. Indicator of Compromise
C. Internet Operations Channel
D. Incident Overwatch Center
, Answer: B
Rationale: IOCs are artifacts such as IP addresses, hashes, or behaviors
that indicate malicious activity.
7. Which log source is most useful for tracking user authentication
attempts?
A. Firewall logs
B. Active Directory logs
C. DNS logs
D. Printer logs
Answer: B
Rationale: Active Directory logs track authentication events such as
logins and failed access attempts.
8. What is the main goal of incident containment?
A. Eradicate all malware permanently
B. Prevent further spread of the incident
C. Restore backups
D. Identify attackers
Answer: B
Questions With Correct Answers (Verified
Answers) Plus Rationales 2026 Q&A | Instant
Download Pdf
1. Which phase of the incident response lifecycle focuses on
identifying whether an event is a true security incident?
A. Containment
B. Detection and Analysis
C. Recovery
D. Post-Incident Review
Answer: B
Rationale: Detection and analysis involves reviewing alerts, logs, and
events to determine whether suspicious activity constitutes a real
security incident and assessing its severity.
2. What is the primary purpose of a chain of custody document?
A. To encrypt evidence during transport
B. To record all individuals who handle evidence
,C. To delete duplicate forensic images
D. To restore compromised systems
Answer: B
Rationale: Chain of custody ensures accountability by documenting
every person who collects, transfers, analyzes, or stores digital
evidence.
3. Which tool is most commonly used for centralized log analysis in
incident response?
A. SIEM
B. FTP
C. DNS
D. DHCP
Answer: A
Rationale: Security Information and Event Management (SIEM)
systems aggregate and analyze logs from multiple sources for threat
detection.
4. What is the first step when handling a suspected compromised
workstation?
A. Immediately wipe the disk
,B. Power off the system
C. Preserve volatile data if possible
D. Reinstall the operating system
Answer: C
Rationale: Volatile data such as RAM contents should be preserved
first because it is lost when power is removed.
5. Which of the following best describes malware persistence?
A. Malware that deletes itself after execution
B. Malware that remains active after reboot
C. Malware that only affects memory
D. Malware that requires user interaction each time
Answer: B
Rationale: Persistent malware is designed to survive reboots and
continue operating on the system.
6. What does IOC stand for in incident response?
A. Internal Operations Control
B. Indicator of Compromise
C. Internet Operations Channel
D. Incident Overwatch Center
, Answer: B
Rationale: IOCs are artifacts such as IP addresses, hashes, or behaviors
that indicate malicious activity.
7. Which log source is most useful for tracking user authentication
attempts?
A. Firewall logs
B. Active Directory logs
C. DNS logs
D. Printer logs
Answer: B
Rationale: Active Directory logs track authentication events such as
logins and failed access attempts.
8. What is the main goal of incident containment?
A. Eradicate all malware permanently
B. Prevent further spread of the incident
C. Restore backups
D. Identify attackers
Answer: B