Incident Response Technician Level I Exam
Questions and Correct Answers Verified
Answers) Plus Rationales 2026 Q&A | Instant
Download Pdf
1. What is the first phase of the incident response lifecycle?
A. Containment
B. Identification
C. Preparation
D. Recovery
Answer: C
Rationale: Preparation ensures policies, tools, and training are in place
before an incident occurs.
2. Which document outlines procedures for handling security
incidents?
A. Acceptable Use Policy
B. Incident Response Plan
C. Disaster Recovery Plan
,D. Service Level Agreement
Answer: B
Rationale: The Incident Response Plan defines steps to detect, respond,
and recover from incidents.
3. What is the primary goal during the containment phase?
A. Identify attacker
B. Limit damage
C. Restore systems
D. Document findings
Answer: B
Rationale: Containment focuses on preventing the spread and
minimizing impact.
4. Which type of incident involves unauthorized access to data?
A. Denial of Service
B. Data Breach
C. Phishing
D. Malware
Answer: B
,Rationale: A data breach specifically involves exposure of sensitive
information.
5. What tool is commonly used to capture network traffic?
A. Antivirus
B. SIEM
C. Packet Sniffer
D. Firewall
Answer: C
Rationale: Packet sniffers analyze network traffic for suspicious activity.
6. What is the purpose of a SIEM system?
A. Encrypt data
B. Monitor and analyze logs
C. Block malware
D. Manage passwords
Answer: B
Rationale: SIEM aggregates and analyzes logs for security monitoring.
, 7. Which phase involves removing the cause of an incident?
A. Recovery
B. Eradication
C. Detection
D. Preparation
Answer: B
Rationale: Eradication eliminates threats such as malware or
vulnerabilities.
8. What is a common indicator of compromise (IOC)?
A. Strong password
B. Unusual outbound traffic
C. Software update
D. Backup completion
Answer: B
Rationale: Abnormal traffic often signals malicious activity.
9. Which type of malware replicates itself across networks?
A. Trojan
B. Worm
C. Spyware
Questions and Correct Answers Verified
Answers) Plus Rationales 2026 Q&A | Instant
Download Pdf
1. What is the first phase of the incident response lifecycle?
A. Containment
B. Identification
C. Preparation
D. Recovery
Answer: C
Rationale: Preparation ensures policies, tools, and training are in place
before an incident occurs.
2. Which document outlines procedures for handling security
incidents?
A. Acceptable Use Policy
B. Incident Response Plan
C. Disaster Recovery Plan
,D. Service Level Agreement
Answer: B
Rationale: The Incident Response Plan defines steps to detect, respond,
and recover from incidents.
3. What is the primary goal during the containment phase?
A. Identify attacker
B. Limit damage
C. Restore systems
D. Document findings
Answer: B
Rationale: Containment focuses on preventing the spread and
minimizing impact.
4. Which type of incident involves unauthorized access to data?
A. Denial of Service
B. Data Breach
C. Phishing
D. Malware
Answer: B
,Rationale: A data breach specifically involves exposure of sensitive
information.
5. What tool is commonly used to capture network traffic?
A. Antivirus
B. SIEM
C. Packet Sniffer
D. Firewall
Answer: C
Rationale: Packet sniffers analyze network traffic for suspicious activity.
6. What is the purpose of a SIEM system?
A. Encrypt data
B. Monitor and analyze logs
C. Block malware
D. Manage passwords
Answer: B
Rationale: SIEM aggregates and analyzes logs for security monitoring.
, 7. Which phase involves removing the cause of an incident?
A. Recovery
B. Eradication
C. Detection
D. Preparation
Answer: B
Rationale: Eradication eliminates threats such as malware or
vulnerabilities.
8. What is a common indicator of compromise (IOC)?
A. Strong password
B. Unusual outbound traffic
C. Software update
D. Backup completion
Answer: B
Rationale: Abnormal traffic often signals malicious activity.
9. Which type of malware replicates itself across networks?
A. Trojan
B. Worm
C. Spyware