Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 36 pages
Exam (elaborations)

Incident Response Technician Level II Certification Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A | Instant Download Pdf

Document preview thumbnail
Preview 4 out of 36 pages

Incident Response Technician Level II Certification Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A | Instant Download Pdf

Content preview

Incident Response Technician Level II
Certification Questions And Correct
Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant Download
Pdf

1. What is the primary goal of incident response?
• A. Prevent all attacks
• B. Eliminate users
• C. Minimize damage and recover quickly
• D. Increase system downtime
Rationale: The main objective of incident response is to limit the impact of a
security incident and restore normal operations as efficiently as possible.


2. Which phase follows identification in the incident response lifecycle?
• A. Preparation
• B. Containment
• C. Recovery
• D. Lessons learned
Rationale: After identifying an incident, containment is performed immediately to
stop its spread and prevent further damage to systems and data.

,3. What tool is commonly used to capture network traffic?
• A. Antivirus
• B. SIEM
• C. Packet sniffer
• D. Firewall
Rationale: Packet sniffers like Wireshark capture and analyze network packets
traversing a network, making them essential for network traffic analysis during
incident response.


4. What does SIEM stand for?
• A. System Internal Event Monitor
• B. Security Incident Email Manager
• C. Security Information and Event Management
• D. Secure Internal Encryption Module
Rationale: SIEM aggregates and analyzes security data from multiple sources in real
time, providing centralized visibility into security events.


5. Which type of attack floods a network with traffic to overwhelm resources?
• A. Phishing
• B. Malware
• C. DDoS
• D. Spoofing

,Rationale: Distributed Denial of Service (DDoS) attacks overwhelm systems with
massive volumes of traffic, rendering services unavailable to legitimate users.


6. What is the purpose of creating a forensic image?
• A. Backup storage
• B. Preserve evidence integrity
• C. Speed up systems
• D. Encrypt files
Rationale: Forensic imaging ensures that data is preserved exactly as it existed at
the time of acquisition, without alteration, to maintain evidentiary integrity.


7. Which protocol is commonly used for secure remote access?
• A. FTP
• B. HTTP
• C. SSH
• D. Telnet
Rationale: SSH (Secure Shell) encrypts remote communication securely, protecting
credentials and data from interception during remote administrative access.


8. What is an IOC in cybersecurity?
• A. Internal Operation Code
• B. Indicator of Compromise
• C. Internet Operating Console
• D. Integrated Output Channel

, Rationale: Indicators of Compromise (IOCs) are forensic artifacts or pieces of
evidence that suggest a system has been compromised or is under attack.


9. What is data exfiltration?
• A. Internal Operation Code verification
• B. Data backup creation
• C. Unauthorized data transfer
• D. Data deletion
Rationale: Exfiltration involves the unauthorized transfer of data from an
organization's systems to an external destination, typically by an attacker.


10. Which tool correlates logs from multiple sources to identify security incidents?
• A. IDS
• B. Firewall
• C. SIEM
• D. VPN
Rationale: SIEM platforms aggregate and correlate logs from diverse sources,
enabling security teams to identify patterns and detect potential incidents.


11. What is a zero-day vulnerability?
• A. Patched flaw
• B. Known exploit
• C. Unknown vulnerability
• D. Expired certificate

Document information

Uploaded on
August 7, 2026
Number of pages
36
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$23.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
masterystudyhub
5.0
(1)
Sold
24
Followers
1
Items
8646
Last sold
16 hours ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions