Incident Response Technician Level I
Questions And Correct Answers (Verified
Answers) Plus Rationales 2026 Q&A |
Instant Download Pdf
1. What is the primary objective of incident response?
A) To assign blame for security incidents
B) To contain and minimize damage from security incidents
C) To increase system complexity
D) To reduce IT staffing costs
Answer: B
Rationale: The primary objective of incident response is to contain and minimize
damage from security incidents while ensuring business continuity. Incident
response focuses on protecting organizational assets, not assigning blame or
reducing costs.
2. Which framework is most commonly used as a baseline for incident response
processes?
A) ITIL Framework
B) COBIT Framework
C) NIST SP 800-61
D) ISO 9001
Answer: C
Rationale: The NIST SP 800-61 (Computer Security Incident Handling Guide) is the
most widely adopted framework for incident response. It provides comprehensive
,guidelines for establishing and maintaining an effective incident response
capability.
3. What is the correct order of the incident response lifecycle phases according to
NIST?
A) Containment, Eradication, Recovery, Preparation, Detection and Analysis, Post-
Incident Activity
B) Preparation, Detection and Analysis, Containment, Eradication and Recovery,
Post-Incident Activity
C) Detection, Analysis, Containment, Recovery, Post-Incident, Preparation
D) Preparation, Detection, Analysis, Recovery, Eradication, Post-Incident
Answer: B
Rationale: The NIST incident response lifecycle follows this specific order:
Preparation, Detection and Analysis, Containment, Eradication and Recovery, and
Post-Incident Activity. This sequence ensures systematic handling of incidents.
4. Which type of incident response team model has team members who work on
incident response as their primary responsibility?
A) Fully centralized
B) Partially distributed
C) Fully distributed
D) Virtual
Answer: A
Rationale: A fully centralized team model consists of dedicated incident response
personnel who work exclusively on incident response activities. They are the
primary responders for all security incidents.
5. What is the first step in the preparation phase of incident response?
A) Building an incident response team
,B) Developing incident response policies
C) Acquiring forensic tools
D) Conducting tabletop exercises
Answer: B
Rationale: Developing incident response policies is the foundational first step in the
preparation phase. These policies establish authority, define roles and
responsibilities, and provide the framework for all subsequent incident response
activities.
6. Which document should be created to define the step-by-step actions to be
taken during specific types of incidents?
A) Incident response policy
B) Incident response plan
C) Incident response playbook
D) Business continuity plan
Answer: C
Rationale: An incident response playbook provides specific, step-by-step procedures
for handling particular types of incidents. While the plan is broader, playbooks offer
detailed technical instructions for common incident scenarios.
7. What is the recommended method for detecting security incidents?
A) Relying solely on user reports
B) Implementing multiple detection layers including IDS/IPS, SIEM, and antivirus
C) Conducting quarterly security audits
D) Monitoring only external network traffic
Answer: B
Rationale: Effective detection requires multiple layers of security monitoring
including Intrusion Detection Systems, Security Information and Event Management
tools, antivirus software, and other monitoring solutions. A defense-in-depth
approach provides better detection coverage.
, 8. What is the difference between an event and an incident?
A) Events are always malicious, incidents are accidental
B) An event is any observable occurrence, while an incident is an event that
negatively impacts security
C) Events occur only at the network level
D) There is no difference between events and incidents
Answer: B
Rationale: An event is any observable occurrence in a system or network, while an
incident is specifically an event that violates security policies or poses a threat to
information security. Not all events become incidents.
9. Which of the following is an example of a false positive in incident detection?
A) A legitimate login attempt being flagged as suspicious
B) An actual malware infection being detected
C) A successful phishing attack being identified
D) A DDoS attack being blocked by the firewall
Answer: A
Rationale: A false positive occurs when a detection system incorrectly identifies
legitimate activity as malicious. A legitimate login flagged as suspicious represents
an erroneous alert that wastes resources and can lead to alert fatigue.
10. What is triage in the context of incident response?
A) The final step of incident response
B) The process of prioritizing incidents based on severity and impact
C) The act of deleting all evidence
D) The method of encrypting compromised systems
Answer: B
Rationale: Triage is the critical process of assessing and prioritizing incidents based
Questions And Correct Answers (Verified
Answers) Plus Rationales 2026 Q&A |
Instant Download Pdf
1. What is the primary objective of incident response?
A) To assign blame for security incidents
B) To contain and minimize damage from security incidents
C) To increase system complexity
D) To reduce IT staffing costs
Answer: B
Rationale: The primary objective of incident response is to contain and minimize
damage from security incidents while ensuring business continuity. Incident
response focuses on protecting organizational assets, not assigning blame or
reducing costs.
2. Which framework is most commonly used as a baseline for incident response
processes?
A) ITIL Framework
B) COBIT Framework
C) NIST SP 800-61
D) ISO 9001
Answer: C
Rationale: The NIST SP 800-61 (Computer Security Incident Handling Guide) is the
most widely adopted framework for incident response. It provides comprehensive
,guidelines for establishing and maintaining an effective incident response
capability.
3. What is the correct order of the incident response lifecycle phases according to
NIST?
A) Containment, Eradication, Recovery, Preparation, Detection and Analysis, Post-
Incident Activity
B) Preparation, Detection and Analysis, Containment, Eradication and Recovery,
Post-Incident Activity
C) Detection, Analysis, Containment, Recovery, Post-Incident, Preparation
D) Preparation, Detection, Analysis, Recovery, Eradication, Post-Incident
Answer: B
Rationale: The NIST incident response lifecycle follows this specific order:
Preparation, Detection and Analysis, Containment, Eradication and Recovery, and
Post-Incident Activity. This sequence ensures systematic handling of incidents.
4. Which type of incident response team model has team members who work on
incident response as their primary responsibility?
A) Fully centralized
B) Partially distributed
C) Fully distributed
D) Virtual
Answer: A
Rationale: A fully centralized team model consists of dedicated incident response
personnel who work exclusively on incident response activities. They are the
primary responders for all security incidents.
5. What is the first step in the preparation phase of incident response?
A) Building an incident response team
,B) Developing incident response policies
C) Acquiring forensic tools
D) Conducting tabletop exercises
Answer: B
Rationale: Developing incident response policies is the foundational first step in the
preparation phase. These policies establish authority, define roles and
responsibilities, and provide the framework for all subsequent incident response
activities.
6. Which document should be created to define the step-by-step actions to be
taken during specific types of incidents?
A) Incident response policy
B) Incident response plan
C) Incident response playbook
D) Business continuity plan
Answer: C
Rationale: An incident response playbook provides specific, step-by-step procedures
for handling particular types of incidents. While the plan is broader, playbooks offer
detailed technical instructions for common incident scenarios.
7. What is the recommended method for detecting security incidents?
A) Relying solely on user reports
B) Implementing multiple detection layers including IDS/IPS, SIEM, and antivirus
C) Conducting quarterly security audits
D) Monitoring only external network traffic
Answer: B
Rationale: Effective detection requires multiple layers of security monitoring
including Intrusion Detection Systems, Security Information and Event Management
tools, antivirus software, and other monitoring solutions. A defense-in-depth
approach provides better detection coverage.
, 8. What is the difference between an event and an incident?
A) Events are always malicious, incidents are accidental
B) An event is any observable occurrence, while an incident is an event that
negatively impacts security
C) Events occur only at the network level
D) There is no difference between events and incidents
Answer: B
Rationale: An event is any observable occurrence in a system or network, while an
incident is specifically an event that violates security policies or poses a threat to
information security. Not all events become incidents.
9. Which of the following is an example of a false positive in incident detection?
A) A legitimate login attempt being flagged as suspicious
B) An actual malware infection being detected
C) A successful phishing attack being identified
D) A DDoS attack being blocked by the firewall
Answer: A
Rationale: A false positive occurs when a detection system incorrectly identifies
legitimate activity as malicious. A legitimate login flagged as suspicious represents
an erroneous alert that wastes resources and can lead to alert fatigue.
10. What is triage in the context of incident response?
A) The final step of incident response
B) The process of prioritizing incidents based on severity and impact
C) The act of deleting all evidence
D) The method of encrypting compromised systems
Answer: B
Rationale: Triage is the critical process of assessing and prioritizing incidents based