1. Which type of security testing would best help identify weaknesses
in a web application?
A. Penetration testing
B. Compliance auditing
C. Social engineering
D. Physical security assessments
Answer: A) Penetration testing
Rationale: Penetration testing simulates attacks on a system, including
web applications, to identify and address vulnerabilities that could be
exploited by attackers.
2. What is the primary objective of an Incident Response (IR) team
during a security incident?
A. To identify and stop the attack as quickly as possible
B. To collect evidence for legal prosecution
C. To ensure the business remains operational at all costs
D. To report the incident to regulatory authorities immediately
Answer: A) To identify and stop the attack as quickly as possible
Rationale: The primary goal of the IR team during a security incident
is to quickly identify the attack and stop it to prevent further damage,
followed by containment and remediation actions.
,3. Which type of backup method involves only copying files that have
changed since the last full backup?
A. Full backup
B. Incremental backup
C. Differential backup
D. Snapshot backup
Answer: B) Incremental backup
Rationale: Incremental backups only copy the files that have changed
since the last full or incremental backup, making them efficient in terms
of storage space and time.
4. What is the primary focus of a Business Continuity Plan (BCP)?
A. To monitor the effectiveness of security policies
B. To ensure essential business operations can continue during or after
a disaster
C. To prevent malware infections
D. To audit user access privileges
Answer: B) To ensure essential business operations can continue
during or after a disaster
Rationale: A Business Continuity Plan ensures that an organization can
maintain critical business operations even in the event of a disaster or
disruptive incident.
, 5. What should be the first step in an incident response plan when a
breach is detected?
A. Contain the incident to prevent further damage
B. Notify the public about the breach
C. Analyze the breach to determine its cause
D. Restore affected systems from backups
Answer: A) Contain the incident to prevent further damage
Rationale: Containing the incident immediately prevents further
damage and limits the spread of the breach, enabling the incident
response team to address the issue effectively.
6. In which phase of the incident response lifecycle is evidence collected
and preserved?
A. Detection and Analysis
B. Containment, Eradication, and Recovery
C. Post-Incident Activity
D. Identification
Answer: A) Detection and Analysis
Rationale: The collection and preservation of evidence occur during the
Detection and Analysis phase, where the incident is confirmed and
forensic data is gathered for further investigation.
in a web application?
A. Penetration testing
B. Compliance auditing
C. Social engineering
D. Physical security assessments
Answer: A) Penetration testing
Rationale: Penetration testing simulates attacks on a system, including
web applications, to identify and address vulnerabilities that could be
exploited by attackers.
2. What is the primary objective of an Incident Response (IR) team
during a security incident?
A. To identify and stop the attack as quickly as possible
B. To collect evidence for legal prosecution
C. To ensure the business remains operational at all costs
D. To report the incident to regulatory authorities immediately
Answer: A) To identify and stop the attack as quickly as possible
Rationale: The primary goal of the IR team during a security incident
is to quickly identify the attack and stop it to prevent further damage,
followed by containment and remediation actions.
,3. Which type of backup method involves only copying files that have
changed since the last full backup?
A. Full backup
B. Incremental backup
C. Differential backup
D. Snapshot backup
Answer: B) Incremental backup
Rationale: Incremental backups only copy the files that have changed
since the last full or incremental backup, making them efficient in terms
of storage space and time.
4. What is the primary focus of a Business Continuity Plan (BCP)?
A. To monitor the effectiveness of security policies
B. To ensure essential business operations can continue during or after
a disaster
C. To prevent malware infections
D. To audit user access privileges
Answer: B) To ensure essential business operations can continue
during or after a disaster
Rationale: A Business Continuity Plan ensures that an organization can
maintain critical business operations even in the event of a disaster or
disruptive incident.
, 5. What should be the first step in an incident response plan when a
breach is detected?
A. Contain the incident to prevent further damage
B. Notify the public about the breach
C. Analyze the breach to determine its cause
D. Restore affected systems from backups
Answer: A) Contain the incident to prevent further damage
Rationale: Containing the incident immediately prevents further
damage and limits the spread of the breach, enabling the incident
response team to address the issue effectively.
6. In which phase of the incident response lifecycle is evidence collected
and preserved?
A. Detection and Analysis
B. Containment, Eradication, and Recovery
C. Post-Incident Activity
D. Identification
Answer: A) Detection and Analysis
Rationale: The collection and preservation of evidence occur during the
Detection and Analysis phase, where the incident is confirmed and
forensic data is gathered for further investigation.