🌍 All Study Guides📊 Dashboard📰 Blog💡 About
IBM Cybersecurity Analyst Professional Certificate • STUDY MODE

PRACTICE QUIZ

QUESTION 1 OF 30

Which three (3) of the following are phases of an incident response?

A
Containment, Eradication & RecoveryCorrect Answer
B
Post Incident Analysis & Lessons Learned
C
PreparationCorrect Answer
D
Detection & AnalysisCorrect Answer
QUESTION 2 OF 30

Which statement is true about an event?

A
An incident is defined as an event that takes place at a specific time and place.
B
An incident can lead to an event if it is determined to be a threat.
C
Multiple events of the same type are necessary before they can be considered an incident.
D
An event may be totally benign, like receiving an email.Correct Answer
QUESTION 3 OF 30

True or False: A robust automated incident response system should be able to detect and prevent loss from all incidents.

A
True
B
FalseCorrect Answer
QUESTION 4 OF 30

Which three (3) are common Incident Response Team models?

A
DistributedCorrect Answer
B
CoordinatingCorrect Answer
C
CentralCorrect Answer
D
Control
QUESTION 5 OF 30

A good automated Incident Response system should be able to detect which three (3) of these common attack vectors?

A
An unauthorized removable drive being attached to the network.Correct Answer
B
A brute force hacking attack.Correct Answer
C
A former employee using his knowledge at a competitor company.
D
An email phishing attack.Correct Answer
QUESTION 6 OF 30

Which three (3) of the following are components of an Incident Response Policy?

A
IR Policy testing responsibility.Correct Answer
B
IR Awareness training.
C
Means, tools and resources available.Correct Answer
D
Identity of IR team members.Correct Answer
QUESTION 7 OF 30

Contact information, Smart phones, and Secure storage facilities all belong to which Incident Response resource category?

A
Incident Handler Communications and Facilities.Correct Answer
B
Incident Analysis Resources.
C
Incident Post-Analysis Resources.
D
Incident Analysis Hardware and Software.
QUESTION 8 OF 30

Which three (3) of the following would be considered an incident detection precursor?

A
Detecting the use of a vulnerability scannerCorrect Answer
B
An announced threat against your organization from an activist group.Correct Answer
C
An application log showing numerous failed login attempts from an unknown remote system.
D
A vendor notice of a vulnerability to a product you own.Correct Answer
QUESTION 9 OF 30

Which type of monitoring system detects anomalous network traffic but typically does not take action beyond sending an alert to an administrator?

A
IPS
B
IDSCorrect Answer
C
DLP
D
SIEM
QUESTION 10 OF 30

True or False: The Incident Response team should keep their documentation as concise as possible so only the most important facts take up the attention of the team leadership.

A
True
B
FalseCorrect Answer
QUESTION 11 OF 30

What is the proper classification for a data breach that resulted in the exposure of sensitive personally identifiable information (PII)?

A
None
B
Privacy BreachCorrect Answer
C
Proprietary Breach
D
Integrity Loss
QUESTION 12 OF 30

What is the proper classification for the recovery effort from a breach if you can estimate the total effort required but it will require bringing in additional resources?

A
Regular
B
Extended
C
SupplementedCorrect Answer
D
Not Recoverable
QUESTION 13 OF 30

During which stage of a comprehensive Containment, Eradication & Recovery strategy does NIST recommend considering the following: Potential damange to and theft of resources, Need for evidence preservation, and Service availability?

A
ContainmentCorrect Answer
B
Eradication
C
Recovery
D
None of these
QUESTION 14 OF 30

Which Post Incident activity would include ascertaining exactly what happened and at what times? INCIDENT RESPONSE GRADED QUIZ

A
Utilizing collected data
B
Evidence retension
C
Lessons learned meetingCorrect Answer
D
Documentation review & update
QUESTION 15 OF 30

Select the missing phase of Incident Response: Preparation, _____, Containment, Eradication & Recovery, Post Incident Activity.

A
Detection and AnalysisCorrect Answer
B
Execution
C
Root Cause Analysis
D
Acquire Data
QUESTION 16 OF 30

Which statement is true about an incident?

A
An incident is an event that negatively affects IT systems.Correct Answer
B
An incident is any collection of 3 or more related events.
C
Incidents involved external actors while events involved internal actors.
D
An incident becomes an event if a threat is identified.
QUESTION 17 OF 30

True or False: A Coordinating Incidents Response Team provides advice and guidance to the Distributed IR teams in each department, but generally does not have specific authority over those teams.

A
TrueCorrect Answer
B
False
QUESTION 18 OF 30

Which Incident Response Team model describes a team that has authority over all aspects of IR within the entire organization?

A
Distributed
B
Coordinating
C
CentralCorrect Answer
D
Control
QUESTION 19 OF 30

In what way will having a set of predefined baseline questions will help you in the event of an incident?

A
Trap the bad actors.
B
Interrogate suspects.
C
Coordinate with other teams and the media.Correct Answer
D
Avoid events turning into Incidents.
QUESTION 20 OF 30

Incident Response team resources can be divided into which three (3) of the following categories?

A
Incident Analysis ResourcesCorrect Answer
B
Incident Handler Communications and FacilitiesCorrect Answer
C
Incident Post-Analysis Resources
D
Incident Analysis Hardware and SoftwareCorrect Answer
QUESTION 21 OF 30

Port lists, Documentation, and Cryptographic hashes all belong to which Incident Response resource category?

A
Incident Post-Analysis Resources
B
Incident Analysis ResourcesCorrect Answer
C
Incident Analysis Hardware and Software
D
Incident Handler Communications and Facilities
QUESTION 22 OF 30

Which three (3) of the following would be considered an incident detection indicator?

A
Detecting the use of a vulnerability scanner.
B
An application log showing numerous failed login attempts from an unknown remote system.Correct Answer
C
A significant deviation from typical network traffic flow patterns.Correct Answer
D
The discovery of a file containing unusual characters by a system administrator.Correct Answer
QUESTION 23 OF 30

Which type of monitoring system analyzes logs and events in real time?

A
IPS
B
IDS
C
DLP
D
SIEMCorrect Answer
QUESTION 24 OF 30

True or False: Highly detailed and thorough documentation is needed to support the analysis of current and future incidents.

A
TrueCorrect Answer
B
False
QUESTION 25 OF 30

What is the proper classification for a breach that results in sensitive or proprietary information being changed or deleted.

A
Proprietary Breach
B
Privacy Breach
C
Integrity LossCorrect Answer
D
None
QUESTION 26 OF 30

What is the proper classification for the recovery effort from a breach if sensitive data was stolen and posted on a public web site?

A
Not RecoverableCorrect Answer
B
Supplemented
C
Regular
D
Extended
QUESTION 27 OF 30

During which stage of a comprehensive Containment, Eradication & Recovery strategy does NIST recommend considering the following: Eliminate components of the incident, Disable compromised accounts, and Identify and mitigate vulnerabilities?

A
Containment
B
EradicationCorrect Answer
C
Recovery
D
None of these.
QUESTION 28 OF 30

Which Post Incident activity would include reviewing response times, which systems were impacted and other metrics associated with the incident?

A
Lessons learned meeting
B
Evidence retention
C
Documentation review & update
D
Utilizing collected dataCorrect Answer
QUESTION 29 OF 30

During which stage of a comprehensive Containment, Eradication & Recovery strategy does NIST recommend considering the following: Potential damange to and theft of resources, Need for evidence preservation, and Service availability?

A
ContainmentCorrect Answer
B
Eradication
C
Recovery
D
None of these
QUESTION 30 OF 30

Which Post Incident activity would include ascertaining exactly what happened and at what times?

A
Utilizing collected data
B
Evidence retension 
C
Lessons learned meetingCorrect Answer
D
Documentation review & update

Ready to test your recall?

Which three (3) of the following are phases of an incident response?

💡Select all 3 correct answers before submitting (0 of 3 selected).
A
Containment, Eradication & Recovery
B
Post Incident Analysis & Lessons Learned
C
Preparation
D
Detection & Analysis

How confident are you in this answer?