45 Incident Response questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.
Free to start: the 2-minute IT readiness check — six questions and a result.
D.Containment — removing the threat (malware, accounts, footholds) from affected systems
Answer + AI explanation with Pro
13. What is Eradication?
Junior
A.initial assessment to classify, prioritize, and assign incidents by severity and impact
B.the core security goals: Confidentiality, Integrity, and Availability
C.removing the threat (malware, accounts, footholds) from affected systems
D.forensic artifact (e.g. hash, IP, domain) signaling a system may be breached
Answer + AI explanation with Pro
14. Which term means: "removing the threat (malware, accounts, footholds) from affected systems"?
Junior
A.Mean Time To Detect (MTTD)
B.Eradication
C.Playbook
D.Threat hunting
Answer + AI explanation with Pro
15. Which statement is correct?
Junior
A.Eradication — proactively searching systems for hidden threats that evaded automated detection
B.Eradication — the core security goals: Confidentiality, Integrity, and Availability
C.Eradication — an event that actually or potentially compromises confidentiality, integrity, or availability
D.Eradication — removing the threat (malware, accounts, footholds) from affected systems
Answer + AI explanation with Pro
16. What is Recovery?
Junior
A.forensic artifact (e.g. hash, IP, domain) signaling a system may be breached
B.average time taken to discover that a security incident has occurred
C.restoring affected systems to normal operation and confirming they are clean
D.Security Orchestration, Automation, and Response platform automating response workflows
Answer + AI explanation with Pro
17. Which term means: "restoring affected systems to normal operation and confirming they are clean"?
Junior
A.Security incident
B.SIEM
C.Recovery
D.Post-incident review
Answer + AI explanation with Pro
18. Which statement is correct?
Junior
A.Recovery — an event that actually or potentially compromises confidentiality, integrity, or availability
B.Recovery — restoring affected systems to normal operation and confirming they are clean
C.Recovery — Security Information and Event Management system aggregating and correlating logs for detection and alerting
D.Recovery — average time taken to discover that a security incident has occurred
Answer + AI explanation with Pro
19. What is Chain of custody?
Mid
A.documented handling of evidence to preserve its integrity for investigation or legal use
B.removing the threat (malware, accounts, footholds) from affected systems
C.Security Orchestration, Automation, and Response platform automating response workflows
D.average time taken to discover that a security incident has occurred
Answer + AI explanation with Pro
20. Which term means: "documented handling of evidence to preserve its integrity for investigation or legal use"?
Mid
A.Security incident
B.CIA triad
C.Threat hunting
D.Chain of custody
Answer + AI explanation with Pro
21. Which statement is correct?
Mid
A.Chain of custody — initial assessment to classify, prioritize, and assign incidents by severity and impact
B.Chain of custody — predefined step-by-step procedure for responding to a specific type of incident
C.Chain of custody — Security Information and Event Management system aggregating and correlating logs for detection and alerting
D.Chain of custody — documented handling of evidence to preserve its integrity for investigation or legal use
Answer + AI explanation with Pro
22. What is SIEM?
Mid
A.Security Information and Event Management system aggregating and correlating logs for detection and alerting
B.the core security goals: Confidentiality, Integrity, and Availability
C.blameless analysis after an incident to capture lessons and improve defenses
D.an event that actually or potentially compromises confidentiality, integrity, or availability
Answer + AI explanation with Pro
23. Which term means: "Security Information and Event Management system aggregating and correlating logs for detection and alerting"?
Mid
A.Mean Time To Detect (MTTD)
B.Post-incident review
C.Tabletop exercise
D.SIEM
Answer + AI explanation with Pro
24. Which statement is correct?
Mid
A.SIEM — Security Information and Event Management system aggregating and correlating logs for detection and alerting
B.SIEM — discussion-based drill where teams walk through their response to a hypothetical incident
C.SIEM — documented handling of evidence to preserve its integrity for investigation or legal use
D.SIEM — average time taken to discover that a security incident has occurred
Answer + AI explanation with Pro
25. What is Playbook?
Mid
A.removing the threat (malware, accounts, footholds) from affected systems
B.predefined step-by-step procedure for responding to a specific type of incident
C.forensic artifact (e.g. hash, IP, domain) signaling a system may be breached
D.blameless analysis after an incident to capture lessons and improve defenses
Answer + AI explanation with Pro
26. Which term means: "predefined step-by-step procedure for responding to a specific type of incident"?
Mid
A.Recovery
B.CIA triad
C.Post-incident review
D.Playbook
Answer + AI explanation with Pro
27. Which statement is correct?
Mid
A.Playbook — predefined step-by-step procedure for responding to a specific type of incident
B.Playbook — restoring affected systems to normal operation and confirming they are clean
C.Playbook — the core security goals: Confidentiality, Integrity, and Availability
D.Playbook — average time taken to discover that a security incident has occurred
Answer + AI explanation with Pro
28. What is Mean Time To Detect (MTTD)?
Mid
A.average time taken to discover that a security incident has occurred
B.proactively searching systems for hidden threats that evaded automated detection
C.removing the threat (malware, accounts, footholds) from affected systems
D.restoring affected systems to normal operation and confirming they are clean
Answer + AI explanation with Pro
29. Which term means: "average time taken to discover that a security incident has occurred"?
Mid
A.Containment
B.Threat hunting
C.Recovery
D.Mean Time To Detect (MTTD)
Answer + AI explanation with Pro
30. Which statement is correct?
Mid
A.Mean Time To Detect (MTTD) — predefined step-by-step procedure for responding to a specific type of incident
B.Mean Time To Detect (MTTD) — limiting the scope and spread of an incident to prevent further damage
C.Mean Time To Detect (MTTD) — proactively searching systems for hidden threats that evaded automated detection
D.Mean Time To Detect (MTTD) — average time taken to discover that a security incident has occurred
Answer + AI explanation with Pro
Showing 30 of 45 Incident Response questions — the full set, with answers, explanations and an AI tutor on every question, is inside.
Free to start
Start with a free readiness check
Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Incident Response question come with Pro.