1. What is Security incident ? Junior A. restoring affected systems to normal operation and confirming they are clean B. blameless analysis after an incident to capture lessons and improve defenses C. an event that actually or potentially compromises confidentiality, integrity, or availability D. predefined step-by-step procedure for responding to a specific type of incident Reveal the answer + AI explanation — free account
2. Which term means: "an event that actually or potentially compromises confidentiality, integrity, or availability"? Junior A. Threat hunting B. CIA triad C. Security incident D. Post-incident review Reveal the answer + AI explanation — free account
3. Which statement is correct? Junior A. Security incident — restoring affected systems to normal operation and confirming they are clean B. Security incident — proactively searching systems for hidden threats that evaded automated detection C. Security incident — an event that actually or potentially compromises confidentiality, integrity, or availability D. Security incident — predefined step-by-step procedure for responding to a specific type of incident Reveal the answer + AI explanation — free account
4. What is CIA triad ? Junior A. average time taken to discover that a security incident has occurred B. the core security goals: Confidentiality, Integrity, and Availability C. discussion-based drill where teams walk through their response to a hypothetical incident D. proactively searching systems for hidden threats that evaded automated detection Reveal the answer + AI explanation — free account
5. Which term means: "the core security goals: Confidentiality, Integrity, and Availability"? Junior A. Indicator of Compromise (IoC) B. Security incident C. Containment D. CIA triad Reveal the answer + AI explanation — free account
6. Which statement is correct? Junior A. CIA triad — the core security goals: Confidentiality, Integrity, and Availability B. CIA triad — limiting the scope and spread of an incident to prevent further damage C. CIA triad — discussion-based drill where teams walk through their response to a hypothetical incident D. CIA triad — an event that actually or potentially compromises confidentiality, integrity, or availability Reveal the answer + AI explanation — free account
7. What is Indicator of Compromise (IoC) ? Junior A. removing the threat (malware, accounts, footholds) from affected systems B. forensic artifact (e.g. hash, IP, domain) signaling a system may be breached C. blameless analysis after an incident to capture lessons and improve defenses D. average time taken to discover that a security incident has occurred Reveal the answer + AI explanation — free account
8. Which term means: "forensic artifact (e.g. hash, IP, domain) signaling a system may be breached"? Junior A. Threat hunting B. Containment C. Indicator of Compromise (IoC) D. Tabletop exercise Reveal the answer + AI explanation — free account
9. Which statement is correct? Junior A. Indicator of Compromise (IoC) — forensic artifact (e.g. hash, IP, domain) signaling a system may be breached B. Indicator of Compromise (IoC) — Security Information and Event Management system aggregating and correlating logs for detection and alerting C. Indicator of Compromise (IoC) — discussion-based drill where teams walk through their response to a hypothetical incident D. Indicator of Compromise (IoC) — blameless analysis after an incident to capture lessons and improve defenses Reveal the answer + AI explanation — free account
10. What is Containment ? Junior A. limiting the scope and spread of an incident to prevent further damage B. discussion-based drill where teams walk through their response to a hypothetical incident C. predefined step-by-step procedure for responding to a specific type of incident D. initial assessment to classify, prioritize, and assign incidents by severity and impact Reveal the answer + AI explanation — free account
11. Which term means: "limiting the scope and spread of an incident to prevent further damage"? Junior A. Containment B. Mean Time To Detect (MTTD) C. Chain of custody D. Threat hunting Reveal the answer + AI explanation — free account
12. Which statement is correct? Junior A. Containment — limiting the scope and spread of an incident to prevent further damage B. Containment — the core security goals: Confidentiality, Integrity, and Availability C. Containment — Security Orchestration, Automation, and Response platform automating response workflows D. Containment — removing the threat (malware, accounts, footholds) from affected systems Reveal the answer + AI explanation — free account
13. What is Eradication ? Junior A. initial assessment to classify, prioritize, and assign incidents by severity and impact B. the core security goals: Confidentiality, Integrity, and Availability C. removing the threat (malware, accounts, footholds) from affected systems D. forensic artifact (e.g. hash, IP, domain) signaling a system may be breached Reveal the answer + AI explanation — free account
14. Which term means: "removing the threat (malware, accounts, footholds) from affected systems"? Junior A. Mean Time To Detect (MTTD) B. Eradication C. Playbook D. Threat hunting Reveal the answer + AI explanation — free account
15. Which statement is correct? Junior A. Eradication — proactively searching systems for hidden threats that evaded automated detection B. Eradication — the core security goals: Confidentiality, Integrity, and Availability C. Eradication — an event that actually or potentially compromises confidentiality, integrity, or availability D. Eradication — removing the threat (malware, accounts, footholds) from affected systems Reveal the answer + AI explanation — free account
16. What is Recovery ? Junior A. forensic artifact (e.g. hash, IP, domain) signaling a system may be breached B. average time taken to discover that a security incident has occurred C. restoring affected systems to normal operation and confirming they are clean D. Security Orchestration, Automation, and Response platform automating response workflows Reveal the answer + AI explanation — free account
17. Which term means: "restoring affected systems to normal operation and confirming they are clean"? Junior A. Security incident B. SIEM C. Recovery D. Post-incident review Reveal the answer + AI explanation — free account
18. Which statement is correct? Junior A. Recovery — an event that actually or potentially compromises confidentiality, integrity, or availability B. Recovery — restoring affected systems to normal operation and confirming they are clean C. Recovery — Security Information and Event Management system aggregating and correlating logs for detection and alerting D. Recovery — average time taken to discover that a security incident has occurred Reveal the answer + AI explanation — free account
19. What is Chain of custody ? Mid A. documented handling of evidence to preserve its integrity for investigation or legal use B. removing the threat (malware, accounts, footholds) from affected systems C. Security Orchestration, Automation, and Response platform automating response workflows D. average time taken to discover that a security incident has occurred Reveal the answer + AI explanation — free account
20. Which term means: "documented handling of evidence to preserve its integrity for investigation or legal use"? Mid A. Security incident B. CIA triad C. Threat hunting D. Chain of custody Reveal the answer + AI explanation — free account
21. Which statement is correct? Mid A. Chain of custody — initial assessment to classify, prioritize, and assign incidents by severity and impact B. Chain of custody — predefined step-by-step procedure for responding to a specific type of incident C. Chain of custody — Security Information and Event Management system aggregating and correlating logs for detection and alerting D. Chain of custody — documented handling of evidence to preserve its integrity for investigation or legal use Reveal the answer + AI explanation — free account
22. What is SIEM ? Mid A. Security Information and Event Management system aggregating and correlating logs for detection and alerting B. the core security goals: Confidentiality, Integrity, and Availability C. blameless analysis after an incident to capture lessons and improve defenses D. an event that actually or potentially compromises confidentiality, integrity, or availability Reveal the answer + AI explanation — free account
23. Which term means: "Security Information and Event Management system aggregating and correlating logs for detection and alerting"? Mid A. Mean Time To Detect (MTTD) B. Post-incident review C. Tabletop exercise D. SIEM Reveal the answer + AI explanation — free account
24. Which statement is correct? Mid A. SIEM — Security Information and Event Management system aggregating and correlating logs for detection and alerting B. SIEM — discussion-based drill where teams walk through their response to a hypothetical incident C. SIEM — documented handling of evidence to preserve its integrity for investigation or legal use D. SIEM — average time taken to discover that a security incident has occurred Reveal the answer + AI explanation — free account
25. What is Playbook ? Mid A. removing the threat (malware, accounts, footholds) from affected systems B. predefined step-by-step procedure for responding to a specific type of incident C. forensic artifact (e.g. hash, IP, domain) signaling a system may be breached D. blameless analysis after an incident to capture lessons and improve defenses Reveal the answer + AI explanation — free account
26. Which term means: "predefined step-by-step procedure for responding to a specific type of incident"? Mid A. Recovery B. CIA triad C. Post-incident review D. Playbook Reveal the answer + AI explanation — free account
27. Which statement is correct? Mid A. Playbook — predefined step-by-step procedure for responding to a specific type of incident B. Playbook — restoring affected systems to normal operation and confirming they are clean C. Playbook — the core security goals: Confidentiality, Integrity, and Availability D. Playbook — average time taken to discover that a security incident has occurred Reveal the answer + AI explanation — free account
28. What is Mean Time To Detect (MTTD) ? Mid A. average time taken to discover that a security incident has occurred B. proactively searching systems for hidden threats that evaded automated detection C. removing the threat (malware, accounts, footholds) from affected systems D. restoring affected systems to normal operation and confirming they are clean Reveal the answer + AI explanation — free account
29. Which term means: "average time taken to discover that a security incident has occurred"? Mid A. Containment B. Threat hunting C. Recovery D. Mean Time To Detect (MTTD) Reveal the answer + AI explanation — free account
30. Which statement is correct? Mid A. Mean Time To Detect (MTTD) — predefined step-by-step procedure for responding to a specific type of incident B. Mean Time To Detect (MTTD) — limiting the scope and spread of an incident to prevent further damage C. Mean Time To Detect (MTTD) — proactively searching systems for hidden threats that evaded automated detection D. Mean Time To Detect (MTTD) — average time taken to discover that a security incident has occurred Reveal the answer + AI explanation — free accountShowing 30 of 45 Incident Response questions — the full set, with answers, explanations and an AI tutor on every question, is inside.