Incident Response interview questions

45 real Incident Response questions from the Security bank, as asked in Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd — free to start.

1. What is Security incident?

Junior
  1. A.restoring affected systems to normal operation and confirming they are clean
  2. B.blameless analysis after an incident to capture lessons and improve defenses
  3. C.an event that actually or potentially compromises confidentiality, integrity, or availability
  4. D.predefined step-by-step procedure for responding to a specific type of incident
Reveal the answer + AI explanation — free account

3. Which statement is correct?

Junior
  1. A.Security incident — restoring affected systems to normal operation and confirming they are clean
  2. B.Security incident — proactively searching systems for hidden threats that evaded automated detection
  3. C.Security incident — an event that actually or potentially compromises confidentiality, integrity, or availability
  4. D.Security incident — predefined step-by-step procedure for responding to a specific type of incident
Reveal the answer + AI explanation — free account

4. What is CIA triad?

Junior
  1. A.average time taken to discover that a security incident has occurred
  2. B.the core security goals: Confidentiality, Integrity, and Availability
  3. C.discussion-based drill where teams walk through their response to a hypothetical incident
  4. D.proactively searching systems for hidden threats that evaded automated detection
Reveal the answer + AI explanation — free account

6. Which statement is correct?

Junior
  1. A.CIA triad — the core security goals: Confidentiality, Integrity, and Availability
  2. B.CIA triad — limiting the scope and spread of an incident to prevent further damage
  3. C.CIA triad — discussion-based drill where teams walk through their response to a hypothetical incident
  4. D.CIA triad — an event that actually or potentially compromises confidentiality, integrity, or availability
Reveal the answer + AI explanation — free account

7. What is Indicator of Compromise (IoC)?

Junior
  1. A.removing the threat (malware, accounts, footholds) from affected systems
  2. B.forensic artifact (e.g. hash, IP, domain) signaling a system may be breached
  3. C.blameless analysis after an incident to capture lessons and improve defenses
  4. D.average time taken to discover that a security incident has occurred
Reveal the answer + AI explanation — free account

9. Which statement is correct?

Junior
  1. A.Indicator of Compromise (IoC) — forensic artifact (e.g. hash, IP, domain) signaling a system may be breached
  2. B.Indicator of Compromise (IoC) — Security Information and Event Management system aggregating and correlating logs for detection and alerting
  3. C.Indicator of Compromise (IoC) — discussion-based drill where teams walk through their response to a hypothetical incident
  4. D.Indicator of Compromise (IoC) — blameless analysis after an incident to capture lessons and improve defenses
Reveal the answer + AI explanation — free account

10. What is Containment?

Junior
  1. A.limiting the scope and spread of an incident to prevent further damage
  2. B.discussion-based drill where teams walk through their response to a hypothetical incident
  3. C.predefined step-by-step procedure for responding to a specific type of incident
  4. D.initial assessment to classify, prioritize, and assign incidents by severity and impact
Reveal the answer + AI explanation — free account

12. Which statement is correct?

Junior
  1. A.Containment — limiting the scope and spread of an incident to prevent further damage
  2. B.Containment — the core security goals: Confidentiality, Integrity, and Availability
  3. C.Containment — Security Orchestration, Automation, and Response platform automating response workflows
  4. D.Containment — removing the threat (malware, accounts, footholds) from affected systems
Reveal the answer + AI explanation — free account

13. What is Eradication?

Junior
  1. A.initial assessment to classify, prioritize, and assign incidents by severity and impact
  2. B.the core security goals: Confidentiality, Integrity, and Availability
  3. C.removing the threat (malware, accounts, footholds) from affected systems
  4. D.forensic artifact (e.g. hash, IP, domain) signaling a system may be breached
Reveal the answer + AI explanation — free account

15. Which statement is correct?

Junior
  1. A.Eradication — proactively searching systems for hidden threats that evaded automated detection
  2. B.Eradication — the core security goals: Confidentiality, Integrity, and Availability
  3. C.Eradication — an event that actually or potentially compromises confidentiality, integrity, or availability
  4. D.Eradication — removing the threat (malware, accounts, footholds) from affected systems
Reveal the answer + AI explanation — free account

16. What is Recovery?

Junior
  1. A.forensic artifact (e.g. hash, IP, domain) signaling a system may be breached
  2. B.average time taken to discover that a security incident has occurred
  3. C.restoring affected systems to normal operation and confirming they are clean
  4. D.Security Orchestration, Automation, and Response platform automating response workflows
Reveal the answer + AI explanation — free account

18. Which statement is correct?

Junior
  1. A.Recovery — an event that actually or potentially compromises confidentiality, integrity, or availability
  2. B.Recovery — restoring affected systems to normal operation and confirming they are clean
  3. C.Recovery — Security Information and Event Management system aggregating and correlating logs for detection and alerting
  4. D.Recovery — average time taken to discover that a security incident has occurred
Reveal the answer + AI explanation — free account

19. What is Chain of custody?

Mid
  1. A.documented handling of evidence to preserve its integrity for investigation or legal use
  2. B.removing the threat (malware, accounts, footholds) from affected systems
  3. C.Security Orchestration, Automation, and Response platform automating response workflows
  4. D.average time taken to discover that a security incident has occurred
Reveal the answer + AI explanation — free account

21. Which statement is correct?

Mid
  1. A.Chain of custody — initial assessment to classify, prioritize, and assign incidents by severity and impact
  2. B.Chain of custody — predefined step-by-step procedure for responding to a specific type of incident
  3. C.Chain of custody — Security Information and Event Management system aggregating and correlating logs for detection and alerting
  4. D.Chain of custody — documented handling of evidence to preserve its integrity for investigation or legal use
Reveal the answer + AI explanation — free account

22. What is SIEM?

Mid
  1. A.Security Information and Event Management system aggregating and correlating logs for detection and alerting
  2. B.the core security goals: Confidentiality, Integrity, and Availability
  3. C.blameless analysis after an incident to capture lessons and improve defenses
  4. D.an event that actually or potentially compromises confidentiality, integrity, or availability
Reveal the answer + AI explanation — free account

23. Which term means: "Security Information and Event Management system aggregating and correlating logs for detection and alerting"?

Mid
  1. A.Mean Time To Detect (MTTD)
  2. B.Post-incident review
  3. C.Tabletop exercise
  4. D.SIEM
Reveal the answer + AI explanation — free account

24. Which statement is correct?

Mid
  1. A.SIEM — Security Information and Event Management system aggregating and correlating logs for detection and alerting
  2. B.SIEM — discussion-based drill where teams walk through their response to a hypothetical incident
  3. C.SIEM — documented handling of evidence to preserve its integrity for investigation or legal use
  4. D.SIEM — average time taken to discover that a security incident has occurred
Reveal the answer + AI explanation — free account

25. What is Playbook?

Mid
  1. A.removing the threat (malware, accounts, footholds) from affected systems
  2. B.predefined step-by-step procedure for responding to a specific type of incident
  3. C.forensic artifact (e.g. hash, IP, domain) signaling a system may be breached
  4. D.blameless analysis after an incident to capture lessons and improve defenses
Reveal the answer + AI explanation — free account

27. Which statement is correct?

Mid
  1. A.Playbook — predefined step-by-step procedure for responding to a specific type of incident
  2. B.Playbook — restoring affected systems to normal operation and confirming they are clean
  3. C.Playbook — the core security goals: Confidentiality, Integrity, and Availability
  4. D.Playbook — average time taken to discover that a security incident has occurred
Reveal the answer + AI explanation — free account

28. What is Mean Time To Detect (MTTD)?

Mid
  1. A.average time taken to discover that a security incident has occurred
  2. B.proactively searching systems for hidden threats that evaded automated detection
  3. C.removing the threat (malware, accounts, footholds) from affected systems
  4. D.restoring affected systems to normal operation and confirming they are clean
Reveal the answer + AI explanation — free account

30. Which statement is correct?

Mid
  1. A.Mean Time To Detect (MTTD) — predefined step-by-step procedure for responding to a specific type of incident
  2. B.Mean Time To Detect (MTTD) — limiting the scope and spread of an incident to prevent further damage
  3. C.Mean Time To Detect (MTTD) — proactively searching systems for hidden threats that evaded automated detection
  4. D.Mean Time To Detect (MTTD) — average time taken to discover that a security incident has occurred
Reveal the answer + AI explanation — free account

Showing 30 of 45 Incident Response questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Answers, AI explanations, and a scored voice mock interview

Sign up free to check your answers with explanations, ask the AI tutor anything on any question, and take one full AI mock interview — scored like a real panel.

Practice Incident Response free