Incident Response interview questions

45 Incident Response questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is Security incident?

Junior
  1. A.restoring affected systems to normal operation and confirming they are clean
  2. B.blameless analysis after an incident to capture lessons and improve defenses
  3. C.an event that actually or potentially compromises confidentiality, integrity, or availability
  4. D.predefined step-by-step procedure for responding to a specific type of incident

Answer + AI explanation with Pro

2. Which term means: "an event that actually or potentially compromises confidentiality, integrity, or availability"?

Junior
  1. A.Threat hunting
  2. B.CIA triad
  3. C.Security incident
  4. D.Post-incident review

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Security incident — restoring affected systems to normal operation and confirming they are clean
  2. B.Security incident — proactively searching systems for hidden threats that evaded automated detection
  3. C.Security incident — an event that actually or potentially compromises confidentiality, integrity, or availability
  4. D.Security incident — predefined step-by-step procedure for responding to a specific type of incident

Answer + AI explanation with Pro

4. What is CIA triad?

Junior
  1. A.average time taken to discover that a security incident has occurred
  2. B.the core security goals: Confidentiality, Integrity, and Availability
  3. C.discussion-based drill where teams walk through their response to a hypothetical incident
  4. D.proactively searching systems for hidden threats that evaded automated detection

Answer + AI explanation with Pro

5. Which term means: "the core security goals: Confidentiality, Integrity, and Availability"?

Junior
  1. A.Indicator of Compromise (IoC)
  2. B.Security incident
  3. C.Containment
  4. D.CIA triad

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.CIA triad — the core security goals: Confidentiality, Integrity, and Availability
  2. B.CIA triad — limiting the scope and spread of an incident to prevent further damage
  3. C.CIA triad — discussion-based drill where teams walk through their response to a hypothetical incident
  4. D.CIA triad — an event that actually or potentially compromises confidentiality, integrity, or availability

Answer + AI explanation with Pro

7. What is Indicator of Compromise (IoC)?

Junior
  1. A.removing the threat (malware, accounts, footholds) from affected systems
  2. B.forensic artifact (e.g. hash, IP, domain) signaling a system may be breached
  3. C.blameless analysis after an incident to capture lessons and improve defenses
  4. D.average time taken to discover that a security incident has occurred

Answer + AI explanation with Pro

8. Which term means: "forensic artifact (e.g. hash, IP, domain) signaling a system may be breached"?

Junior
  1. A.Threat hunting
  2. B.Containment
  3. C.Indicator of Compromise (IoC)
  4. D.Tabletop exercise

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.Indicator of Compromise (IoC) — forensic artifact (e.g. hash, IP, domain) signaling a system may be breached
  2. B.Indicator of Compromise (IoC) — Security Information and Event Management system aggregating and correlating logs for detection and alerting
  3. C.Indicator of Compromise (IoC) — discussion-based drill where teams walk through their response to a hypothetical incident
  4. D.Indicator of Compromise (IoC) — blameless analysis after an incident to capture lessons and improve defenses

Answer + AI explanation with Pro

10. What is Containment?

Junior
  1. A.limiting the scope and spread of an incident to prevent further damage
  2. B.discussion-based drill where teams walk through their response to a hypothetical incident
  3. C.predefined step-by-step procedure for responding to a specific type of incident
  4. D.initial assessment to classify, prioritize, and assign incidents by severity and impact

Answer + AI explanation with Pro

11. Which term means: "limiting the scope and spread of an incident to prevent further damage"?

Junior
  1. A.Containment
  2. B.Mean Time To Detect (MTTD)
  3. C.Chain of custody
  4. D.Threat hunting

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.Containment — limiting the scope and spread of an incident to prevent further damage
  2. B.Containment — the core security goals: Confidentiality, Integrity, and Availability
  3. C.Containment — Security Orchestration, Automation, and Response platform automating response workflows
  4. D.Containment — removing the threat (malware, accounts, footholds) from affected systems

Answer + AI explanation with Pro

13. What is Eradication?

Junior
  1. A.initial assessment to classify, prioritize, and assign incidents by severity and impact
  2. B.the core security goals: Confidentiality, Integrity, and Availability
  3. C.removing the threat (malware, accounts, footholds) from affected systems
  4. D.forensic artifact (e.g. hash, IP, domain) signaling a system may be breached

Answer + AI explanation with Pro

14. Which term means: "removing the threat (malware, accounts, footholds) from affected systems"?

Junior
  1. A.Mean Time To Detect (MTTD)
  2. B.Eradication
  3. C.Playbook
  4. D.Threat hunting

Answer + AI explanation with Pro

15. Which statement is correct?

Junior
  1. A.Eradication — proactively searching systems for hidden threats that evaded automated detection
  2. B.Eradication — the core security goals: Confidentiality, Integrity, and Availability
  3. C.Eradication — an event that actually or potentially compromises confidentiality, integrity, or availability
  4. D.Eradication — removing the threat (malware, accounts, footholds) from affected systems

Answer + AI explanation with Pro

16. What is Recovery?

Junior
  1. A.forensic artifact (e.g. hash, IP, domain) signaling a system may be breached
  2. B.average time taken to discover that a security incident has occurred
  3. C.restoring affected systems to normal operation and confirming they are clean
  4. D.Security Orchestration, Automation, and Response platform automating response workflows

Answer + AI explanation with Pro

17. Which term means: "restoring affected systems to normal operation and confirming they are clean"?

Junior
  1. A.Security incident
  2. B.SIEM
  3. C.Recovery
  4. D.Post-incident review

Answer + AI explanation with Pro

18. Which statement is correct?

Junior
  1. A.Recovery — an event that actually or potentially compromises confidentiality, integrity, or availability
  2. B.Recovery — restoring affected systems to normal operation and confirming they are clean
  3. C.Recovery — Security Information and Event Management system aggregating and correlating logs for detection and alerting
  4. D.Recovery — average time taken to discover that a security incident has occurred

Answer + AI explanation with Pro

19. What is Chain of custody?

Mid
  1. A.documented handling of evidence to preserve its integrity for investigation or legal use
  2. B.removing the threat (malware, accounts, footholds) from affected systems
  3. C.Security Orchestration, Automation, and Response platform automating response workflows
  4. D.average time taken to discover that a security incident has occurred

Answer + AI explanation with Pro

20. Which term means: "documented handling of evidence to preserve its integrity for investigation or legal use"?

Mid
  1. A.Security incident
  2. B.CIA triad
  3. C.Threat hunting
  4. D.Chain of custody

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.Chain of custody — initial assessment to classify, prioritize, and assign incidents by severity and impact
  2. B.Chain of custody — predefined step-by-step procedure for responding to a specific type of incident
  3. C.Chain of custody — Security Information and Event Management system aggregating and correlating logs for detection and alerting
  4. D.Chain of custody — documented handling of evidence to preserve its integrity for investigation or legal use

Answer + AI explanation with Pro

22. What is SIEM?

Mid
  1. A.Security Information and Event Management system aggregating and correlating logs for detection and alerting
  2. B.the core security goals: Confidentiality, Integrity, and Availability
  3. C.blameless analysis after an incident to capture lessons and improve defenses
  4. D.an event that actually or potentially compromises confidentiality, integrity, or availability

Answer + AI explanation with Pro

23. Which term means: "Security Information and Event Management system aggregating and correlating logs for detection and alerting"?

Mid
  1. A.Mean Time To Detect (MTTD)
  2. B.Post-incident review
  3. C.Tabletop exercise
  4. D.SIEM

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.SIEM — Security Information and Event Management system aggregating and correlating logs for detection and alerting
  2. B.SIEM — discussion-based drill where teams walk through their response to a hypothetical incident
  3. C.SIEM — documented handling of evidence to preserve its integrity for investigation or legal use
  4. D.SIEM — average time taken to discover that a security incident has occurred

Answer + AI explanation with Pro

25. What is Playbook?

Mid
  1. A.removing the threat (malware, accounts, footholds) from affected systems
  2. B.predefined step-by-step procedure for responding to a specific type of incident
  3. C.forensic artifact (e.g. hash, IP, domain) signaling a system may be breached
  4. D.blameless analysis after an incident to capture lessons and improve defenses

Answer + AI explanation with Pro

26. Which term means: "predefined step-by-step procedure for responding to a specific type of incident"?

Mid
  1. A.Recovery
  2. B.CIA triad
  3. C.Post-incident review
  4. D.Playbook

Answer + AI explanation with Pro

27. Which statement is correct?

Mid
  1. A.Playbook — predefined step-by-step procedure for responding to a specific type of incident
  2. B.Playbook — restoring affected systems to normal operation and confirming they are clean
  3. C.Playbook — the core security goals: Confidentiality, Integrity, and Availability
  4. D.Playbook — average time taken to discover that a security incident has occurred

Answer + AI explanation with Pro

28. What is Mean Time To Detect (MTTD)?

Mid
  1. A.average time taken to discover that a security incident has occurred
  2. B.proactively searching systems for hidden threats that evaded automated detection
  3. C.removing the threat (malware, accounts, footholds) from affected systems
  4. D.restoring affected systems to normal operation and confirming they are clean

Answer + AI explanation with Pro

29. Which term means: "average time taken to discover that a security incident has occurred"?

Mid
  1. A.Containment
  2. B.Threat hunting
  3. C.Recovery
  4. D.Mean Time To Detect (MTTD)

Answer + AI explanation with Pro

30. Which statement is correct?

Mid
  1. A.Mean Time To Detect (MTTD) — predefined step-by-step procedure for responding to a specific type of incident
  2. B.Mean Time To Detect (MTTD) — limiting the scope and spread of an incident to prevent further damage
  3. C.Mean Time To Detect (MTTD) — proactively searching systems for hidden threats that evaded automated detection
  4. D.Mean Time To Detect (MTTD) — average time taken to discover that a security incident has occurred

Answer + AI explanation with Pro

Showing 30 of 45 Incident Response questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Incident Response question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers