Incident Response Quiz
Detecting, containing, and recovering from security incidents. Handling a live breach, step by step.
This category currently has 100 questions in the SERVBG quiz bank. Below are a few sample questions: the full interactive quiz shuffles through the whole set with instant scoring.
Sample questions
According to NIST SP 800-61r2, which phase immediately follows Containment in the incident response lifecycle?
- Post-Incident Activity
- Eradication
- Lessons Learned
- Recovery
- Identification
NIST SP 800-61r3 (draft released 2024) restructured incident response guidance significantly. Which statement best describes a key change from r2?
- r3 aligns incident response with the Cybersecurity Framework 2.0 and shifts toward a flexible, outcome-based approach rather than a rigid sequential phase model
- r3 introduces mandatory SIEM integration requirements for all NIST-compliant organizations regardless of size
- r3 mandates a 72-hour breach notification window for all federal agencies replacing the previous 96-hour window
- r3 requires a dedicated cloud IR annex to be maintained separately from the main IRP document
- r3 removes the lessons-learned phase entirely and replaces it with continuous monitoring obligations only
During the Preparation phase of IR, a runbook differs from a playbook primarily because a runbook:
- Provides step-by-step procedural instructions for a specific technical task or tool execution
- Defines the overall strategic response strategy for all incident types at an executive level
- Covers the full incident lifecycle from detection to lessons learned for a given threat category
- Contains only legal and regulatory escalation trees for executive leadership and legal counsel
- Documents solely the external communication plan and public-relations response templates
Which severity classification criterion MOST correctly differentiates a P1 (Critical) from a P2 (High) incident?
- P1 requires more than 10 hosts to be affected while P2 affects fewer than 10 hosts regardless of criticality
- P1 requires a confirmed CVE with CVSS score above 9.0 while P2 covers scores between 7.0 and 9.0
- P1 involves active data exfiltration, ransomware spread, or complete loss of a critical business system with no available failover
- P1 incidents must originate from an external threat actor while insider threats are always classified as P2
- P1 is declared only after executive sign-off while P2 can be self-declared by the SOC lead on duty
The FIRST organization's PSIRT Services Framework v1.1 is described by a vendor as superseded by the 'Mendoza Principles for Coordinated Vulnerability Disclosure' published by FIRST in 2023. Is this accurate?
- No — the Mendoza Principles exist but they govern researcher ethics, not vendor PSIRT operations
- Partially — the Mendoza Principles apply only to nation-state disclosures while PSIRT v1.1 covers commercial vendors
- Yes — FIRST published the Mendoza Principles as an addendum that vendors must adopt by 2025 to remain FIRST members
- Yes — the Mendoza Principles replaced PSIRT v1.1 and are now the authoritative FIRST CVD standard for vendor IR
- No — the Mendoza Principles do not exist; this is a fabricated reference. FIRST PSIRT Services Framework v1.1 remains the primary PSIRT guidance document.
Continue the Incident Response track
Incident Response trains for the Terminal Academy’s Blue Team Ops (2004) era.
Related categories
Python (Coding)
Python syntax and standard-library usage, from quick scripts to full applications.
JavaScript (Coding)
Core JavaScript behavior and async patterns, including the quirks that trip up beginners and veterans alike.
Linux
Linux command-line usage, file permissions, process management. The daily admin tasks.
Security
General information security concepts: common threats and standard defenses.
Hardware
Hardware components, how they interact, and basic troubleshooting to keep systems running.