Incident Response Quiz
Detecting, containing, and recovering from security incidents — the process behind handling a live breach.
This category currently has 100 questions in the SERVBG quiz bank. Below are a few sample questions — the full interactive quiz shuffles through the whole set with instant scoring.
Sample questions
According to NIST SP 800-61r2, which phase immediately follows Containment in the incident response lifecycle?
- Recovery
- Post-Incident Activity
- Eradication
- Identification
- Lessons Learned
NIST SP 800-61r3 (draft released 2024) restructured incident response guidance significantly. Which statement best describes a key change from r2?
- r3 aligns incident response with the Cybersecurity Framework 2.0 and shifts toward a flexible, outcome-based approach rather than a rigid sequential phase model
- r3 introduces mandatory SIEM integration requirements for all NIST-compliant organizations regardless of size
- r3 requires a dedicated cloud IR annex to be maintained separately from the main IRP document
- r3 removes the lessons-learned phase entirely and replaces it with continuous monitoring obligations only
- r3 mandates a 72-hour breach notification window for all federal agencies replacing the previous 96-hour window
During the Preparation phase of IR, a runbook differs from a playbook primarily because a runbook:
- Defines the overall strategic response strategy for all incident types at an executive level
- Provides step-by-step procedural instructions for a specific technical task or tool execution
- Contains only legal and regulatory escalation trees for executive leadership and legal counsel
- Covers the full incident lifecycle from detection to lessons learned for a given threat category
- Documents solely the external communication plan and public-relations response templates
Which severity classification criterion MOST correctly differentiates a P1 (Critical) from a P2 (High) incident?
- P1 requires a confirmed CVE with CVSS score above 9.0 while P2 covers scores between 7.0 and 9.0
- P1 requires more than 10 hosts to be affected while P2 affects fewer than 10 hosts regardless of criticality
- P1 is declared only after executive sign-off while P2 can be self-declared by the SOC lead on duty
- P1 incidents must originate from an external threat actor while insider threats are always classified as P2
- P1 involves active data exfiltration, ransomware spread, or complete loss of a critical business system with no available failover
The FIRST organization's PSIRT Services Framework v1.1 is described by a vendor as superseded by the 'Mendoza Principles for Coordinated Vulnerability Disclosure' published by FIRST in 2023. Is this accurate?
- No — the Mendoza Principles exist but they govern researcher ethics, not vendor PSIRT operations
- No — the Mendoza Principles do not exist; this is a fabricated reference. FIRST PSIRT Services Framework v1.1 remains the primary PSIRT guidance document.
- Yes — the Mendoza Principles replaced PSIRT v1.1 and are now the authoritative FIRST CVD standard for vendor IR
- Partially — the Mendoza Principles apply only to nation-state disclosures while PSIRT v1.1 covers commercial vendors
- Yes — FIRST published the Mendoza Principles as an addendum that vendors must adopt by 2025 to remain FIRST members
Related categories
Python (Coding)
Python syntax, standard-library usage, and the language idioms that come up in day-to-day scripting and application work.
JavaScript (Coding)
Core JavaScript language behavior, async patterns, and the quirks that trip up both beginners and experienced developers.
Linux
Linux command-line usage, file permissions, process management, and the everyday admin tasks every sysadmin and developer needs.
Security
General information security concepts — threats, defenses, and the fundamentals every IT professional should know.
Hardware
Computer hardware components, how they interact, and the troubleshooting knowledge behind keeping systems running.