7.0 Security Operations

Incident Response & Forensics Practice Questions

Incident response phases, digital forensics, order of volatility, chain of custody, and evidence types.

One solved question, so you can see how these are marked

A SIEM alert indicates that a privileged account authenticated from two distant countries within five minutes. What is the BEST first action for the incident manager?

Validate and scope the alert using relevant authentication, endpoint, and network data.

Detection and analysis should first validate the suspected incident and determine its scope and impact so that response actions are proportionate. Disabling all accounts, public notification, or rebuilding a system before analysis may disrupt operations, destroy evidence, or be premature.

Every question in the set below is marked like this. The answers stay hidden until you pick one.