Courseiva

CS0-004 · domain

Incident Response and Management

This domain covers the NIST SP 800-61 lifecycle — preparation, detection and analysis, containment/eradication/recovery, and post-incident activity — plus forensic evidence handling. CS0-004 tests it through scenario questions: choosing the right acquisition tool, ordering containment actions, and deciding when to preserve versus restore systems during a live incident.

98 questions25 easy49 medium24 hard

Focused practice

Practice Incident Response and Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Incident Response and Management

Map every scenario to a NIST SP 800-61 phase and justify the action order. The single most important thing: preserve volatile evidence first, then contain, then eradicate and recover — never destroy data to stop an attack.

Selecting memory acquisition tools such as LiME, WinPmem, or FTK Imager on running hosts

Applying NIST SP 800-61 phases to contain, eradicate, and recover from ransomware and malware

Order of volatility: capturing RAM, network state, and temporary files before disk images

Using SIEM alert triage, log correlation, and indicators of compromise to scope an incident

Watch out for

Common Incident Response and Management exam traps

  • ▸Pulling the plug on a live system to preserve evidence, destroying volatile memory and network connections needed for analysis
  • ▸Jumping straight to eradication or restoration before scoping the incident and preserving forensic evidence
  • ▸Confusing containment with recovery, or treating a business-continuity workaround as incident closure without root-cause analysis

Question index

All Incident Response and Management questions (98)

Click any question to see the full explanation, or start a practice session above.

1

When performing digital forensics, which of the following represents the correct order of volatility from most volatile to least volatile?

Medium
2

After a phishing incident, the security team wants to improve detection of similar attacks in the future. Which THREE actions should the team take as part of post-incident activity? (Choose THREE.)

Medium
3

During forensic analysis of a compromised Linux server, an analyst needs to acquire memory evidence. The server is running and the analyst has root access. Which of the following tools should the analyst use to capture the contents of RAM with the least impact on the system?

Hard
4

During an incident response engagement, a junior analyst asks the team lead about the purpose of a lessons learned meeting. Which of the following BEST describes the primary objective of this meeting?

Easy
5

During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, a security analyst identifies an alert indicating a high volume of outbound traffic from a critical server to an unknown IP address. Which of the following actions should the analyst perform FIRST?

Medium
6

Which of the following is an example of a behavioral indicator of compromise (IOC) observed during dynamic malware analysis?

Easy
7

A security analyst is investigating a potential data breach. The analyst needs to preserve evidence before containment. Which of the following actions is MOST appropriate at this stage?

Medium
8

During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, a security analyst identifies suspicious network traffic from an internal host to a known malicious IP address. Which of the following is the most appropriate next step?

Medium
9

During a post-incident review, a security analyst identifies that the mean time to detect (MTTD) for incidents is significantly higher than the industry benchmark. Which THREE actions should the analyst recommend to improve detection capabilities?

Easy
10

A CSIRT is following its incident response plan during a confirmed data breach. The team lead needs to ensure that all evidence collected is admissible in a future legal proceeding. Which of the following should the team lead implement FIRST?

Hard
11

During the detection and analysis phase of an incident, an analyst identifies a file with a hash that matches a known malware signature. The analyst wants to enrich this IOC with additional context. Which resource is BEST suited for this enrichment?

Medium
12

A security operations center (SOC) analyst receives an alert about a potential ransomware infection on a critical server. The incident response team needs to contain the threat quickly. Which of the following should be performed FIRST as a short-term containment measure?

Medium
13

After containing a malware outbreak, the incident response team performs static malware analysis on a suspicious executable. Which of the following artifacts would be most helpful in creating a YARA rule to detect variants of the malware?

Medium
14

During a forensic investigation, an analyst must acquire digital evidence while maintaining forensic soundness. Which THREE practices should the analyst follow? (Choose three.)

Hard
15

A security analyst is responding to a potential data exfiltration incident. As part of the containment strategy, the analyst must preserve evidence. Which TWO actions should the analyst take before containment? (Select two.)

Medium
16

During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, an analyst identifies suspicious network traffic from an internal host to a known malicious IP address. Which step should the analyst perform next to validate the alert?

Easy
17

A CSIRT is investigating a ransomware incident that encrypted files on multiple servers. The team needs to determine the initial infection vector. Which THREE pieces of evidence should the team prioritize collecting? (Select three.)

Hard
18

A security analyst is conducting static analysis of a suspicious executable. Which of the following tools or techniques is BEST suited for extracting strings and viewing the import table?

Medium
19

After containing a security incident, the incident response team conducts a root cause analysis. Which of the following is the PRIMARY purpose of this activity?

Medium
20

After a DDoS attack, the incident response team wants to improve detection and prevention. Which of the following metrics would be MOST useful for evaluating the effectiveness of the response?

Medium
21

An organization's security team receives an alert about a potential ransomware infection on a critical server. The severity classification is 'high' because the server supports a production database. According to the incident response plan, which containment action should be taken first to minimize data loss?

Medium
22

A security analyst is performing static analysis on a suspicious PE file. Which initial step should the analyst take to understand the file's imports and potential capabilities?

Medium
23

During a forensic investigation, an analyst needs to acquire disk images from multiple suspect drives. Which THREE practices ensure forensic soundness? (Select THREE)

Hard
24

A security analyst is performing dynamic analysis of a suspicious file in a sandbox. Which of the following observations is most indicative of ransomware behavior?

Hard
25

An organization is implementing an incident response plan. Which phase of the NIST SP 800-61 lifecycle includes activities such as creating policies, establishing IR teams, and acquiring necessary tools?

Easy
26

A security analyst is investigating a potential data breach. The analyst needs to collect digital evidence while preserving its integrity. Which TWO actions should the analyst take? (Choose TWO.)

Medium
27

An organization's incident response team is classifying an incident based on severity and priority. Which TWO factors should the team consider when determining the priority of an incident? (Select TWO.)

Easy
28

An analyst is using YARA to create rules for detecting a specific malware strain. Which of the following pieces of information is MOST useful for writing a YARA rule?

Medium
29

An organization's incident response team is handling a ransomware incident where critical servers have been encrypted. The team has identified the ransomware variant and determined that decryption is not possible. Which of the following is the BEST post-incident activity to prevent recurrence?

Hard
30

An analyst is examining a disk image acquired from a compromised Linux server. The analyst needs to verify that the image is an exact bit-for-bit copy of the original drive. Which forensic sound procedure should the analyst perform?

Medium
31

During dynamic analysis of a malware sample in a sandbox, the analyst observes that the malware attempts to connect to an IP address 198.51.100.23 and modifies the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Which IOC type is the IP address an example of?

Medium
32

Which of the following is the FIRST step in the NIST SP 800-61 incident response lifecycle?

Easy
33

During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) for a recent breach was 14 days, while the mean time to respond (MTTR) was 6 hours. Which metric should the team prioritize to improve in future incidents?

Medium
34

During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) for incidents is significantly higher than industry benchmarks. Which of the following improvements would most directly reduce MTTD?

Hard
35

An organization has identified indicators of compromise (IOCs) from a recent incident. Which data format is specifically designed for sharing threat intelligence in a standardized, machine-readable way?

Easy
36

During a post-incident review, the CSIRT identifies that the mean time to detect (MTTD) is significantly higher than the industry benchmark. Which initiative would MOST likely reduce MTTD?

Medium
37

An analyst needs to capture the contents of volatile memory from a Windows system suspected of being compromised. Which tool should the analyst use to acquire a memory image?

Easy
38

An analyst runs a YARA rule against a set of files and gets a hit. The rule was written to detect a specific malware family. What is the PRIMARY purpose of using YARA rules in this context?

Hard
39

During a ransomware incident, the incident response team needs to preserve evidence before containment. Which of the following actions should be performed BEFORE isolating the infected system from the network?

Hard
40

A security analyst is investigating a potential malware infection on a Windows workstation. The analyst needs to collect evidence while preserving the order of volatility. Which TWO pieces of data should the analyst collect FIRST? (Select TWO)

Medium
41

After containing a data breach, the incident response team discovers that an attacker exfiltrated sensitive data over DNS tunneling. Which of the following detection rules would BEST identify similar activity in the future?

Hard
42

During which phase of the NIST SP 800-61 incident response lifecycle would an organization conduct a lessons learned meeting?

Easy
43

A security analyst detects ransomware on a critical server. Which containment strategy should be implemented FIRST to minimize damage?

Medium
44

A security analyst is investigating a potential data exfiltration incident. The analyst captures memory from a Windows system and finds a process that is injecting code into other processes. Which THREE indicators from the memory analysis would MOST strongly suggest malicious activity? (Select THREE.)

Hard
45

A security analyst is classifying an incident where an employee's workstation is infected with ransomware that encrypts files and displays a ransom note. Which incident category and severity level best describe this scenario?

Easy
46

A security analyst is reviewing indicators of compromise (IOCs) from a recent phishing campaign. Which of the following is an example of an email-related IOC?

Easy
47

An incident responder needs to collect forensic evidence from a server that was attacked. The evidence includes network connections, running processes, memory contents, and disk data. According to the order of volatility, which piece of evidence should the responder collect FIRST?

Medium
48

During the preparation phase of the NIST SP 800-61 incident response lifecycle, a security analyst is tasked with ensuring the team has the necessary tools and resources. Which of the following is the MOST important activity to perform during this phase?

Easy
49

An organization uses MISP as its threat intelligence platform. After a security incident, the team wants to share IOCs with other trusted organizations. Which standard should they use to package and exchange the threat intelligence?

Easy
50

An incident response team is conducting post-incident activities after a ransomware attack. The team wants to improve detection and response for future incidents. Which TWO actions are most appropriate for updating detection rules? (Select TWO.)

Medium
51

An analyst is investigating a possible data exfiltration incident. The analyst has acquired a memory dump from the compromised system. Which of the following would be the BEST approach to extract evidence of exfiltration?

Hard
52

During post-incident activities, the security team reviews metrics. Which metric measures the average time taken to detect an incident?

Medium
53

During dynamic analysis of a suspicious file in a sandbox environment, which THREE behaviors are considered indicators of compromise (IOCs) that suggest malicious activity? (Choose THREE.)

Medium
54

During a phishing incident, an analyst extracts a URL from the email body and searches VirusTotal. The URL is associated with a credential harvesting page. Which type of indicator is this URL?

Medium
55

A security analyst is investigating a phishing incident that resulted in credential theft. Which TWO actions should the analyst take as part of short-term containment? (Choose two.)

Medium
56

During the preparation phase of the NIST SP 800-61 incident response lifecycle, which of the following is the MOST important activity to ensure effective incident response?

Easy
57

After containing a ransomware incident, the incident response team is conducting post-incident activities. Which action is MOST important to prevent a similar attack in the future?

Medium
58

During a forensic investigation, an analyst must preserve evidence in accordance with forensic sound procedures. Which THREE of the following practices should the analyst follow? (Select THREE.)

Hard
59

A security analyst receives an alert about a possible ransomware outbreak. Which short-term containment action should be performed FIRST to prevent further spread?

Easy
60

During the detection and analysis phase of incident response, a security analyst identifies suspicious outbound traffic from a finance workstation to a known malicious IP address at 2:00 AM. The analyst checks the firewall logs and sees a single connection. Which action should the analyst take FIRST according to NIST SP 800-61?

Medium
61

A security analyst is triaging an alert indicating that a user's workstation has been infected with ransomware. The file server shows signs of encryption. The analyst needs to contain the incident. Which action should the analyst take FIRST to minimize damage?

Medium
62

An incident responder is called to a server room where a critical database server is exhibiting signs of compromise. The responder must preserve evidence while preventing further damage. Which of the following is a short-term containment strategy that also preserves evidence?

Medium
63

During dynamic malware analysis in a sandbox, an analyst observes that the malware attempts to connect to a remote IP address on port 443, modifies the Windows registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and drops a DLL in the system32 folder. Which type of IOC is most indicative of persistence?

Medium
64

During a forensic investigation, an analyst creates a disk image using dd with a SHA256 hash. Later, the analyst needs to verify the integrity of the image before analysis. Which command should the analyst use to compare the original hash with a newly computed hash?

Medium
65

An organization has been experiencing repeated phishing attacks that bypass email filters. The incident response team wants to enhance detection by creating rules based on characteristics of the phishing emails. Which of the following IOCs would be most effective for detecting similar phishing campaigns?

Medium
66

A security analyst is reviewing IOCs from a threat intelligence feed. The analyst wants to enrich the IOCs using open-source tools. Which THREE tools are commonly used for IOC enrichment? (Select three.)

Easy
67

An organization is experiencing a DDoS attack targeting its web servers. Which of the following is the BEST short-term containment strategy?

Medium
68

A security team is responding to a phishing incident that led to credential compromise. Which of the following is the BEST short-term containment action to prevent further damage?

Medium
69

An incident responder is performing containment of a ransomware incident that has encrypted files on several file servers. Which THREE actions are appropriate for long-term containment and recovery? (Select THREE)

Medium
70

An analyst is investigating a suspected data breach. The analyst needs to identify which files were exfiltrated and preserve evidence. According to the order of volatility, which of the following should the analyst capture FIRST?

Medium
71

During the detection and analysis phase of incident response, a security analyst identifies suspicious outbound traffic from a workstation to an external IP address known for command and control (C2) activity. Which classification should the analyst assign to this incident?

Medium
72

An incident responder is classifying an incident. The incident involves ransomware encrypting files on multiple workstations, causing significant business disruption. Which severity level should be assigned to this incident?

Easy
73

A security analyst is investigating a potential insider threat where a user is suspected of exfiltrating sensitive data via USB drives. The analyst needs to gather evidence while preserving the chain of custody. Which THREE actions should the analyst perform? (Choose THREE.)

Hard
74

An analyst is reviewing a suspicious executable using static analysis. Which of the following would provide information about the functions the executable imports from system libraries?

Medium
75

A security analyst receives an alert that a workstation is communicating with a known C2 server over DNS. The analyst wants to quickly isolate the endpoint from the network but keep it powered on for later memory capture. Which of the following actions should the analyst take FIRST?

Medium
76

During a post-incident review, the team identifies that detection was delayed because alerts from multiple sources were not correlated. Which improvement would BEST address this issue?

Hard
77

An analyst is performing static analysis on a suspicious executable. The analyst discovers that the PE file has a suspicious section name and a high entropy value. Which tool or technique would be MOST useful for further analyzing the packed nature of the file?

Hard
78

A SOC analyst receives an alert from a threat intelligence platform (TIP) about a new phishing campaign. The indicator is a URL. Which enrichment source is BEST for determining the URL's current hosting infrastructure?

Hard
79

An incident response team is conducting post-incident activities after containing a malware outbreak. Which TWO activities should be included in the lessons learned phase? (Choose TWO.)

Easy
80

An incident response team is analyzing indicators of compromise (IOCs) from a phishing campaign. Which THREE of the following are commonly used IOC types? (Select THREE.)

Easy
81

A security analyst is analyzing a suspicious file using static analysis. The analyst wants to identify imported functions to determine the file's capabilities. Which tool or technique is BEST suited for this task?

Easy
82

During a forensic analysis, an analyst needs to collect data in order of volatility. Which of the following represents the correct order from most volatile to least volatile?

Medium
83

A security analyst is performing forensic analysis of a compromised system. The analyst needs to acquire disk evidence in a forensically sound manner. Which TWO actions should the analyst take to ensure the integrity of the evidence? (Choose TWO.)

Medium
84

An organization wants to automate the sharing of threat intelligence with other trusted entities using a standardized protocol. Which protocol is specifically designed for this purpose?

Easy
85

A security analyst is performing memory acquisition on a compromised Linux server using LiME. The analyst needs to capture the memory image with minimal impact on the system. Which of the following parameters should the analyst use to ensure the output is forensically sound?

Hard
86

An organization is experiencing a distributed denial-of-service (DDoS) attack targeting its web servers. The incident response team is implementing containment strategies. Which TWO actions are appropriate for short-term containment of a DDoS attack? (Choose TWO.)

Medium
87

An organization uses MISP (Malware Information Sharing Platform) to share threat intelligence with trusted partners. Which of the following standards is commonly used by MISP to structure and exchange threat intelligence data?

Medium
88

A security analyst needs to share threat intelligence with other organizations in a standardized format. Which of the following standards should the analyst use?

Easy
89

During a forensic investigation, an analyst needs to acquire memory from a Linux server. Which tool is specifically designed for this purpose?

Hard
90

During a post-incident activity, the CSIRT performs a root cause analysis for a data breach. They discover that the breach originated from a misconfigured S3 bucket that allowed public read access. Which of the following actions should be included in the lessons learned to prevent recurrence?

Hard
91

An analyst is performing static analysis on a suspicious executable file. Which of the following would be MOST useful to identify potential malicious behavior without executing the file?

Medium
92

A forensic analyst is investigating a suspected data breach involving a compromised workstation. The analyst wants to collect volatile data in accordance with the order of volatility. Which sequence of data collection is correct?

Hard
93

During forensic analysis of a compromised server, an analyst needs to preserve evidence in order of volatility. Which of the following actions should the analyst perform FIRST?

Hard
94

An organization has experienced a data breach involving personally identifiable information (PII). The incident response team has contained the breach and eradicated the threat. During the post-incident activity phase, which activity is MOST critical to prevent future similar incidents?

Medium
95

An analyst receives a threat intelligence feed containing IOCs in STIX format. Which of the following BEST describes the purpose of STIX?

Easy
96

After a DDoS attack, the CSIRT wants to share IOCs with other organizations. Which protocol is specifically designed for automated, real-time threat intelligence sharing?

Medium
97

During a forensic investigation of a compromised Linux server, the analyst needs to acquire memory for analysis. The system is running and the analyst cannot power it off. Which tool is MOST appropriate for acquiring memory in this scenario?

Hard
98

Which of the following is the correct order of volatility for digital evidence?

Easy

Frequently asked questions

What does the Incident Response and Management domain cover on the CS0-004 exam?
Map every scenario to a NIST SP 800-61 phase and justify the action order. The single most important thing: preserve volatile evidence first, then contain, then eradicate and recover — never destroy data to stop an attack.
How many questions are in this domain?
This page lists all 98 Incident Response and Management questions in the CS0-004 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Incident Response and Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cysa-plus CYSA-PLUS cysa incident response Practice Questions