Courseiva

CCNA Incident Response and Management Questions

23 of 98 questions · Page 2/2 · Incident Response and Management · Answers revealed

76
MCQhard

During a post-incident review, the team identifies that detection was delayed because alerts from multiple sources were not correlated. Which improvement would BEST address this issue?

A.Disable non-critical alerts
B.Implement a SIEM solution
C.Increase the number of security staff
D.Increase logging verbosity
AnswerB

A SIEM ingests logs and alerts from disparate sources into a single platform and applies correlation rules to link related events, such as a failed login followed by a privilege escalation and outbound data transfer, into one incident timeline, directly solving the described correlation gap.

Why this answer

A SIEM solution aggregates logs and alerts from multiple sources, normalizes them, and correlates events across systems to surface related activity that individual tools would miss. This directly addresses the root cause — lack of correlation — by providing centralized detection and alerting. It is the standard architectural answer for improving cross-source detection.

Exam trap

CS0-004 often tests the difference between noise reduction and correlation: candidates pick 'disable non-critical alerts' or 'increase logging' because they sound like detection improvements, but the question specifically targets cross-source correlation, which only a SIEM provides.

How to eliminate wrong answers

Option A is wrong because disabling non-critical alerts reduces noise but does not add correlation; it may even hide signals needed to detect multi-stage attacks. Option C is wrong because adding staff increases response capacity but does not solve the technical problem of uncorrelated alerts across sources. Option D is wrong because increasing logging verbosity produces more data without correlation, likely worsening alert fatigue rather than improving detection.

77
MCQhard

An analyst is performing static analysis on a suspicious executable. The analyst discovers that the PE file has a suspicious section name and a high entropy value. Which tool or technique would be MOST useful for further analyzing the packed nature of the file?

A.Extracting strings from the binary
B.Using a YARA rule to detect the packer
C.Using PEiD or similar packer identifier
D.Running the file in a sandbox
AnswerC

PEiD and similar packer detection tools analyze the Portable Executable (PE) headers, entry point signatures, and section characteristics to quickly and accurately identify specific packers, cryptors, or compilers. This static analysis technique is the most direct and efficient way to confirm if an executable is packed and to determine the exact packing algorithm applied.

Why this answer

PEiD or similar tools can detect packers by scanning for known signatures. High entropy and suspicious section names often indicate packing, so using a packer identifier is appropriate.

78
MCQhard

A SOC analyst receives an alert from a threat intelligence platform (TIP) about a new phishing campaign. The indicator is a URL. Which enrichment source is BEST for determining the URL's current hosting infrastructure?

A.VirusTotal
B.WHOIS
C.Shodan
D.Passive DNS
AnswerD

Passive DNS databases log DNS query and response transactions captured by sensors across the internet. This allows analysts to reconstruct historical domain-to-IP mappings, identify fast-flux DNS techniques, and pinpoint when a malicious domain pointed to specific infrastructure.

Why this answer

Passive DNS allows querying historical and current IP addresses associated with a domain, revealing hosting changes.

79
Multi-Selecteasy

An incident response team is conducting post-incident activities after containing a malware outbreak. Which TWO activities should be included in the lessons learned phase? (Choose TWO.)

Select 2 answers
A.Deleting all logs from the incident.
B.Conducting a root cause analysis.
C.Rewriting the organization's security policy from scratch.
D.Updating detection rules based on IOCs.
E.Patching all systems immediately.
AnswersB, D

Conducting a root cause analysis is the central activity of the lessons-learned phase, as it systematically identifies the underlying human, technical, or procedural factors that allowed the incident. Using structured methods like "5 Whys" or fault tree analysis, the team traces the chain of events back to initial conditions, distinguishing the immediate trigger from the deeper vulnerabilities or gaps. This analysis drives targeted remediation—such as revised hardening standards or additional training—so that similar incidents are less likely to recur.

Why this answer

Option B (Conducting a root cause analysis) is correct because the lessons learned phase of incident response requires determining why the malware outbreak occurred and how it bypassed existing controls, so the team can address the underlying weakness rather than just the symptom. Option D (Updating detection rules based on IOCs) is correct because indicators of compromise gathered during the incident should be operationalized into SIEM correlation rules, IDS/IPS signatures, or EDR detections to improve future detection and reduce time to identify similar threats. Option A is wrong because deleting logs destroys forensic evidence and violates retention and chain-of-custody requirements; logs should be preserved and reviewed.

Option C is wrong because rewriting the entire security policy from scratch is an overreaction not scoped to lessons learned, which should produce targeted improvements. Option E is wrong because patching all systems immediately is a remediation action that belongs to the eradication/recovery phase, not the post-incident lessons learned review.

Exam trap

CS0-004 often tests the confusion between remediation actions (patching, deleting malware, restoring systems) and post-incident lessons-learned activities (root cause analysis, detection tuning, playbook updates) — candidates pick 'patching all systems' because it sounds proactive, but it belongs to the eradication/recovery phase, not lessons learned.

80
Multi-Selecteasy

An incident response team is analyzing indicators of compromise (IOCs) from a phishing campaign. Which THREE of the following are commonly used IOC types? (Select THREE.)

Select 3 answers
A.CPU registers
B.IP addresses
C.Domain names
D.Software version numbers
E.File hashes
AnswersB, C, E

IP addresses are fundamental network-level IOCs because they denote the source or destination of malicious traffic observed in logs, packet captures, or DNS queries. When an infection communicates with a command-and-control (C2) node or an attacker launches a brute-force attack, that IP address becomes a repeatable, searchable value in firewall logs, SIEM alerts, and threat feeds. Sharing an IP address allows other organizations to block the endpoint, but note that IPs can change quickly, making them a time-sensitive indicator.

Why this answer

IP addresses (B) are a standard network-based IOC, since malicious command-and-control servers, phishing hosts, and payload delivery endpoints are tracked by their IPv4/IPv6 addresses. Domain names (C) are equally common IOCs, as phishing URLs, C2 domains, and DNS-based exfiltration are identified by fully qualified domain names. File hashes (E), typically MD5, SHA-1, or SHA-256 values, are host-based IOCs used to uniquely identify known malicious files such as phishing attachments or malware binaries.

CPU registers (A) are volatile runtime processor state, not a shareable indicator of compromise, and software version numbers (D) describe legitimate application builds rather than evidence of malicious activity.

Exam trap

CS0-004 often tests whether candidates distinguish IOCs from vulnerability indicators — software version numbers describe exposure, not observed compromise, and are not IOCs.

81
MCQeasy

A security analyst is analyzing a suspicious file using static analysis. The analyst wants to identify imported functions to determine the file's capabilities. Which tool or technique is BEST suited for this task?

A.Extracting strings from the file
B.Submitting the file to VirusTotal
C.Running the file in a sandbox like Cuckoo
D.Analyzing the PE header's import table
AnswerD

Analyzing the Portable Executable (PE) header's import table, specifically the Import Address Table (IAT), is a fundamental static analysis technique. It explicitly lists the dynamic-link libraries (DLLs) and the specific functions that the binary requests from the operating system, such as InternetOpenA or WriteProcessMemory. This provides immediate, concrete clues about the program's intended capabilities and behavior without executing the payload.

Why this answer

PE header analysis includes examining the import table to see which Windows API functions the executable calls, revealing its potential behavior.

82
MCQmedium

During a forensic analysis, an analyst needs to collect data in order of volatility. Which of the following represents the correct order from most volatile to least volatile?

A.Disk, swap, RAM, CPU registers, logs
B.CPU registers, RAM, swap, disk, logs
C.RAM, CPU registers, swap, disk, logs
D.Logs, disk, swap, RAM, CPU registers
AnswerB

This matches the RFC 3227 order of volatility precisely: CPU registers and cache decay in nanoseconds, RAM contents are lost on power-off within seconds, swap/pagefile persists slightly longer on disk, and log files and disk data remain until explicitly deleted, so evidence must be captured in exactly this sequence to avoid destroying the most fragile artifacts first.

Why this answer

The order of volatility dictates that volatile data in memory (CPU registers, RAM) is collected first, then less volatile data like swap, disk, and logs. The correct sequence is CPU registers, RAM, swap, disk, then logs.

83
Multi-Selectmedium

A security analyst is performing forensic analysis of a compromised system. The analyst needs to acquire disk evidence in a forensically sound manner. Which TWO actions should the analyst take to ensure the integrity of the evidence? (Choose TWO.)

Select 2 answers
A.Calculate a hash of the original drive before imaging
B.Disable the write blocker to speed up the imaging process
C.Use a write blocker when connecting the source drive
D.Power on the system and run a full antivirus scan before imaging
E.Reboot the system to clear any temporary files
AnswersA, C

Computing a cryptographic hash (e.g., SHA-256) of the original drive before imaging establishes a baseline integrity value. This baseline lets the examiner later hash the acquired image and confirm it is bit-for-bit identical to the source, proving the imaging process did not alter or omit data. Recording the hash in chain-of-custody documentation also provides legal defensibility.

Why this answer

Option A is correct because calculating a cryptographic hash (e.g., MD5 or SHA-256) of the original drive before imaging establishes a baseline value that can later be compared to the hash of the forensic image, proving the data was not altered. Option C is correct because a hardware or software write blocker prevents any write operations to the source drive during acquisition, preserving the original evidence in an unmodified state as required for forensic soundness. Option B is incorrect because disabling the write blocker would allow the forensic workstation to write to the source drive, contaminating or altering the evidence.

Option D is incorrect because powering on the system and running an antivirus scan modifies file system metadata, timestamps, and potentially deletes or quarantines files, destroying evidence integrity. Option E is incorrect because rebooting the system alters volatile data and can modify file system artifacts such as temporary files, log entries, and timestamps, which compromises the evidence.

Exam trap

The trap here is confusing 'speed' or 'cleanup' actions (disabling write blocker, rebooting, running AV) with integrity-preserving actions — candidates who prioritize convenience over forensic soundness pick the wrong options.

84
MCQeasy

An organization wants to automate the sharing of threat intelligence with other trusted entities using a standardized protocol. Which protocol is specifically designed for this purpose?

A.STIX
B.TAXII
C.REST API
D.MISP
AnswerB

Trusted Automated Exchange of Intelligence Information (TAXII) is the application-layer protocol specifically designed to route and exchange cyber threat intelligence over HTTPS. It supports multiple sharing models, such as hub-and-spoke or peer-to-peer, enabling organizations to securely automate the ingestion and dissemination of STIX-formatted data.

Why this answer

TAXII (Trusted Automated eXchange of Indicator Information) is a protocol for exchanging cyber threat intelligence in a standardized format, often used with STIX.

85
MCQhard

A security analyst is performing memory acquisition on a compromised Linux server using LiME. The analyst needs to capture the memory image with minimal impact on the system. Which of the following parameters should the analyst use to ensure the output is forensically sound?

A.Use the --digest option to calculate a SHA256 hash during acquisition
B.Specify a format that compresses the output to reduce size
C.Ensure the output path is on a write-blocked device
D.Use the --reload option to reload the original kernel module after acquisition
AnswerC

Directing the acquired memory image to a write-blocked destination device is a critical forensic practice that prevents accidental overwriting, modification, or contamination of the evidence. This ensures that the captured volatile data remains in an untampered state from the exact moment of acquisition through the entire chain of custody.

Why this answer

Using a write blocker ensures the memory capture does not alter the storage media, preserving forensic integrity.

86
Multi-Selectmedium

An organization is experiencing a distributed denial-of-service (DDoS) attack targeting its web servers. The incident response team is implementing containment strategies. Which TWO actions are appropriate for short-term containment of a DDoS attack? (Choose TWO.)

Select 2 answers
A.Rerouting traffic through a DDoS mitigation service or scrubbing center
B.Disabling the accounts of the attackers
C.Applying a security patch to the web server software
D.Rebuilding the web servers from clean images
E.Blocking the attacking IP addresses at the firewall
AnswersA, E

Rerouting traffic through a DDoS mitigation service or scrubbing center is the most effective response because these services employ specialized filtering, rate limiting, and behavioral analysis to distinguish legitimate user requests from malicious traffic, forwarding only clean traffic to the origin. This approach is well-suited for both volumetric floods and application-layer attacks, and it can be activated quickly by updating DNS or BGP to redirect traffic.

Why this answer

Option A is correct because rerouting traffic through a DDoS mitigation service or scrubbing center filters and absorbs malicious volumetric traffic before it reaches the web servers, providing immediate short-term relief during an active attack. Option E is correct because blocking the attacking IP addresses at the firewall quickly drops traffic from known malicious sources, reducing the immediate impact on the targeted web servers. Option B is not appropriate because DDoS attacks typically originate from botnets or spoofed sources, so disabling attacker accounts is neither feasible nor effective for containment.

Option C is incorrect because applying a security patch addresses a software vulnerability, not an ongoing traffic-flooding attack, and would not stop the DDoS. Option D is incorrect because rebuilding web servers from clean images is a recovery action, not a short-term containment measure, and does nothing to stop the incoming attack traffic.

Exam trap

The trap is confusing containment with eradication or recovery; candidates pick patching or rebuilding because they sound like fixes, but the question asks specifically for short-term containment of an active DDoS.

87
MCQmedium

An organization uses MISP (Malware Information Sharing Platform) to share threat intelligence with trusted partners. Which of the following standards is commonly used by MISP to structure and exchange threat intelligence data?

A.NetFlow
B.SNMP
C.STIX/TAXII
D.Syslog
AnswerC

STIX provides a structured language for describing threat indicators, while TAXII defines the transport protocol for exchanging that data between platforms. MISP natively supports both, satisfying the requirement to structure and exchange threat intelligence with trusted partners. OpenIOC and PDF are unrelated formats, and Microsoft Entra ID governs identity, not intelligence sharing.

Why this answer

STIX (Structured Threat Information Expression) and TAXII (Trusted Automated Exchange of Indicator Information) are standards for exchanging cyber threat intelligence. MISP supports STIX and TAXII for sharing.

88
MCQeasy

A security analyst needs to share threat intelligence with other organizations in a standardized format. Which of the following standards should the analyst use?

A.REST
B.STIX/TAXII
C.SOAP
D.SNMP
AnswerB

Structured Threat Information Expression (STIX) is a standardized serialization format used to model and represent structured cyber threat intelligence. Trusted Automated Exchange of Intelligence Information (TAXII) is the application-layer protocol specifically designed to securely route and exchange these STIX-formatted threat feeds over HTTPS, making them the industry standard for automated threat sharing.

Why this answer

STIX (Structured Threat Information Expression) is a standardized language for describing cyber threat intelligence, and TAXII (Trusted Automated Exchange of Intelligence Information) is the protocol for exchanging that intelligence over HTTPS. Together, they provide a standardized format and transport mechanism for sharing threat intel between organizations, as required by the question.

Exam trap

CS0-004 often tests the confusion between general web protocols (REST, SOAP) and specialized threat intelligence standards, tricking candidates into choosing REST because it's commonly used for APIs.

How to eliminate wrong answers

Option A is wrong because REST is a general architectural style for web services, not a specific threat intelligence standard. Option C is wrong because SOAP is a messaging protocol for web services, not a threat intelligence sharing standard. Option D is wrong because SNMP is used for network management, not threat intelligence exchange.

89
MCQhard

During a forensic investigation, an analyst needs to acquire memory from a Linux server. Which tool is specifically designed for this purpose?

A.dd
B.LiME
C.FTK Imager
D.WinPmem
AnswerB

LiME (Linux Memory Extractor) is a kernel-space tool designed specifically for acquiring volatile memory from Linux-based systems. It operates as a Loadable Kernel Module (LKM), allowing it to bypass user-space limitations and capture a full, uncorrupted dump of physical RAM, including volatile artifacts, while minimizing its footprint on the host system.

Why this answer

LiME (Linux Memory Extractor) is a loadable kernel module specifically designed to acquire volatile memory from Linux systems in a forensically sound manner. It captures RAM contents and outputs them in formats like raw or lime, which can then be analyzed with tools such as Volatility. This makes it the correct answer for Linux memory acquisition.

Exam trap

CS0-004 often tests the confusion between general-purpose tools (dd) and purpose-built forensic memory acquisition tools (LiME for Linux, WinPmem for Windows), catching candidates who pick dd for Linux memory capture.

How to eliminate wrong answers

Option A is wrong because dd is a general-purpose disk/device copy utility; while it can read /dev/mem, that approach is unreliable on modern kernels with restricted /dev/mem access and does not produce a forensically validated memory image. Option C is wrong because FTK Imager is primarily a Windows disk/memory imaging tool (with limited Linux support) and is not the standard Linux memory acquisition tool. Option D is wrong because WinPmem is a Windows memory acquisition tool, not a Linux one.

90
MCQhard

During a post-incident activity, the CSIRT performs a root cause analysis for a data breach. They discover that the breach originated from a misconfigured S3 bucket that allowed public read access. Which of the following actions should be included in the lessons learned to prevent recurrence?

A.Rotate all access keys for the affected account
B.Disable public access to all S3 buckets permanently
C.Conduct a penetration test on the cloud environment
D.Implement automated compliance checks for cloud storage configurations
AnswerD

Implementing automated compliance checks, such as Cloud Security Posture Management (CSPM) tools, directly addresses the root cause by continuously auditing resource configurations against security baselines. These tools provide real-time detection and automated remediation of drift, ensuring that unauthorized public access is blocked immediately upon misconfiguration.

Why this answer

Implementing automated compliance checks using tools like AWS Config ensures that storage configurations are continuously monitored and misconfigurations are flagged or corrected.

91
MCQmedium

An analyst is performing static analysis on a suspicious executable file. Which of the following would be MOST useful to identify potential malicious behavior without executing the file?

A.Running the file in a sandbox.
B.Monitoring network connections during execution.
C.Analyzing the import table.
D.Checking the file's digital signature.
AnswerC

The import table lists external functions and libraries the executable calls, revealing capabilities such as network access, file manipulation, or process injection without running the code. This static inspection satisfies the no-execution constraint while exposing likely malicious behaviour.

Why this answer

Static analysis involves examining the file without executing it. The import table shows which Windows API functions the executable uses, which can indicate capabilities such as network communication, file operations, or registry modifications.

92
MCQhard

A forensic analyst is investigating a suspected data breach involving a compromised workstation. The analyst wants to collect volatile data in accordance with the order of volatility. Which sequence of data collection is correct?

A.Disk → RAM → Swap → CPU registers → Network connections → Archived media
B.CPU registers → RAM → Swap → Network connections → Disk → Archived media
C.Network connections → CPU registers → RAM → Swap → Disk → Archived media
D.CPU registers → RAM → Swap → Disk → Network connections → Archived media
AnswerB

Correct: RAM (most volatile) first, then CPU registers, then swap, then network connections, then disk, then archived media. This follows the standard order of volatility.

Why this answer

The correct order of volatility is CPU registers, RAM, swap, network connections, disk, archived media. This sequence captures the most volatile data first: CPU registers are the most volatile, followed by RAM, then swap, then network connections, then disk, and finally archived media.

Exam trap

Many candidates incorrectly place network connections after disk, assuming they are less volatile. However, network connections are more volatile than disk because they represent active communications that can be lost quickly.

93
MCQhard

During forensic analysis of a compromised server, an analyst needs to preserve evidence in order of volatility. Which of the following actions should the analyst perform FIRST?

A.Collect log files from the system
B.Create a forensic image of the hard drive
C.Run antivirus scan
D.Acquire a memory dump using WinPmem
AnswerD

Volatile memory (RAM) contains transient data such as active network connections, running processes, and unencrypted cryptographic keys that are lost upon system shutdown or reboot. Utilizing a dedicated tool like WinPmem allows analysts to capture a physical memory dump immediately after securing the system. This adheres strictly to the Order of Volatility, ensuring critical, short-lived evidence is preserved before any disk-based collection occurs.

Why this answer

The order of volatility dictates collecting the most perishable evidence first. RAM contents — running processes, network connections, encryption keys, and injected code — vanish on reboot or power loss, so acquiring a memory dump with a tool like WinPmem must be the first action. Only after memory is captured should the analyst move to less volatile sources.

Exam trap

The trap is prioritizing the disk image or logs because they feel like 'the evidence,' when the order of volatility demands the most ephemeral source — RAM — be captured first.

How to eliminate wrong answers

Option A is wrong because log files reside on disk and persist across reboots, making them less volatile than RAM; they should be collected after memory. Option B is wrong because a forensic disk image captures persistent storage, which is far less volatile than memory and can be acquired later without losing data. Option C is wrong because running an antivirus scan modifies the system (quarantining files, altering timestamps, consuming CPU) and can destroy volatile evidence — it is an investigative action, not an evidence-preservation step, and should never precede memory capture.

94
MCQmedium

An organization has experienced a data breach involving personally identifiable information (PII). The incident response team has contained the breach and eradicated the threat. During the post-incident activity phase, which activity is MOST critical to prevent future similar incidents?

A.Resetting all user passwords
B.Updating the firewall rules to block the attacker's IP
C.Conducting a root cause analysis
D.Restoring data from backups
AnswerC

Performing a root cause analysis (RCA) is the definitive post-incident activity required to identify the underlying vulnerabilities and systemic failures that allowed the breach to succeed. By pinpointing the exact vector, security teams can implement permanent, strategic remediation controls to prevent similar incidents.

Why this answer

Conducting a root cause analysis helps identify the underlying vulnerability or weakness that led to the breach, enabling the organization to implement corrective measures and prevent recurrence.

95
MCQeasy

An analyst receives a threat intelligence feed containing IOCs in STIX format. Which of the following BEST describes the purpose of STIX?

A.A protocol for real-time log collection
B.A framework for automating incident response
C.A standardized language for threat intelligence
D.A tool for malware analysis
AnswerC

Structured Threat Information Expression (STIX) is an XML/JSON-based serialization language that standardizes the representation of cyber threat intelligence. It allows organizations to share structured data about threat actors, campaigns, indicators, and tactics in a consistent, machine-readable format.

Why this answer

STIX (Structured Threat Information Expression) is a standardized language and serialization format for representing cyber threat intelligence, including indicators, threat actors, campaigns, and relationships. It is designed to be machine-readable and interoperable, allowing organizations to share threat intelligence consistently. Therefore, the best description is that STIX is a standardized language for threat intelligence.

Exam trap

CS0-004 often tests the difference between STIX and TAXII, and candidates commonly confuse the content format (STIX) with the transport protocol (TAXII) or with incident response automation.

How to eliminate wrong answers

Option A is wrong because real-time log collection is handled by protocols like syslog, SNMP, or APIs, not STIX. Option B is wrong because automating incident response is the role of SOAR platforms and standards like CACAO, not STIX itself. Option D is wrong because malware analysis tools include sandboxes and reverse-engineering frameworks; STIX is a data format, not an analysis tool.

96
MCQmedium

After a DDoS attack, the CSIRT wants to share IOCs with other organizations. Which protocol is specifically designed for automated, real-time threat intelligence sharing?

A.HTTP
B.SMTP
C.TAXII
D.FTP
AnswerC

Trusted Automated eXchange of Indicator Information (TAXII) is an application-layer protocol specifically designed to route cyber threat intelligence (CTI) over HTTPS. It supports common sharing models such as hub-and-spoke or peer-to-peer, allowing CSIRTs to automate the secure distribution and ingestion of STIX-formatted IoCs directly into security tools.

Why this answer

TAXII (Trusted Automated Exchange of Indicator Information) is the protocol for exchanging threat intelligence over HTTPS.

97
MCQhard

During a forensic investigation of a compromised Linux server, the analyst needs to acquire memory for analysis. The system is running and the analyst cannot power it off. Which tool is MOST appropriate for acquiring memory in this scenario?

A.LiME
B.FTK Imager
C.WinPmem
D.dd
AnswerA

LiME (Linux Memory Extractor) is a kernel-mode tool specifically designed for volatile memory acquisition on Linux systems. It operates as a Kernel Loadable Module (LKM), allowing investigators to capture full RAM dumps with minimal footprint and high integrity, even bypassing restrictions that might block user-space memory access.

Why this answer

LiME (Linux Memory Extractor) is a tool designed for acquiring memory from Linux systems while they are running, and it can be loaded as a kernel module without shutting down.

98
MCQeasy

Which of the following is the correct order of volatility for digital evidence?

A.Swap, RAM, CPU registers, disk, logs
B.Disk, RAM, swap, CPU registers, logs
C.RAM, CPU registers, swap, disk, logs
D.CPU registers, RAM, swap, disk, logs
AnswerD

This sequence accurately represents the descending order of volatility according to RFC 3227 guidelines. CPU registers and cache are the most transient, followed by system RAM, then swap/paging files, local hard disks, and finally remote or archived logs. Following this order during an incident response ensures that the most fragile, short-lived digital evidence is preserved before it is overwritten by system processes or power loss.

Why this answer

The order of volatility: CPU registers and cache (most volatile), then RAM, then swap/page file, then disk, then network logs, then archived media (least volatile).

← PreviousPage 2 of 2 · 98 questions total

Ready to test yourself?

Try a timed practice session using only Incident Response and Management questions.