Courseiva

CS0-004 · topic practice

Incident Response and Management practice questions

This domain covers the NIST SP 800-61 lifecycle — preparation, detection and analysis, containment/eradication/recovery, and post-incident activity — plus forensic evidence handling. CS0-004 tests it through scenario questions: choosing the right acquisition tool, ordering containment actions, and deciding when to preserve versus restore systems during a live incident.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Incident Response and Management

What the exam tests

What to know about Incident Response and Management

Map every scenario to a NIST SP 800-61 phase and justify the action order. The single most important thing: preserve volatile evidence first, then contain, then eradicate and recover — never destroy data to stop an attack.

Selecting memory acquisition tools such as LiME, WinPmem, or FTK Imager on running hosts

Applying NIST SP 800-61 phases to contain, eradicate, and recover from ransomware and malware

Order of volatility: capturing RAM, network state, and temporary files before disk images

Using SIEM alert triage, log correlation, and indicators of compromise to scope an incident

Watch out for

Common Incident Response and Management exam traps

  • ▸Pulling the plug on a live system to preserve evidence, destroying volatile memory and network connections needed for analysis
  • ▸Jumping straight to eradication or restoration before scoping the incident and preserving forensic evidence
  • ▸Confusing containment with recovery, or treating a business-continuity workaround as incident closure without root-cause analysis

Practice set

Incident Response and Management questions

20 questions · select your answer, then reveal the explanation

An analyst receives an alert about a user account that has been locked out multiple times within an hour. The account belongs to a system administrator. Which incident category does this scenario most likely fall under?

Which of the following is the MOST volatile data according to the order of volatility?

A company has experienced a ransomware attack that encrypted critical servers. The incident response team is in the containment, eradication, and recovery phase. Which THREE actions are part of long-term containment? (Choose three.)

An incident responder needs to collect memory from a Linux system during an incident. Which tool should the responder use?

An analyst is investigating a suspected data breach and needs to preserve network logs. Which of the following actions is MOST appropriate?

A security analyst is performing incident response for a suspected malware outbreak. Which TWO actions are examples of long-term containment? (Select TWO.)

An organization's security team receives a report of a potential insider threat. An employee is suspected of accessing sensitive files without authorization. Which incident category BEST describes this scenario?

During a DDoS attack, the incident response team notices that the attack traffic originates from multiple IP addresses across different countries. The team decides to implement a long-term containment strategy. Which action is MOST appropriate for long-term containment?

During a forensic investigation, an analyst needs to acquire volatile memory from a compromised Linux server running a critical application. The server cannot be powered off. Which tool should the analyst use to capture memory with the least impact on the system?

During a dynamic malware analysis session, a security analyst uses a sandbox to detonate a suspicious file. Which of the following observations would be considered a behavioral indicator of compromise (IOC)?

A security analyst is investigating a suspected insider threat incident. The analyst needs to preserve evidence before containment. Which of the following actions should the analyst prioritize to maintain the integrity of digital evidence?

During a malware outbreak, an incident responder uses YARA rules to detect similar malware across the environment. The responder created a custom YARA rule based on static analysis of the malware sample. Which THREE elements are MOST useful for creating an effective YARA rule for this malware? (Choose THREE.)

A security analyst is performing dynamic malware analysis using a sandbox. The analyst observes that the malware creates a scheduled task that executes a PowerShell command to download a payload from a remote server. Which of the following behavioral IOCs should be prioritized for detection?

A security team is responding to a suspected data breach involving exfiltration of customer data via email. During the containment phase, which TWO actions should the team perform to preserve evidence while preventing further data loss?

A security analyst is responding to an incident involving a compromised user account. The analyst has confirmed that the account was used to access sensitive files. Which TWO of the following actions should the analyst take to contain the incident while preserving evidence? (Choose two.)

During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, an analyst identifies suspicious network traffic from an internal host to a known malicious IP address. Which step should the analyst perform next to validate the alert?

An organization's security team receives an alert about a potential ransomware infection on a critical server. The severity classification is 'high' because the server supports a production database. According to the incident response plan, which containment action should be taken first to minimize data loss?

A forensic analyst is investigating a suspected data breach involving a compromised workstation. The analyst wants to collect volatile data in accordance with the order of volatility. Which sequence of data collection is correct?

After containing a malware outbreak, the incident response team performs static malware analysis on a suspicious executable. Which of the following artifacts would be most helpful in creating a YARA rule to detect variants of the malware?

During dynamic malware analysis in a sandbox, an analyst observes that the malware attempts to connect to a remote IP address on port 443, modifies the Windows registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and drops a DLL in the system32 folder. Which type of IOC is most indicative of persistence?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Incident Response and Management sessions

Start a Incident Response and Management only practice session

Every question in these sessions is drawn from the Incident Response and Management domain — nothing else.

Related practice questions

Related CS0-004 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CS0-004 exam test about Incident Response and Management?
Map every scenario to a NIST SP 800-61 phase and justify the action order. The single most important thing: preserve volatile evidence first, then contain, then eradicate and recover — never destroy data to stop an attack.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Incident Response and Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Incident Response and Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CS0-004 topics?
Use the topic links above to move to related areas, or go back to the CS0-004 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CS0-004 exam covers. They are not copied from any real exam or dump site.