Courseiva

CCNA Incident Handling And Response Questions

15 questions · Incident Handling And Response topic · All types, answers revealed

1
MCQeasy

A security analyst receives an alert that a workstation's antivirus detected and quarantined a known trojan. The endpoint is still running and the user reports no unusual behavior. According to the SANS six-step incident handling process, which phase is the analyst currently in?

A.Identification
B.Eradication
C.Containment
D.Recovery
AnswerA

Identification is the phase where an event is confirmed as an incident and its scope is assessed. The antivirus alert and quarantine confirmation constitute detection and initial validation of a real security event. The analyst has not yet contained, eradicated, or recovered anything, so Identification is the correct phase according to the SANS PICERL model.

Why this answer

The SANS incident handling process begins with Preparation, followed by Identification, Containment, Eradication, Recovery, and Lessons Learned. When an alert fires and an analyst validates that a genuine security event has occurred, the activity maps to Identification. No containment, eradication, or recovery actions have been described, so the scenario sits squarely in the Identification phase.

Exam trap

The trap here is confusing the antivirus's automatic quarantine action with the Eradication phase, when quarantine is merely part of detecting and validating the incident.

2
Multi-Selecthard

A company's incident response plan requires a formal lessons-learned review after a major ransomware incident. Which TWO activities are appropriate during the Post-Incident Activity phase? (Choose two.)

Select 2 answers
A.Reimage all affected endpoints and restore data from the most recent backups.
B.Conduct a meeting with stakeholders to review what worked, what failed, and how to improve the plan.
C.Update the incident response plan and detection rules based on findings from the review.
D.Isolate the compromised network segment to prevent the ransomware from spreading further.
E.Eradicate the ransomware binaries and remove persistence mechanisms from infected hosts.
AnswersB, C

The Post-Incident Activity phase centers on reviewing the incident to improve future response. A structured meeting with stakeholders captures lessons, identifies gaps in the plan, and assigns improvements. This directly fulfills the phase's purpose of turning experience into actionable changes, making it a correct activity for this scenario.

Why this answer

The Post-Incident Activity phase is about learning from the incident and improving future response. Holding a stakeholder review meeting and updating the IR plan and detection rules based on findings both directly serve that purpose. Recovery and eradication actions belong to earlier phases, and containment is likewise an earlier-phase activity, so they are not appropriate here.

Exam trap

The trap here is conflating recovery actions, such as reimaging and restoring backups, with post-incident review activities, which focus on analysis and process improvement.

3
MCQmedium

During an investigation, an analyst finds that a compromised host has an outbound connection to a known command-and-control IP every 60 seconds. The host is on a production VLAN with other servers. Which containment strategy best limits the adversary's access while preserving evidence for later analysis?

A.Immediately power off the host to sever the C2 channel and prevent further data exfiltration.
B.Change the host's IP address and update DNS records to redirect the adversary to a honeypot.
C.Block the C2 IP at the perimeter firewall and leave the host online to observe further adversary behavior.
D.Isolate the host using network access control or an EDR network containment feature, keeping it powered on for memory capture.
AnswerD

Network isolation via NAC or EDR containment severs the adversary's access while keeping the host running, so volatile memory and active connections remain available for capture. This limits spread to other production servers and preserves evidence, satisfying both containment and forensic requirements. It is the most balanced strategy for a live compromised host on a shared VLAN.

Why this answer

Effective containment must both stop the adversary's access and preserve evidence for later analysis. Isolating the host through NAC or EDR network containment severs the C2 channel and prevents lateral movement across the production VLAN while leaving the system powered on, so volatile memory and active connections can still be captured. This balances operational risk with forensic integrity.

Exam trap

The trap here is thinking that blocking a single C2 IP is sufficient containment, when the adversary can pivot to fallback infrastructure and continue operating on the live host.

4
MCQeasy

Which document is essential to have in place before an incident occurs to ensure legal and regulatory compliance regarding data privacy and breach notification?

A.The Incident Response Plan
B.A list of all employee hardware serial numbers
C.The corporate employee handbook
D.The server room floor plan
AnswerA

The Incident Response Plan is the primary document that outlines the steps to take during a breach, including legal and regulatory notification requirements. Having this plan in place ensures that legal obligations are met promptly, reducing the risk of non-compliance penalties and ensuring consistent communication with regulatory authorities.

Why this answer

An Incident Response Plan (IRP) defines the procedures, roles, and communication paths required during a breach. It is essential for compliance because it dictates the timeline and requirements for notifying regulators and affected parties. Without a pre-established plan, organizations often fail to meet legal reporting deadlines, resulting in significant fines and loss of stakeholder trust, making the IRP a foundational piece of the response process.

Exam trap

Candidates often confuse the Incident Response Plan with a Disaster Recovery Plan or a Business Continuity Plan, failing to recognize that the IRP specifically governs the response to security incidents.

5
MCQmedium

An analyst receives an alert that a server's CPU usage has spiked to 100% and is generating outbound traffic to a known command-and-control IP address. The server is critical for a production application. After confirming the compromise, the analyst decides to isolate the server from the network. Which incident response phase does this action fall under?

A.Containment
B.Preparation
C.Recovery
D.Eradication
AnswerA

Containment aims to limit the scope and impact of an incident. Isolating the server prevents further lateral movement and stops the attacker from exfiltrating data or causing more damage. This is a classic containment action, as it separates the affected system from the rest of the network while allowing forensic analysis to continue.

Why this answer

The correct answer is containment because isolating a compromised server is a direct step to limit the incident's spread and impact. Containment actions are taken immediately after detection to prevent further damage, while eradication and recovery come later. Preparation is pre-incident, and recovery restores normal operations.

Exam trap

The trap here is confusing containment with eradication; isolation limits spread but does not remove the threat.

6
MCQhard

A security team is conducting a post-incident review after a successful ransomware attack. The team identifies that the initial infection vector was a phishing email that delivered a malicious macro. The team wants to improve future response. Which of the following actions is MOST effective for preventing a similar incident from succeeding in the future?

A.Disable macros in Microsoft Office applications by default and only allow signed macros from trusted publishers.
B.Implement a security awareness training program that teaches employees to recognize phishing emails.
C.Deploy an endpoint detection and response (EDR) solution to detect and block malicious macro execution.
D.Configure email filtering to block all emails with macro-enabled attachments.
AnswerA

Disabling macros by default and allowing only signed macros from trusted publishers directly prevents the execution of malicious macros, which was the initial infection vector. This is a technical control that enforces a secure configuration and is highly effective because it blocks the attack technique regardless of user action. It aligns with the principle of least functionality and is a recommended security baseline.

Why this answer

The most effective action is to disable macros by default and allow only signed macros from trusted publishers. This directly prevents the malicious macro from executing, regardless of whether the phishing email reaches the user. It is a technical control that enforces a secure configuration and reduces the attack surface.

While other measures like training, EDR, and email filtering add defense in depth, they are not as reliable in stopping this specific vector. Disabling macros is a best practice recommended by security organizations.

Exam trap

The trap here is choosing a detective or user-dependent control like training or EDR when a preventive technical control that directly blocks the attack technique is available and more effective.

7
MCQmedium

Refer to the exhibit. Which type of attack is being mitigated by the application framework, and what incident phase should this alert trigger?

A.SQL Injection; Containment
B.Cross-Site Scripting; Identification
C.Cross-Site Request Forgery; Eradication
D.Buffer Overflow; Preparation
AnswerB

The log displays an XSS payload injected into a form field, which the framework correctly blocked. This activity represents an active probe by an attacker. It must move to the Identification phase to determine the extent of the scanning or exploitation attempts being conducted against the web application.

Why this answer

The exhibit shows a Cross-Site Scripting (XSS) attempt blocked by the application's input validation layer. This should trigger the Identification phase of the incident response lifecycle. Even though the attack was blocked, it indicates an attacker is actively probing the application for vulnerabilities.

Early detection allows the team to block the source IP and verify if other, more successful, attempts were made against the infrastructure.

Exam trap

Candidates frequently confuse the 'Identification' phase with 'Containment'. They assume that because the attack was blocked, the incident is closed, overlooking that identification is necessary to assess the threat actor's intent.

8
MCQhard

An analyst is examining a Linux server suspected of compromise. The analyst runs a script that lists open network connections, running processes, and loaded kernel modules, but does not copy the binaries to external media. Which principle is the analyst applying?

A.Chain of custody, by documenting each piece of evidence collected.
B.Order of volatility, by collecting live system state before it changes.
C.Least privilege, by limiting the analyst's access to system resources.
D.Defense in depth, by using multiple tools to examine the system.
AnswerB

The analyst is capturing volatile data such as network connections, processes, and kernel modules while the system is live, before it changes or is lost. This directly follows the order of volatility principle, which prioritizes the most perishable evidence first. Running the script before copying binaries reflects that prioritization, making this the correct principle.

Why this answer

The order of volatility directs responders to collect the most perishable evidence first, such as network connections, running processes, and kernel modules, before they change or disappear. By gathering this live state before copying static binaries, the analyst is prioritizing volatile data. Chain of custody, least privilege, and defense in depth address different concerns and do not describe this collection sequence.

Exam trap

The trap here is assuming that copying binaries to external media is the first step, when volatile live state must be captured before less perishable artifacts.

9
Multi-Selecthard

During an investigation, you discover a persistent backdoor. Which THREE actions should be included in the Eradication phase?

Select 3 answers
A.Resetting compromised user passwords
B.Analyzing the memory dump for malware signatures
C.Patching the vulnerability used for initial access
D.Re-imaging infected systems from a known-good source
E.Drafting an incident report for executive leadership
AnswersA, C, D

If an attacker has stolen credentials, simply removing the backdoor is insufficient because the attacker can still authenticate using the compromised account. Resetting passwords is a mandatory eradication step to prevent the adversary from regaining access via legitimate authentication channels after the malicious artifacts are removed.

Why this answer

Eradication aims to completely remove the adversary's presence. Simply deleting a file is rarely sufficient; attackers often leave multiple persistence mechanisms or backdoors. By resetting credentials, patching the underlying vulnerability, and re-imaging systems, the organization ensures that the attacker cannot easily return, effectively closing the window of opportunity that allowed the initial unauthorized access to occur and persist.

Exam trap

Candidates often choose only one action (like patching) while ignoring that eradication must address the attacker's persistence mechanisms, such as compromised credentials and backdoors, to be truly effective.

10
MCQhard

A junior analyst at a healthcare provider receives a call from the help desk: a radiology workstation is behaving erratically and displaying a ransom note. The analyst immediately opens a remote session, logs in with domain administrator credentials, and begins deleting suspicious files in the user's startup folder. The workstation is still powered on and connected to the network. Which incident handling principle did the analyst MOST directly violate?

A.Containment must precede eradication to prevent the threat from spreading to other systems.
B.The analyst used domain administrator credentials, which violates the principle of least privilege.
C.The analyst failed to preserve the chain of custody for the workstation's hard drive.
D.The analyst should have escalated to senior management before taking any action on the workstation.
AnswerA

The analyst deleted files before containing the workstation, leaving it networked and allowing the malware to spread or communicate. Proper sequence is containment then eradication. Deleting files with elevated credentials also risks tipping off the attacker and destroying volatile evidence. This is the most direct violation of the containment-first principle.

Why this answer

The analyst began eradication (deleting files) while the compromised workstation remained powered on and connected to the network. This violates the containment-first principle: without isolating the system, malware can spread laterally, communicate with command-and-control, or re-infect. Proper incident handling isolates the host—via network disconnection or VLAN isolation—before removing malicious artifacts.

Containment limits damage and preserves evidence for later analysis.

Exam trap

The trap here is assuming that immediate deletion of malicious files constitutes effective response, when in fact containment must occur first to prevent spread and preserve evidence.

11
MCQmedium

A responder is preparing to image a compromised Windows server's memory before shutting it down. The server hosts a critical database and management insists on minimal downtime. Which action best preserves the most volatile evidence while respecting the operational constraint?

A.Disconnect the server from the network, then capture memory after confirming no active sessions remain.
B.Capture a full physical memory dump using a trusted tool, then proceed with containment and shutdown.
C.Shut down the server immediately to prevent lateral movement, then image the disk on a write blocker.
D.Run a full antivirus scan and collect the resulting log before capturing memory.
AnswerB

Physical memory is the most volatile evidence and contains running processes, network connections, and injected code that vanish on shutdown. Capturing it first with a trusted, forensically sound tool satisfies the order of volatility while allowing containment afterward. This balances evidentiary integrity with the operational need to limit downtime, making it the best action in this scenario.

Why this answer

The order of volatility dictates that the most perishable evidence, such as RAM contents, be collected first. A physical memory dump captures running processes, network connections, and in-memory-only malware before containment actions alter or destroy them. Once memory is secured, the responder can contain and shut down the server, satisfying both forensic integrity and the operational requirement to minimize downtime.

Exam trap

The trap here is assuming that shutting down quickly is always the safest containment step, when it actually destroys the most volatile and often most valuable evidence.

12
MCQhard

After a major security breach, the incident response team conducts a lessons-learned meeting. The team identifies that the initial detection was delayed because log sources were not properly integrated into the SIEM. Which phase of the incident response lifecycle does this finding primarily aim to improve?

A.Preparation
B.Detection and Analysis
C.Containment, Eradication, and Recovery
D.Post-Incident Activity
AnswerA

The lessons-learned meeting is part of the post-incident activity phase, but the specific finding about log integration directly addresses preparation. Improving log sources and SIEM integration enhances future readiness and detection capabilities. Preparation encompasses building and maintaining the tools and processes needed to respond effectively, so this finding aims to strengthen that phase.

Why this answer

The finding that log sources were not integrated into the SIEM points to a gap in preparation. Preparation involves setting up logging, monitoring, and detection tools. By addressing this, the team enhances future detection capabilities.

While the review occurs in Post-Incident Activity, the corrective action targets Preparation.

Exam trap

The trap here is assuming the phase where the review occurs is the phase being improved, rather than the phase the finding addresses.

13
MCQhard

Refer to the exhibit. An analyst observes this command execution on a workstation. Which immediate action represents the most effective containment strategy?

A.Reboot the workstation immediately
B.Isolate the workstation from the network
C.Delete the PowerShell process
D.Update the antivirus definitions
AnswerB

Isolating the host prevents the attacker from issuing further commands or exfiltrating data, effectively containing the threat. By cutting the network path, you stop the malicious script from reaching its destination without destroying the volatile memory evidence needed to identify the full scope of the attack activity.

Why this answer

The exhibit shows base64 encoded PowerShell execution, commonly used for malicious script downloads. Immediate containment requires isolating the endpoint from the network to prevent further outbound connections to C2 servers. By severing the network connection, responders prevent the attacker from executing additional instructions, exfiltrating data, or establishing secondary persistence mechanisms while the forensic investigation proceeds offline.

Exam trap

Candidates often suggest running a malware scan or deleting the script, which allows the attacker to maintain C2 connectivity while the responder works, failing to prioritize immediate containment.

14
Multi-Selectmedium

A security analyst is responding to a confirmed malware infection on a critical server. The analyst has already contained the infection by isolating the server from the network. According to the incident handling process, which TWO actions should the analyst perform during the eradication phase? (Choose two.)

Select 2 answers
A.Conduct a post-incident review to document lessons learned.
B.Apply security patches and updates to the server's operating system and applications.
C.Restore the server from a known good backup taken before the infection.
D.Identify and remove all malicious files and processes from the server.
E.Monitor network traffic for signs of re-infection.
AnswersB, D

Applying security patches and updates is part of eradication because it addresses the vulnerability that may have been exploited. Even if the malware is removed, without patching, the server remains vulnerable to re-infection. Eradication involves not only removing the threat but also eliminating the root cause. Patching is a preventive measure that strengthens the system against future attacks.

Why this answer

The correct actions are to identify and remove all malicious files and processes, and to apply security patches and updates. Eradication is the phase where the threat is eliminated from the environment. This includes removing malware and addressing the vulnerability that allowed the infection.

Patching ensures that the same attack vector cannot be used again. Restoring from backup, post-incident review, and monitoring are associated with recovery or post-incident activities, not eradication.

Exam trap

The trap here is confusing recovery actions like restoring from backup with eradication actions, which focus on removing the threat and its root cause.

15
MCQmedium

An organization is deploying an automated incident response tool. Which requirement is most important to ensure the tool's effectiveness during a high-severity security incident?

A.Integration with the social media monitoring platform
B.Integration with external threat intelligence feeds
C.Pre-defined and validated response playbooks
D.Unlimited cloud storage for log retention
AnswerC

Automated response tools rely on playbooks to determine actions. If these are not pre-defined and tested, the tool could inadvertently disrupt business operations. Validated playbooks ensure the automation performs safe and effective containment actions without requiring manual intervention, which is essential during a fast-moving, high-severity security incident.

Why this answer

Automated tools must have clear, pre-defined playbooks. If automation is used without strict, validated logic, it may trigger unintended consequences, such as locking out critical production services or deleting valid data during an active attack. Effective automation requires accurate context to prevent the incident response tool from causing more operational downtime than the actual security threat it is designed to mitigate during a crisis.

Exam trap

Candidates often prioritize the 'speed' of the tool over the 'accuracy' of the playbooks, missing that unvalidated automation can cause catastrophic self-denial-of-service during a critical incident.

Ready to test yourself?

Try a timed practice session using only Incident Handling And Response questions.