01. Midway through an incident, responders find that the situation does not match any step in the applicable playbook, and following it further would not address what they are seeing.
What is the MOST appropriate response?
a) Suspend the response until the playbook has been revised, reviewed and formally reapproved
b) Continue following the playbook, since deviating from an approved procedure introduces risk
c) Select a different playbook and follow it instead of the one originally identified
d) Escalate to the response lead, document the deviation, and act on the assessed situation
02. An automated discovery sweep returns 1,240 live hosts on a segment where the configuration management database lists 1,090. The extra systems answer on standard ports and sit in the same addressing range.
What should the responder do FIRST with the 150 unmatched systems?
a) Exclude them from the assessment scope, and revisit once the database is updated to list them
b) Treat them as in scope and establish ownership and business function for each
c) Raise a data quality defect against the configuration management database and reconcile at the next review cycle
d) Request that network operations remove the unlisted systems from the segment
03. While building an incident timeline, an analyst finds that an endpoint record and an application record describe the same action but disagree about which account performed it.
What is the MOST appropriate way to handle this in the report?
a) Report the endpoint record, since evidence collected closest to the action is more reliable
b) Omit the action from the timeline, until the discrepancy can be conclusively resolved
c) Record both accounts with their sources, and state that the conflict is unresolved
d) Report the application record, since it reflects the account the application authenticated
04. Before analysis begins, an investigator computes a value over the acquired image and records it in the case file.
What does this establish?
a) That the image can later be shown to be unchanged since acquisition
b) That the image contains no malicious code, which analysis of its contents would otherwise find
c) That the acquisition captured the entire volume successfully
d) That the original system was not modified during acquisition, or afterwards
05. A responder is building the asset inventory for a manufacturing plant's control network. The environment includes programmable logic controllers on a legacy fieldbus, and plant engineering has records of several of them halting when they received unexpected traffic. The inventory still has to be complete enough to scope the vulnerability management program.
Which discovery approach is MOST appropriate for these assets?
a) Full-rate active discovery run from the enterprise network across the routed boundary into the plant
b) Passive monitoring at the plant aggregation switch, identifying devices from the traffic they already generate
c) Credentialed active scanning of the control subnet, scheduled inside the plant's documented weekly maintenance window
d) An unauthenticated port sweep across the control subnet, rate-limited to one probe per second
06. Analysts are closing a high proportion of alerts from one rule as benign, and the team is considering how to respond.
What is the PRIMARY risk of leaving the rule untuned?
a) Other detection rules will be evaluated more slowly, because of the additional platform load
b) The rule will eventually stop firing because the platform suppresses repetitive alerts
c) Analysts become conditioned to dismiss the rule and may close a genuine detection with it
d) The monitoring platform's storage will be consumed by the retained alert records
07. Counsel advises that litigation arising from an incident is likely. The analyst notices that the automated retention job will delete the relevant logs next week.
What must the analyst ensure happens?
a) A copy of the records is exported and stored on the analyst's own workstation
b) The retention period is extended across all log sources in the environment
c) The records are summarized into a report before the retention job removes them
d) The records are placed under legal hold so routine deletion does not remove them
08. An analyst distinguishes between a sign that an incident may occur in the future and a sign that an incident may have already occurred.
Which term describes the first of these?
a) An artifact
b) A precursor
c) A baseline
d) An indicator
09. During a significant incident, several managers begin sending their own updates to different parts of the business. Accounts of the situation start to diverge.
Which measure MOST directly addresses this?
a) Require managers to have their updates reviewed by the response lead before sending
b) Publish the incident case record, allowing managers to consult it directly
c) Issue updates from a single point on a defined schedule to all internal audiences
d) Restrict knowledge of the incident to the response team until it has been resolved
10. Two internal hosts each contact a single external address repeatedly. Host A connects every 60 seconds exactly, always transferring a similar small payload. Host B connects at irregular intervals with widely varying transfer sizes during working hours only.
Which assessment is BEST supported?
a) Host A's regularity is more consistent with automated command-and-control polling
b) Host B's varying transfer sizes are more consistent with staged data exfiltration
c) Neither is suspicious, because command-and-control channels deliberately randomize their intervals
d) Both patterns are equally suspicious, since each involves repeated contact with one external address