Security Incident Investigation Quiz

5 questions Pass: 70% +25 pts

Quiz covering Security and Deployment Issues

Security Incident Investigation Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    During a security incident, what is the primary purpose of creating a forensic image of a compromised drive before analysis?

  2. 2

    You notice an unusual spike in outbound traffic from a web server to an unknown IP address. What is the most appropriate first step in the incident response process?

  3. 3

    Which of the following is considered a 'volatile' data source that should be collected first during an incident investigation?

  4. 4

    While investigating a compromise, you find an entry in the web server access logs showing a 'POST' request to a hidden PHP script with base64 encoded parameters. What does this suggest?

  5. 5

    You are performing a post-mortem analysis on a Linux server. The attacker used 'timestomping' to hide their activity. Which forensic technique is most effective at identifying this manipulation?