I11 Incident Response Basics Module Test
Complete this twenty-five-question assessment covering incident response readiness, detection, triage, classification, scoping, containment, evidence preservation, timeline building, eradication, recovery, communication, escalation, documentation, post-incident review, corrective actions, residual risk, governance, closure, and portfolio safety.
Readiness Check
Module Test Readiness
0/5 ready
Assessment Rules
How to Use This Module Test
Before revealing answers
Read the full question, compare all choices, and select the strongest evidence-based defensive response.
After revealing answers
Record missed questions, explain why your choice was weaker, and connect the correct answer to the matching lesson.
Scoring
Give yourself one point for each correct answer. Use the score guide only after completing all twenty-five questions.
Professional standard
Strong answers preserve exact evidence, bounded scope, source health, uncertainty, proportionate controls, legitimate workflows, accountable ownership, validation, residual risk, and measurable closure.
Check Your Understanding
I11 Incident Response Basics: 25-Question Module Test
Choose your answers first. Explanations appear only after submission.
1. What should a fictional incident-response program define before an incident occurs?
2. Why should evidence-source health be tested during readiness?
3. Why is business-continuity planning part of incident-response readiness?
4. What should happen first when a fictional alert or user report enters the response process?
5. Why is a high alert severity not enough to confirm a high-severity incident?
6. Which classification best fits unusual fictional activity when important evidence is still missing?
7. What is the strongest description of fictional incident scope?
8. When may a fictional asset be marked reviewed-unaffected?
9. What makes fictional containment defensible?
10. What should happen when a narrow containment control causes unacceptable business impact?
11. What should an evidence index contain?
12. Why should original and normalized timestamps both be preserved?
13. When should a fictional timeline use a time range instead of an exact second?
14. What distinguishes fictional eradication from containment?
15. Which set best represents a known-good fictional recovery baseline?
16. Why are positive and negative tests both required before service restoration?
17. What is the strongest fictional restoration sequence?
18. What should every fictional incident update separate?
19. What makes a fictional escalation defensible?
20. What should happen when an earlier fictional incident update is inaccurate?
21. What is the purpose of a fictional blameless post-incident review?
22. Which statement best separates a direct cause from a contributing condition?
23. What makes a fictional corrective action complete?
24. When may a fictional incident close with residual risk?
25. What is the safest way to create a public portfolio artifact from a fictional incident case?
Score Guide
Interpret Your Result
23–25 correct
Advanced Module Mastery
You can connect readiness, triage, scope, containment, evidence, recovery, communication, improvement, residual risk, and closure across Module I11.
20–22 correct
Strong Readiness
Review missed questions and explain why the strongest answer is better supported than every alternative.
16–19 correct
Developing Readiness
Revisit the matching lessons and repeat the test after completing the mastery checklist.
0–15 correct
More Review Recommended
Focus on evidence quality, scope, proportionate containment, recovery gates, communication, lessons learned, and professional closure.
Mastery Review
Connect Missed Questions to the Correct Lessons
Control area
Lifecycle and readiness
Mastery statement
Preparation, roles, authority, contacts, evidence sources, source health, playbooks, continuity, activation, decision gates, and closure standards.
Review
I11.1
Control area
Detection, triage, and assessment
Mastery statement
Original signals, correlation, source health, classification, confidence, severity, business context, ownership, and reassessment.
Review
I11.2
Control area
Scope and containment
Mastery statement
Affected, suspected, related, unknown, reviewed-unaffected, contained, and recovered scope; authority, continuity, monitoring, rollback, and exit criteria.
Review
I11.3
Control area
Evidence and timeline
Mastery statement
Evidence index, original records, source lineage, handling history, time normalization, conflicts, gaps, confidence, and timeline versions.
Review
I11.4
Control area
Eradication and recovery
Mastery statement
Root-cause correction, known-good baselines, positive and negative testing, staged restoration, source health, business validation, observation, and rollback.
Review
I11.5
Control area
Communication, review, and closure
Mastery statement
Audience-specific updates, escalation, documentation, corrections, blameless review, corrective actions, residual risk, governance, closure, and portfolio safety.
Review
I11.6–I11.8
Defender Habits
I11 Module Mastery Checklist
Portfolio Prompt
Final Module Portfolio Check
Create a one-page fictional Incident Response Basics Summary connecting readiness, one original signal, source health, initial assessment, scope, containment, evidence preservation, timeline, communication, eradication, recovery, post-incident review, one corrective action, residual risk, closure criteria, and owner approval.
Key Takeaways
What You Should Remember
Navigation