High School IntermediateModule I11Module Assessment

I11 Incident Response Basics Module Test

Complete this twenty-five-question assessment covering incident response readiness, detection, triage, classification, scoping, containment, evidence preservation, timeline building, eradication, recovery, communication, escalation, documentation, post-incident review, corrective actions, residual risk, governance, closure, and portfolio safety.

Readiness Check

Module Test Readiness

0/5 ready

Assessment Rules

How to Use This Module Test

Before revealing answers

Read the full question, compare all choices, and select the strongest evidence-based defensive response.

After revealing answers

Record missed questions, explain why your choice was weaker, and connect the correct answer to the matching lesson.

Scoring

Give yourself one point for each correct answer. Use the score guide only after completing all twenty-five questions.

Professional standard

Strong answers preserve exact evidence, bounded scope, source health, uncertainty, proportionate controls, legitimate workflows, accountable ownership, validation, residual risk, and measurable closure.

Check Your Understanding

I11 Incident Response Basics: 25-Question Module Test

Choose your answers first. Explanations appear only after submission.

1. What should a fictional incident-response program define before an incident occurs?

2. Why should evidence-source health be tested during readiness?

3. Why is business-continuity planning part of incident-response readiness?

4. What should happen first when a fictional alert or user report enters the response process?

5. Why is a high alert severity not enough to confirm a high-severity incident?

6. Which classification best fits unusual fictional activity when important evidence is still missing?

7. What is the strongest description of fictional incident scope?

8. When may a fictional asset be marked reviewed-unaffected?

9. What makes fictional containment defensible?

10. What should happen when a narrow containment control causes unacceptable business impact?

11. What should an evidence index contain?

12. Why should original and normalized timestamps both be preserved?

13. When should a fictional timeline use a time range instead of an exact second?

14. What distinguishes fictional eradication from containment?

15. Which set best represents a known-good fictional recovery baseline?

16. Why are positive and negative tests both required before service restoration?

17. What is the strongest fictional restoration sequence?

18. What should every fictional incident update separate?

19. What makes a fictional escalation defensible?

20. What should happen when an earlier fictional incident update is inaccurate?

21. What is the purpose of a fictional blameless post-incident review?

22. Which statement best separates a direct cause from a contributing condition?

23. What makes a fictional corrective action complete?

24. When may a fictional incident close with residual risk?

25. What is the safest way to create a public portfolio artifact from a fictional incident case?

Score Guide

Interpret Your Result

23–25 correct

Advanced Module Mastery

You can connect readiness, triage, scope, containment, evidence, recovery, communication, improvement, residual risk, and closure across Module I11.

20–22 correct

Strong Readiness

Review missed questions and explain why the strongest answer is better supported than every alternative.

16–19 correct

Developing Readiness

Revisit the matching lessons and repeat the test after completing the mastery checklist.

0–15 correct

More Review Recommended

Focus on evidence quality, scope, proportionate containment, recovery gates, communication, lessons learned, and professional closure.

Mastery Review

Connect Missed Questions to the Correct Lessons

Control area

Lifecycle and readiness

Mastery statement

Preparation, roles, authority, contacts, evidence sources, source health, playbooks, continuity, activation, decision gates, and closure standards.

Review

I11.1

Control area

Detection, triage, and assessment

Mastery statement

Original signals, correlation, source health, classification, confidence, severity, business context, ownership, and reassessment.

Review

I11.2

Control area

Scope and containment

Mastery statement

Affected, suspected, related, unknown, reviewed-unaffected, contained, and recovered scope; authority, continuity, monitoring, rollback, and exit criteria.

Review

I11.3

Control area

Evidence and timeline

Mastery statement

Evidence index, original records, source lineage, handling history, time normalization, conflicts, gaps, confidence, and timeline versions.

Review

I11.4

Control area

Eradication and recovery

Mastery statement

Root-cause correction, known-good baselines, positive and negative testing, staged restoration, source health, business validation, observation, and rollback.

Review

I11.5

Control area

Communication, review, and closure

Mastery statement

Audience-specific updates, escalation, documentation, corrections, blameless review, corrective actions, residual risk, governance, closure, and portfolio safety.

Review

I11.6–I11.8

Defender Habits

I11 Module Mastery Checklist

Portfolio Prompt

Final Module Portfolio Check

Create a one-page fictional Incident Response Basics Summary connecting readiness, one original signal, source health, initial assessment, scope, containment, evidence preservation, timeline, communication, eradication, recovery, post-incident review, one corrective action, residual risk, closure criteria, and owner approval.

Use only fictional systems, users, identities, files, routes, logs, contacts, owners, metrics, timelines, actions, and organizations.
Separate confirmed facts, supported conclusions, alternatives, uncertainty, scope, business impact, decisions, actions, and residual risk.
Show how evidence changes classification, containment, recovery, communication, lessons, and closure.
Do not include real alerts, screenshots, logs, system names, routes, filenames, credentials, contact lists, incident records, recovery details, or private organizational information.

Key Takeaways

What You Should Remember

1.Incident response connects readiness, detection, triage, scope, containment, evidence, recovery, communication, improvement, governance, and closure.
2.Tool severity, dashboard color, one alert, or one source cannot independently prove complete scope or impact.
3.Strong containment preserves evidence and continuity while remaining narrow, authorized, monitored, reversible, owned, and open to reassessment.
4.Evidence preservation and timeline building require original records, lineage, handling history, source health, timestamps, conflicts, gaps, confidence, and visible revisions.
5.Recovery should correct validated causes and prove approved and denied behavior across production and recovery through staged restoration and observation.
6.Communication, lessons learned, corrective actions, residual risk, governance, and closure should remain accurate, traceable, validated, and portfolio-safe.

Navigation

Return to Module I11