D340 Cyber Defense and Countermeasures - Set 4 - Part 1
Test your knowledge of technical writing concepts with these practice questions. Each question includes detailed explanations to help you understand the correct answers.
Question 1: What are the standard phases of incident response?
Question 2: Why is the preparation phase considered the most important?
Question 3: What is the goal of the containment phase?
Question 4: What is the difference between short-term and long-term containment?
Question 5: Why might immediately powering off a compromised system be a mistake?
Question 6: What is the order of volatility principle in forensics?
Question 7: What is chain of custody?
Question 8: Why is a forensic image preferred over examining the original disk?
Question 9: What is a hash used for in digital forensics?
Question 10: What is the eradication phase concerned with?
Question 11: Why is identifying the initial access vector critical before recovery?
Question 12: What is the risk of restoring from a backup taken after the compromise began?
Question 13: What is dwell time in an incident?
Question 14: Why should credentials be reset after a significant compromise?
Question 15: What is the recovery phase focused on?
Question 16: Why is enhanced monitoring important immediately after recovery?
Question 17: What is the purpose of the lessons learned phase?
Question 18: When should the lessons learned review ideally occur?
Question 19: What is an incident response playbook?
Question 20: Why are predefined roles important in incident response?
Need Guaranteed Results?
Our exam support service guarantees you'll pass your OA on the first attempt. Pay only after you pass!
Get Exam Support