Free CompTIA Cybersecurity Analyst (CySA+) practice — 6 questions on Incident Response and Management, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Incident Response and Management
During a Diamond Model analysis of an intrusion, an analyst maps four core features of the event. The malware sample uses a custom RC4-based encryption routine with a hardcoded key that has been seen in three prior campaigns attributed to the same threat actor. Which Diamond Model feature does this custom encryption routine represent?
The malware's specific technical tooling (the encryption routine/method) is the adversary's 'capability' — the tools, techniques, and malware used to execute the attack.
Question 2 of 6 · Incident Response and Management
A forensic analyst arrives at a compromised server that is still powered on and must collect evidence following the correct order of volatility. Which sequence is correct, from MOST volatile to LEAST volatile?
RFC 3227's order of volatility dictates collecting the most fragile data first: CPU registers and cache (nanoseconds), then RAM contents, then disk data, then archival media/backups, since each successive category persists longer without power or active processes.
Question 3 of 6 · Incident Response and Management
Ransomware is actively encrypting files across multiple hosts on a flat network segment via SMB (port 445). The incident commander needs to stop the spread immediately while preserving the ability to investigate infected hosts. Which containment action is BEST?
Segmentation/isolation via ACLs blocking SMB traffic stops lateral spread immediately without powering down hosts, preserving RAM and running processes for later forensic analysis — this is a standard short-term containment strategy.
Question 4 of 6 · Incident Response and Management
During post-incident review, an analyst wants to identify the underlying root cause of a breach by repeatedly asking 'why' a failure occurred until reaching the fundamental cause, rather than mapping all contributing categories of failure (people, process, technology, environment) visually. Which root cause analysis technique is being used?
The 5 Whys technique involves iteratively asking 'why' a problem occurred, drilling down through causal layers until the true root cause is identified — exactly as described.
Question 5 of 6 · Incident Response and Management
An organization's IR plan has never been tested. Leadership wants a low-cost, low-disruption exercise where key stakeholders discuss their roles and responses to a hypothetical incident scenario in a conference room, without touching production systems. Which type of IR plan test should be conducted FIRST?
A tabletop exercise is a discussion-based walkthrough where stakeholders talk through their roles and decisions for a hypothetical scenario without any operational impact — it is the lowest-cost, least disruptive test and typically the first step in an IR/BC-DR testing program.
Question 6 of 6 · Incident Response and Management
A junior analyst collects a hard drive from a compromised workstation, images it, and stores the original drive in an unlocked supply closet accessible to the whole IT team while working on the image. Legal counsel later says the evidence may be inadmissible. What is the MOST likely reason?
Chain of custody requires that original evidence be secured with strict, documented, and controlled access at all times; storing it in an unlocked closet accessible to unauthorized personnel breaks the chain of custody, creating reasonable doubt about evidence integrity and admissibility.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.