Free Systems Security Certified Practitioner practice — 6 questions on Incident Response and Recovery, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 4: Incident Response and Recovery
During incident analysis of a suspected memory-resident rootkit on a live production server, the incident handler has only minutes before the system must be taken offline for business reasons. Following the order of volatility principle, which artifact should be collected FIRST?
RAM is the most volatile data source and is lost immediately when the system is powered down or rebooted. Per the order of volatility, memory must be captured before less volatile sources such as disk, logs, or removable media.
Question 2 of 6 · Domain 4: Incident Response and Recovery
A financial services company must achieve an RTO of 4 hours for its core trading platform, but budget constraints prohibit maintaining a fully mirrored production environment at a secondary location. The secondary site currently has power, cooling, network connectivity, and pre-configured hardware, but application data and software are only synchronized twice per day. Which type of alternate site does this describe?
A warm site has partially configured infrastructure — hardware, power, and connectivity in place — but requires some data or software restoration before becoming fully operational. Twice-daily syncing and an hours-scale RTO match this profile exactly.
Question 3 of 6 · Domain 4: Incident Response and Recovery
An SSCP is transferring a forensic disk image to a third-party analysis lab for further review as part of an incident investigation. To preserve the integrity of the chain of custody documentation, which piece of information is MOST critical to record at the moment of transfer?
Recording the cryptographic hash values before and after transfer allows verification that the evidence was not altered in transit, which is the core integrity assurance required for chain of custody.
Question 4 of 6 · Domain 4: Incident Response and Recovery
An organization detects a compromised internal server communicating with a known command-and-control IP address. The incident response team immediately isolates the server on a quarantine VLAN with no internet access while investigation continues. Which incident response phase does this action represent?
Isolating an affected system to prevent further spread or communication with attacker infrastructure is the definition of containment — limiting the scope and impact of the incident before the threat is removed.
Question 5 of 6 · Domain 4: Incident Response and Recovery
A company backs up its file server nightly using an incremental backup strategy, with a full backup performed every Sunday. If the server fails on Thursday morning, how many backup sets must be restored, in sequence, to bring the system to the most recent recoverable state?
Incremental backups capture only changes since the last backup of any type. Restoring the full data set requires the last full backup plus every subsequent incremental in sequence — in this case Sunday's full plus Monday, Tuesday, and Wednesday incrementals (four sets total).
Question 6 of 6 · Domain 4: Incident Response and Recovery
During an ongoing incident investigation, a system administrator who is not part of the incident response team discovers a compromised workstation and, trying to be helpful, copies suspicious files to a USB drive and then reboots the machine to "see if the problem clears." Which BEST describes the consequence of this action from a forensic investigation standpoint?
Rebooting a live compromised system destroys volatile memory contents and active network connection state. Additionally, copying files without a forensically sound process can alter file metadata such as access timestamps, both of which undermine the evidentiary value of the system.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.