Which of the following correctly identifies the phases of a typical incident response lifecycle?
Opening subject page...
Loading your content
CPA Isc Quiz
Practice Incident Response And Breach Notification Procedures in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
Question 1 / 20
0 of 20 answered
Which of the following correctly identifies the phases of a typical incident response lifecycle?
This quiz focuses on Incident Response And Breach Notification Procedures, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
Which of the following correctly identifies the phases of a typical incident response lifecycle?
Explanation: The NIST SP 800-61 incident response lifecycle has six phases: Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post-Incident Activity. Answer C is correct. Answer A is COBIT management phases. Answer B is the NIST Cybersecurity Framework functions. Answer D is a generic process model.
During a ransomware incident, the IT team's first priority should be to:
Explanation: Containment - isolating affected systems - is the first priority to stop ransomware from spreading to additional systems. Investigation, notification, and recovery follow containment. Answer A is correct. Paying ransom (B) is a last resort. Root cause analysis (C) occurs after containment. Customer notification (D) follows assessment of data exposure.
The primary purpose of the 'eradication' phase of incident response is to:
Explanation: Eradication focuses on completely removing the attacker's presence and tools from the environment - not just stopping the immediate attack but eliminating all footholds. Answer B is correct. System restoration (A) is the recovery phase. Stakeholder notification (C) occurs during and after containment. Lessons learned (D) are post-incident activities.
An organization's incident response plan designates a Computer Security Incident Response Team (CSIRT). The CSIRT should include representatives from which functions?
Explanation: Effective incident response requires cross-functional coordination: IT handles technical response, legal manages liability and regulatory obligations, communications manages external messaging, HR addresses employee-related matters, and business units understand business impact. Answer C is correct. Technical staff alone (A) cannot manage legal, PR, or business implications. Management and legal alone (B) cannot execute technical response. External agencies (D) may be involved but do not constitute the internal CSIRT.
Which of the following best describes the purpose of a 'tabletop exercise' in incident response preparedness?
Explanation: Tabletop exercises test incident response knowledge and coordination through discussion of simulated scenarios - identifying gaps in procedures, communication, and decision-making without the risk and cost of live exercises. Answer A is correct. Full system failover (B) is a full-scale exercise. Physical security drills (C) test physical controls. Policy reviews (D) assess documentation.
Which of the following is the most important document to maintain during an incident for both operational and legal purposes?
Explanation: A detailed incident log provides the authoritative record of what happened, when, by whom, and why - essential for regulatory reporting, legal proceedings, lessons learned, and demonstrating due diligence. Answer A is correct. Backups (B) are important for recovery. Employee notification lists (C) are one element of documentation. Insurance policies (D) are business documents, not incident records.
An organization detects a breach and finds evidence that attackers had access for 45 days before detection. This period between initial compromise and detection is called:
Explanation: Dwell time measures how long an attacker operates undetected within a network - a key indicator of detection capability maturity. Shorter dwell time means faster detection and less damage. Answer C is correct. RTO (A) measures recovery speed. MTTR (B) measures response time after detection. The notification window (D) is a regulatory compliance concept.
When a breach notification is sent to affected individuals, which of the following information should typically be included?
Explanation: Breach notifications should be clear and actionable - explaining the incident, what data was affected, organizational response actions, protective steps individuals can take, and how to get help. Answer A is correct. Technical attack details (B) are not helpful to individuals and may aid further attacks. Employee names (C) are confidential. Full data inventories (D) are not required and may raise additional privacy concerns.
An organization's incident response plan includes a 'containment strategy decision tree.' The primary purpose of this decision tool is to:
Explanation: A containment decision tree helps responders quickly determine the right containment strategy for different incident types - balancing the urgency to stop spread against the need to maintain critical operations. Answer D is correct. Regulatory routing (A), cost calculation (B), and root cause identification (C) are separate activities in the IR lifecycle.
A company discovers that an employee's laptop containing unencrypted customer data was stolen. Which of the following is the organization's most immediate legal obligation?
Explanation: A stolen laptop with unencrypted customer data is likely a reportable breach - the organization must immediately assess what data was on the device and determine applicable notification requirements under state, federal, and international laws. Answer B is correct. Laptop replacement (A) is an operational matter. A police report (C) alone is insufficient. Waiting 30 days (D) would likely violate notification deadlines.
Which of the following best describes the 'recovery' phase of incident response?
Explanation: Recovery focuses on restoring normal operations safely - rebuilding systems, restoring data from verified clean backups, and confirming functionality before re-entering production. Answer A is correct. Analyzing indicators of compromise (B) is detection and analysis. Removing malware (C) is eradication. Stakeholder communication (D) runs throughout the IR lifecycle.
An organization's incident response team is investigating a potential breach and discovers log files that show unauthorized access. The team should:
Explanation: Log files are critical evidence - they must be preserved in their original, unmodified state with proper chain of custody to be usable in legal proceedings or regulatory investigations. Answer D is correct. Deleting (A) or modifying (C) logs is evidence tampering. Public sharing (B) may alert attackers and compromise the investigation.
Which of the following is the most critical element of an effective incident response plan?
Explanation: Clarity about who does what, who decides what, and how information flows is the foundation of effective incident response - confusion about roles during an active incident wastes critical time. Answer B is correct. Asset inventories (A) support response but are not the most critical IR element. Threat actor lists (C) and MSSP contracts (D) support security programs but are not foundational to IR plan effectiveness.
An organization learns that a former employee may have exfiltrated sensitive financial data before leaving. Which of the following is the most appropriate first step in the incident response process?
Explanation: Evidence preservation is the critical first step - disabling accounts and preserving logs before the former employee can be alerted or evidence is overwritten. Answer A is correct. Contacting the former employee (B) alerts them and may result in evidence destruction. Customer notification (C) is premature before scope is determined. System restoration (D) may destroy evidence and is premature.
Which of the following metrics best measures the effectiveness of an organization's incident response capability?
Explanation: MTTD and MTTR measure the core effectiveness dimensions of incident response: detection speed (how quickly threats are found) and response speed (how quickly they are controlled). Shorter times mean less damage. Answer C is correct. Incident count (A) reflects threat volume. Team size (B) and budget allocation (D) are resource metrics, not effectiveness measures.
An organization's incident response plan requires that any incident involving personal data be escalated to the privacy officer within 4 hours of identification. During an audit, the auditor finds that 6 of 10 sampled incidents involving personal data were not escalated to the privacy officer at all. The auditor should:
Explanation: A 60% failure rate in escalating personal data incidents to the privacy officer means notification obligations were likely not assessed - a significant compliance and legal risk. Answer B is correct. Resolution of incidents (A) does not substitute for proper escalation. Officer availability (C) is irrelevant if escalation did not occur. The plan's requirement is mandatory, not aspirational (D).
Under GDPR, when must organizations notify the relevant supervisory authority following a personal data breach?
Explanation: GDPR Article 33 requires supervisory authority notification within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in risk to individuals' rights and freedoms. Answer D is correct. 24 hours (A) is too short and not required. 30 days (B) exceeds the requirement. The threshold is not based on individual count (C).
Under U.S. state breach notification laws, notification to affected individuals is generally required when:
Explanation: Most U.S. state breach notification laws trigger individual notification when defined categories of sensitive personal information (PII, financial data, health data) are compromised - particularly when unencrypted. Answer D is correct. Not all unauthorized access triggers notification (A). Thresholds (B) vary by state. Legal triggers, not customer service decisions (C), mandate notification.
A company's incident response plan has not been updated in three years and does not reflect the current IT infrastructure, key contacts, or regulatory requirements. The primary risk of this outdated plan is:
Explanation: An outdated IR plan leads to confusion, delays, and missed obligations during an actual incident - exactly when clarity and speed matter most. Answer B is correct. External auditors may note the gap (A) but the operational risk is more significant. Insurance premiums (C) are not automatically affected. Training (D) is unrelated.
Which of the following scenarios would trigger a SEC cybersecurity incident disclosure requirement for a publicly traded company under the SEC's 2023 cybersecurity disclosure rules?
Explanation: The SEC's 2023 cybersecurity rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining the incident is material. Answer C is correct. Disclosure is not required for all incidents (A). Materiality is broader than just customer data theft (B). The rules apply to all material incidents, not just international ones (D).