Home

Tutoring

Subjects

Live Classes

Study Coach

Essay Review

On-Demand Courses

Colleges

Games


Sign up

Log in

Opening subject page...

Loading your content

Practice

  • All Subjects
  • Algebra Flashcards
  • SAT Math Practice Tests
  • Math Question of the Day
  • Live Classes
  • On-Demand Courses

Varsity Tutors

  • Find a Tutor
  • Test Prep
  • Online Classes
  • K-12 Learning
  • College Search
  • VarsityTutors.com

© 2026 Varsity Tutors. All rights reserved.

← Back to quizzes

CPA Isc Quiz

CPA Isc Quiz: Incident Response And Breach Notification Procedures

Practice Incident Response And Breach Notification Procedures in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

Question 1 / 20

0 of 20 answered

Which of the following correctly identifies the phases of a typical incident response lifecycle?

Select an answer to continue

What this quiz covers

This quiz focuses on Incident Response And Breach Notification Procedures, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

Which of the following correctly identifies the phases of a typical incident response lifecycle?

  1. Plan, Build, Run, Monitor
  2. Identify, Protect, Detect, Respond, Recover
  3. Preparation, Detection and Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (correct answer)
  4. Assess, Remediate, Test, Deploy

Explanation: The NIST SP 800-61 incident response lifecycle has six phases: Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post-Incident Activity. Answer C is correct. Answer A is COBIT management phases. Answer B is the NIST Cybersecurity Framework functions. Answer D is a generic process model.

Question 2

During a ransomware incident, the IT team's first priority should be to:

  1. Contain the attack by isolating infected systems from the network to prevent further spread before beginning investigation or recovery. (correct answer)
  2. Immediately pay the ransom to restore access to critical systems as quickly as possible.
  3. Conduct a full root cause analysis to determine how the ransomware entered the network.
  4. Notify all customers that their data may have been compromised.

Explanation: Containment - isolating affected systems - is the first priority to stop ransomware from spreading to additional systems. Investigation, notification, and recovery follow containment. Answer A is correct. Paying ransom (B) is a last resort. Root cause analysis (C) occurs after containment. Customer notification (D) follows assessment of data exposure.

Question 3

The primary purpose of the 'eradication' phase of incident response is to:

  1. Restore affected systems from clean backups to resume normal operations.
  2. Remove the root cause of the incident - including malware, compromised accounts, and attacker persistence mechanisms - from the affected environment. (correct answer)
  3. Notify stakeholders and regulatory authorities about the incident.
  4. Document lessons learned and improve defenses based on the incident.

Explanation: Eradication focuses on completely removing the attacker's presence and tools from the environment - not just stopping the immediate attack but eliminating all footholds. Answer B is correct. System restoration (A) is the recovery phase. Stakeholder notification (C) occurs during and after containment. Lessons learned (D) are post-incident activities.

Question 4

An organization's incident response plan designates a Computer Security Incident Response Team (CSIRT). The CSIRT should include representatives from which functions?

  1. Only IT security staff who have technical knowledge of the systems involved.
  2. Only senior management and legal counsel.
  3. IT security, IT operations, legal, communications/PR, HR, and relevant business units - reflecting the cross-functional nature of incident response. (correct answer)
  4. External law enforcement and regulatory agencies only.

Explanation: Effective incident response requires cross-functional coordination: IT handles technical response, legal manages liability and regulatory obligations, communications manages external messaging, HR addresses employee-related matters, and business units understand business impact. Answer C is correct. Technical staff alone (A) cannot manage legal, PR, or business implications. Management and legal alone (B) cannot execute technical response. External agencies (D) may be involved but do not constitute the internal CSIRT.

Question 5

Which of the following best describes the purpose of a 'tabletop exercise' in incident response preparedness?

  1. A discussion-based exercise where team members walk through a simulated incident scenario to test their understanding of roles, procedures, and decision-making without activating actual systems. (correct answer)
  2. A live technical exercise that activates the disaster recovery site to test full system failover.
  3. A physical security drill simulating unauthorized access to the data center.
  4. An annual review of the incident response policy document by IT management.

Explanation: Tabletop exercises test incident response knowledge and coordination through discussion of simulated scenarios - identifying gaps in procedures, communication, and decision-making without the risk and cost of live exercises. Answer A is correct. Full system failover (B) is a full-scale exercise. Physical security drills (C) test physical controls. Policy reviews (D) assess documentation.

Question 6

Which of the following is the most important document to maintain during an incident for both operational and legal purposes?

  1. A detailed incident log recording all actions taken, decisions made, timestamps, personnel involved, and evidence collected throughout the response. (correct answer)
  2. A complete backup of all affected systems made at the start of the incident.
  3. A list of all employees who were notified about the incident.
  4. A copy of the organization's cyber insurance policy.

Explanation: A detailed incident log provides the authoritative record of what happened, when, by whom, and why - essential for regulatory reporting, legal proceedings, lessons learned, and demonstrating due diligence. Answer A is correct. Backups (B) are important for recovery. Employee notification lists (C) are one element of documentation. Insurance policies (D) are business documents, not incident records.

Question 7

An organization detects a breach and finds evidence that attackers had access for 45 days before detection. This period between initial compromise and detection is called:

  1. The recovery time objective (RTO).
  2. The mean time to respond (MTTR).
  3. Dwell time - the period an attacker remains undetected within a compromised environment. (correct answer)
  4. The breach notification window.

Explanation: Dwell time measures how long an attacker operates undetected within a network - a key indicator of detection capability maturity. Shorter dwell time means faster detection and less damage. Answer C is correct. RTO (A) measures recovery speed. MTTR (B) measures response time after detection. The notification window (D) is a regulatory compliance concept.

Question 8

When a breach notification is sent to affected individuals, which of the following information should typically be included?

  1. A description of what happened, the types of information involved, what the organization is doing in response, steps individuals can take to protect themselves, and contact information for further assistance. (correct answer)
  2. The full technical details of the attack methodology and vulnerabilities exploited.
  3. The names of all employees involved in the incident response.
  4. A complete list of all data the organization holds about the individual.

Explanation: Breach notifications should be clear and actionable - explaining the incident, what data was affected, organizational response actions, protective steps individuals can take, and how to get help. Answer A is correct. Technical attack details (B) are not helpful to individuals and may aid further attacks. Employee names (C) are confidential. Full data inventories (D) are not required and may raise additional privacy concerns.

Question 9

An organization's incident response plan includes a 'containment strategy decision tree.' The primary purpose of this decision tool is to:

  1. Determine which regulatory authority must be notified first.
  2. Calculate the financial cost of the incident for insurance purposes.
  3. Identify the root cause of the incident before any action is taken.
  4. Guide responders in selecting the appropriate containment approach based on the type and severity of the incident, balancing speed of containment against operational impact. (correct answer)

Explanation: A containment decision tree helps responders quickly determine the right containment strategy for different incident types - balancing the urgency to stop spread against the need to maintain critical operations. Answer D is correct. Regulatory routing (A), cost calculation (B), and root cause identification (C) are separate activities in the IR lifecycle.

Question 10

A company discovers that an employee's laptop containing unencrypted customer data was stolen. Which of the following is the organization's most immediate legal obligation?

  1. Immediately replace the stolen laptop with a new device.
  2. Assess the scope of the data breach and determine applicable breach notification obligations based on the type of data, jurisdiction, and number of affected individuals. (correct answer)
  3. File a police report about the laptop theft and take no further action pending the investigation.
  4. Wait 30 days to determine whether the data has been misused before making any notifications.

Explanation: A stolen laptop with unencrypted customer data is likely a reportable breach - the organization must immediately assess what data was on the device and determine applicable notification requirements under state, federal, and international laws. Answer B is correct. Laptop replacement (A) is an operational matter. A police report (C) alone is insufficient. Waiting 30 days (D) would likely violate notification deadlines.

Question 11

Which of the following best describes the 'recovery' phase of incident response?

  1. Restoring affected systems to normal operation - including system rebuilding, data restoration from clean backups, and validation that systems are functioning correctly before returning them to production. (correct answer)
  2. Identifying and analyzing indicators of compromise to understand the attack.
  3. Removing malware and attacker persistence mechanisms from affected systems.
  4. Communicating with stakeholders about the incident's impact and resolution timeline.

Explanation: Recovery focuses on restoring normal operations safely - rebuilding systems, restoring data from verified clean backups, and confirming functionality before re-entering production. Answer A is correct. Analyzing indicators of compromise (B) is detection and analysis. Removing malware (C) is eradication. Stakeholder communication (D) runs throughout the IR lifecycle.

Question 12

An organization's incident response team is investigating a potential breach and discovers log files that show unauthorized access. The team should:

  1. Immediately delete the logs to prevent the attacker from knowing they were detected.
  2. Share the logs publicly on social media to warn the security community.
  3. Modify the logs to add additional context before preserving them.
  4. Preserve the logs in their original state, create verified forensic copies, and maintain chain of custody documentation to ensure their integrity for investigation and potential legal proceedings. (correct answer)

Explanation: Log files are critical evidence - they must be preserved in their original, unmodified state with proper chain of custody to be usable in legal proceedings or regulatory investigations. Answer D is correct. Deleting (A) or modifying (C) logs is evidence tampering. Public sharing (B) may alert attackers and compromise the investigation.

Question 13

Which of the following is the most critical element of an effective incident response plan?

  1. A detailed inventory of all IT assets and their configurations.
  2. Clearly defined roles and responsibilities, escalation paths, decision authorities, and communication protocols - ensuring every team member knows their role before an incident occurs. (correct answer)
  3. A comprehensive list of all known threat actors targeting the industry.
  4. A contract with a managed security service provider for 24/7 monitoring.

Explanation: Clarity about who does what, who decides what, and how information flows is the foundation of effective incident response - confusion about roles during an active incident wastes critical time. Answer B is correct. Asset inventories (A) support response but are not the most critical IR element. Threat actor lists (C) and MSSP contracts (D) support security programs but are not foundational to IR plan effectiveness.

Question 14

An organization learns that a former employee may have exfiltrated sensitive financial data before leaving. Which of the following is the most appropriate first step in the incident response process?

  1. Preserve relevant evidence - including access logs, email records, and system activity - before taking any action that might alert the former employee or destroy evidence. (correct answer)
  2. Immediately contact the former employee to request return of any copied data.
  3. Publish a security bulletin warning customers about the potential data exposure.
  4. Restore all affected systems from backup to ensure no backdoors remain.

Explanation: Evidence preservation is the critical first step - disabling accounts and preserving logs before the former employee can be alerted or evidence is overwritten. Answer A is correct. Contacting the former employee (B) alerts them and may result in evidence destruction. Customer notification (C) is premature before scope is determined. System restoration (D) may destroy evidence and is premature.

Question 15

Which of the following metrics best measures the effectiveness of an organization's incident response capability?

  1. The total number of security incidents per year.
  2. The size of the incident response team.
  3. Mean time to detect (MTTD) and mean time to respond/contain (MTTR) - measuring how quickly threats are identified and controlled. (correct answer)
  4. The percentage of the IT budget allocated to incident response tools.

Explanation: MTTD and MTTR measure the core effectiveness dimensions of incident response: detection speed (how quickly threats are found) and response speed (how quickly they are controlled). Shorter times mean less damage. Answer C is correct. Incident count (A) reflects threat volume. Team size (B) and budget allocation (D) are resource metrics, not effectiveness measures.

Question 16

An organization's incident response plan requires that any incident involving personal data be escalated to the privacy officer within 4 hours of identification. During an audit, the auditor finds that 6 of 10 sampled incidents involving personal data were not escalated to the privacy officer at all. The auditor should:

  1. Accept this since the incidents were ultimately resolved.
  2. Report this as a significant finding - the escalation control did not operate as designed, creating risk that breach notification obligations were not assessed or triggered for multiple incidents. (correct answer)
  3. Accept this if the privacy officer was available during the incidents.
  4. Accept this since the 4-hour requirement is aspirational, not mandatory.

Explanation: A 60% failure rate in escalating personal data incidents to the privacy officer means notification obligations were likely not assessed - a significant compliance and legal risk. Answer B is correct. Resolution of incidents (A) does not substitute for proper escalation. Officer availability (C) is irrelevant if escalation did not occur. The plan's requirement is mandatory, not aspirational (D).

Question 17

Under GDPR, when must organizations notify the relevant supervisory authority following a personal data breach?

  1. Within 24 hours of the breach occurring.
  2. Within 30 days of discovering the breach.
  3. Only if the breach affects more than 100 individuals.
  4. Within 72 hours of becoming aware of the breach, where feasible, unless the breach is unlikely to result in risk to individuals. (correct answer)

Explanation: GDPR Article 33 requires supervisory authority notification within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in risk to individuals' rights and freedoms. Answer D is correct. 24 hours (A) is too short and not required. 30 days (B) exceeds the requirement. The threshold is not based on individual count (C).

Question 18

Under U.S. state breach notification laws, notification to affected individuals is generally required when:

  1. Any data is accessed by an unauthorized party, regardless of the type of data involved.
  2. The breach involves more than 500 individuals.
  3. The organization determines that customers should be informed as a matter of good customer service.
  4. A breach involves specific categories of sensitive personal information (such as SSNs, financial account numbers, or medical information) and the data was not encrypted or otherwise protected. (correct answer)

Explanation: Most U.S. state breach notification laws trigger individual notification when defined categories of sensitive personal information (PII, financial data, health data) are compromised - particularly when unencrypted. Answer D is correct. Not all unauthorized access triggers notification (A). Thresholds (B) vary by state. Legal triggers, not customer service decisions (C), mandate notification.

Question 19

A company's incident response plan has not been updated in three years and does not reflect the current IT infrastructure, key contacts, or regulatory requirements. The primary risk of this outdated plan is:

  1. The plan will be rejected by external auditors during the annual audit.
  2. During an actual incident, the team will follow incorrect procedures, contact wrong personnel, and miss regulatory obligations - increasing incident impact and legal exposure. (correct answer)
  3. The company's cyber insurance premium will automatically increase.
  4. Employees will not complete required security training on time.

Explanation: An outdated IR plan leads to confusion, delays, and missed obligations during an actual incident - exactly when clarity and speed matter most. Answer B is correct. External auditors may note the gap (A) but the operational risk is more significant. Insurance premiums (C) are not automatically affected. Training (D) is unrelated.

Question 20

Which of the following scenarios would trigger a SEC cybersecurity incident disclosure requirement for a publicly traded company under the SEC's 2023 cybersecurity disclosure rules?

  1. Any cybersecurity incident regardless of significance.
  2. Only incidents that result in confirmed theft of customer financial data.
  3. A cybersecurity incident that the company determines is material - requiring disclosure within four business days on Form 8-K. (correct answer)
  4. Incidents affecting systems outside the United States only.

Explanation: The SEC's 2023 cybersecurity rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining the incident is material. Answer C is correct. Disclosure is not required for all incidents (A). Materiality is broader than just customer data theft (B). The rules apply to all material incidents, not just international ones (D).