01. Ransomware encryption began at 02:00 on Sunday across three file servers. The technical team wants to concentrate the investigation on reconstructing what happened from 02:00 onward.
Why should the incident leader redirect that effort?
a) Reconstructing the encryption itself establishes which files were affected, and the business cannot set a restoration order until that inventory is complete.
b) Restoration cannot start until the encryption window is fully mapped, so this work is correctly sequenced ahead of everything else.
c) Timestamps on systems the attacker controlled cannot be trusted, so the sequence has to be rebuilt from a record held outside those systems.
d) Encryption is the last stage of a longer intrusion, and the period before it holds the credential theft, backup tampering and exfiltration.
02. After an incident an executive asks for the organization's ATT&CK score, so that it can be tracked quarterly alongside other security measures.
How should the incident leader answer?
a) Explain that it produces no score, and offer coverage against the techniques relevant to the threats the organization faces.
b) Provide the percentage of all techniques in the framework for which some detection exists, tracked quarterly.
c) Provide the organization's maturity level against the framework's tiers, which is the number the question is really asking for.
d) Decline the measure entirely, since detection coverage cannot be expressed in any form an executive could track over time.
03. Recovery is about to begin after a ransomware incident and several teams are each asking for their systems first.
Which two inputs should set the order in which systems are restored?
(Choose two.)
a) Which systems the technical team can bring back fastest, so that visible progress is made early.
b) The order in which the systems were encrypted, since the earliest ones have the most catching up to do.
c) The dependencies between systems, so that a restored service is not waiting on one still down.
d) Which systems the business has identified as the ones it cannot operate without.
04. An external researcher who reported a flaw in a customer-facing service has set a publication date that falls two weeks before the earliest date engineering can ship a fix. Counsel confirms there is no basis to compel a delay.
What should the incident leader do?
a) Treat the date as fixed, put a compensating control in place, and keep the researcher informed.
b) Press the researcher repeatedly to move the date, since publication before a fix exposes every customer of the service.
c) Escalate to executives to authorize an emergency release that ships the fix before the publication date regardless of testing.
d) Publish the organization's own advisory ahead of the researcher, so that the narrative is set before the disclosure lands.
05. Eradication work on a ransomware incident is nearly finished and the business is pressing to bring the first systems back.
Which two conditions should the incident leader require before restoration begins?
(Choose two.)
a) A signed statement from the business owner accepting the residual risk of returning to service early.
b) An agreed plan to monitor the restored systems more closely than normal for a defined period.
c) Confirmation that the access paths the attacker used are closed and verified, not merely believed closed.
d) Completion of the notification determination, so that restored systems do not create new obligations.
06. A compromised vendor product is business-critical and the vendor's fix has no committed date. The business cannot remove the product.
Which two elements must the incident leader's plan contain?
(Choose two.)
a) A constraint on what the product can reach in the meantime, sized to the exposure.
b) An escalation to the vendor's executive team, repeated on a schedule until a date is committed.
c) A named date at which the organization decides what to do if no fix has arrived, with the owner of that decision named.
d) A decision to treat the product as compromised and rebuild it from the last release that the vendor confirms is clean.
07. On the first morning of a ransomware incident the leader can direct the team to one of several early tasks. The extortion note carries a deadline, executives are asking about options, and counsel has been engaged.
Which task most changes the decisions available to the organization?
a) Identifying which business units are affected so the recovery order can be drafted with their owners.
b) Determining which variant was deployed, so the response can be matched to its documented behavior.
c) Establishing whether a known-good backup exists and actually restores, rather than assuming the estate survived.
d) Producing a first estimate of the financial cost of the outage for the executive briefing.
08. An external forensic firm is engaged mid-incident. It proposes working from its own case system and delivering a written report at the end of the engagement.
What should the incident leader require instead?
a) That the firm submit a written summary at the end of each day, which the organization's coordinator then enters into the incident record.
b) That the firm's findings and the actions it takes enter the organization's incident record as they are established.
c) That the firm provide access to its case system, letting the organization's responders read its working notes.
d) That the firm's system be treated as the authoritative record for the technical strand, and the organization's record cover everything else.
09. The team considered shutting down a manufacturing line during containment and decided against it. Nothing about that discussion appears in the record, because the option was not taken.
How should the incident leader treat that omission?
a) Accept it, and cover the rejected options in the after-action report, where the analysis of decisions belongs.
b) Correct it after the incident, when the review can capture the rejected options together with the reasoning behind each.
c) Correct it, because a decision not to act is still a decision, and the reasoning behind it is what a later reader will ask for.
d) Accept it, since the record is an account of what was done, and adding rejected options would obscure the sequence.
10. A managed service provider with standing administrative access to the organization's estate reports that its own systems are compromised. Suspending that access would stop several production services.
Who should decide whether to suspend it, and on what basis?
a) The provider, since it is better placed to judge whether its access has actually been misused in this case.
b) The technical lead, who should suspend it immediately and inform the business owners once the action is complete.
c) The incident leader, on the technical assessment of what that access could reach, since containment is the leader's call.
d) The business, with the leader supplying what the access reaches and what the outage would cost.