Take our Cyber Incident Response Quiz

Cyber Incident Response Quiz

This 20 question quiz is designed to test and strengthen your understanding of Cyber Incident Response, including the actions, decisions, and responsibilities required to effectively detect, contain, investigate, and recover from cyber security incidents. Each question is based on the key principles, processes, and scenarios covered throughout this webinar, including incident identification, evidence preservation, ransomware response, Microsoft 365 account compromise, data breach assessment, communications, recovery procedures, and regulatory obligations.

You will be asked to choose the most accurate, practical, and security-focused answer in each case.


The goal of this exercise is to help you understand how effective cyber incident response reduces business impact, limits the spread of attacks, preserves critical evidence, supports informed decision-making, and enables organisations to recover safely and efficiently. By working through these questions, you will reinforce your knowledge of incident management, containment strategies, evidence handling, ransomware and account compromise response, data breach assessment, third-party risks, communication responsibilities, and the importance of maintaining an accurate incident record throughout the response and recovery process.


Make your attempt count, you only have one chance to pass this quiz.

By continuing, you agree that System Force can use your details to send you your quiz results by email.

1 / 24

1. During the first 15 minutes of a suspected cyber incident, what should be the highest priority?

2 / 24

2. Why should a suspected compromised device normally remain powered on?

3 / 24

3. If privileged or identity accounts are involved in an incident, the severity should generally be treated as

4 / 24

4. When establishing command during an incident, who is responsible for owning the timeline?

5 / 24

5. Which action is recommended before security logs are overwritten?

6 / 24

6. Which item should be reviewed when investigating a phishing or business email compromise?

7 / 24

7. In a Microsoft 365 account compromise, why is a password reset alone insufficient?

8 / 24

8. During a ransomware incident, what should happen to unaffected systems?

9 / 24

9. Why must backup integrity be verified before recovery?

10 / 24

10. What is an important consideration when assessing a suspected data breach?

11 / 24

11. A laptop containing customer data is stolen. Which factor most strongly influences the risk assessment?

12 / 24

12. What is the recommended approach to communications during the first 24 hours?

13 / 24

13. A supplier reports a security breach. What should be reviewed first?

14 / 24

14. Which of the following best demonstrates evidence preservation?

15 / 24

15. In the tabletop email compromise exercise, what malicious configuration redirected invoice information externally?

16 / 24

16. During ransomware response, what is generally preferred over a blanket shutdown?

17 / 24

17. When should recovery from backups begin?

18 / 24

18. If a personal data breach is determined to be notifiable, when should reporting occur?

19 / 24

19. Following a website compromise, which action helps prevent reinfection?

20 / 24

20. Which statement best reflects good incident management practice?

21 / 24

1. How confident do you feel in your ability to identify and respond to cyber threats after attending this webinar?

22 / 24

2. Any additional feedback you would like to make us aware of?

23 / 24

3. What additional topics would you like to see covered in future cyber resiliency sessions?

24 / 24

4. Which part of the training did you find most valuable for improving your cyber resiliency skills, and why?