Home Quizzes Quiz Detail
Practice Quiz

CIR Practice Questions - PECB Certified Incident Responder (CIR) Exam

100 questions 5.0 rating Mobile friendly
$69.00

Unlock the full practice quiz

Get complete access to the questions, explanations and printable quiz resources.

Full access: unlock all quiz questions and explanations.
Printable review: access the full quiz PDF with correct answers after purchase.

About this Exam

Prepare with the CIR Practice Questions - PECB Certified Incident Responder (CIR) Exam practice quiz. This question bank includes 100 questions covering ransomware, incident, malware, analysis, and responder. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

Sample Questions

Question 1
Which sequence correctly orders the main phases of the incident response lifecycle as used in the PECB Certified Incident Responder body of knowledge?
Preparation, detection, containment, recovery, eradication, lessons learned
Preparation, detection, containment, eradication, recovery, lessons learned
Detection, preparation, containment, eradication, lessons learned, recovery
Preparation, containment, detection, eradication, recovery, lessons learned
Question 2
What is the primary goal of the containment phase of incident response?
To remove all malware and persistence mechanisms from affected systems
To restore business services from verified clean backups as quickly as possible
To limit the spread of the incident and prevent further damage while preserving evidence
To document root cause and improvements for the final incident report
Question 3
Which of the following is the clearest example of an indicator of compromise (IoC)?
A newly hired employee receiving a standard corporate laptop image
An unexpected outbound connection from a workstation to an IP address associated with known malware command-and-control infrastructure
A scheduled antivirus scan completing successfully on a file server
A user resetting their password through the self-service portal
Question 4
Why is maintaining a chain of custody essential when collecting evidence during an incident investigation?
It encrypts all collected evidence so attackers cannot read it
It documents who handled the evidence, when, and how, preserving its integrity and admissibility for legal or disciplinary action
It guarantees that the evidence will identify the attacker with certainty
It allows responders to share evidence freely with any third party that requests it
Question 5
A responder wants to inspect running processes on a Windows host, including parent-child process relationships and verified signatures. Which built-in or Sysinternals tool is best suited for this task?
Process Explorer
Notepad
Disk Defragmenter
Windows Fax and Scan

Ready to test your knowledge?

Buy Now to Access

Additional Information

CIR Practice Questions - PECB Certified Incident Responder (CIR) Exam

This practice set contains 100 questions from the matching question bank and focuses on ransomware, incident, malware, analysis, and responder. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Frequently Asked Questions

This quiz contains a total of 100 practice questions carefully selected to test your knowledge on this subject.
Yes, you will have exactly 0 minutes to complete the exam. A countdown timer will be visible once you start.
Yes, you can retake this practice test as many times as you need. The questions and options may be randomized on subsequent attempts to ensure comprehensive learning.

Reviews

5.0

Based on 0 reviews

Leave a Review

No reviews yet. Be the first to review!