Question 1
In incident response, which document outlines each member's roles and responsibilities?
Correct Answer:
Incident Response Plan
Explanation:
Assigning who does what during an incident is the purpose of an incident response plan. This document clearly lays out the incident response team’s structure, who has authority to make decisions, who leads the response, who handles technical analysis, who communicates with stakeholders, and how escalation should occur. It also specifies contact lists, the sequence of actions at each stage (detection, containment, eradication, recovery, and lessons learned), and the overall workflow to keep the response organized and efficient. Other documents serve different purposes. An Acceptable Use Policy defines what users may and may not do with IT resources. A Data Handling Procedure explains how data should be classified and protected. A Continuity Plan focuses on keeping critical business functions running or restoring them after a disruption, rather than detailing the incident response roles and day-to-day actions during a security incident.
Question 2
Baselining is concerned with establishing a known state of the system’s what?
Correct Answer:
Configuration
Explanation:
Baselining establishes a known state of how the system is configured. This means capturing the exact setup: hardware and software inventory, installed patches and updates, enabled or disabled services, startup configurations, security settings, and user accounts and permissions. By documenting this configuration, you create a reference point to compare against future states and quickly detect any changes, drift, or unauthorized modifications. While performance metrics or network topology can have their own baselines in other contexts, the fundamental idea here is to know and compare the system’s setup—its configuration.
Question 3
A worm has the unique characteristic of being able to replicate without needing _________ to activate the virus.
Correct Answer:
A user
Explanation:
Worms spread autonomously, needing no user to trigger replication. Their defining trait is that they can copy themselves to other systems and propagate across networks without someone clicking an attachment or running a program. This contrasts with many other malware types that rely on a user action to activate. While a worm may use network connections to move around or even be delivered via email in some cases, the essential property is that no user is required to start its replication. The missing element in the statement is a user.
Question 4
After credentials are verified, which AAA component governs granting access rights?
Correct Answer:
Authorization
Explanation:
Authorization determines what you are allowed to do once your identity has been confirmed. After credentials are verified (authentication), authorization applies access-control policies to grant specific rights to resources or actions—like which files you can read, which systems you can access, or which commands you can run. Accounting then logs your activity for auditing. So the reason authorization is correct is that it translates a verified identity into the permissions that define your access rights.
Question 5
When should gathering information take place during root cause analysis?
Correct Answer:
First step
Explanation:
Gathering information at the outset is essential because it provides the facts, timeline, and context needed to understand what happened and what’s affected. Collecting logs, configurations, witness accounts, and process data early helps distinguish symptoms from the true root cause and prevents jumping to conclusions too soon. This initial data collection sets the boundaries of the investigation, preserves evidence, and informs what questions to ask during analysis. You can and should continue gathering information as needed during the analysis, but starting with information collection ensures the analysis is grounded in real data rather than assumptions. Waiting until after remediation risks losing important evidence and biases the investigation toward the fix rather than understanding the underlying cause.
Question 1
Exam overview

About this Exam

Prepare with the Cyber Fundamentals Block 5 Practice Exam practice quiz. This question bank includes 10 questions covering worm, known, incident, cyber, and fundamentals. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Cyber Fundamentals Block 5 Practice Exam

This practice set contains 10 questions from the matching question bank and focuses on worm, known, incident, cyber, and fundamentals. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions