yoklainterview sim

Security Bt Ir Playbook Execution Interview Questions

75 verified Security Bt Ir Playbook Execution interview questions — solve with answers, learn from explanations, test yourself in a real simulation.

Try the real simulation →

Sample questions

Bt Ir Playbook ExecutionDifficulty 1
In the standard incident response lifecycle, what is the correct order of the three phases that come right after detection and analysis?
  • aContainment, then eradication, then recovery.
  • bRecovery, then eradication, then containment.
  • cEradication, then recovery, then containment.
  • dRecovery, then containment, then eradication.
Explanation:After an incident is detected and analyzed, responders first contain it to stop further damage, then eradicate the root cause, and finally recover affected systems back to normal operation.
Bt Ir Playbook ExecutionDifficulty 1
What is the primary purpose of containment during an active incident?
  • aTo write the final incident report for management review, since documentation should always come before any technical action is taken to slow the incident down.
  • bTo permanently remove the vulnerability that allowed the attacker to get in.
  • cTo restore all affected systems to full production traffic immediately.
  • dTo stop the incident from spreading further or causing more damage while the team investigates.
Explanation:Containment's goal is to limit the blast radius — stop the spread or ongoing damage — while the team still has time to investigate and plan eradication. Removing the root cause is eradication; restoring service is recovery; reporting comes later.
Bt Ir Playbook ExecutionDifficulty 1
What distinguishes short-term containment from long-term containment in an incident response playbook?
  • aShort-term containment always involves reimaging every affected system, while long-term containment never does.
  • bShort-term containment applies a quick stopgap (like isolating a host) to stop the bleeding, while long-term containment sets up a more durable fix (like a rebuilt, patched system) while investigation continues.
  • cThere is no real difference; the two terms describe the exact same set of actions performed at any point in an incident.
  • dShort-term containment is only used for insider-threat cases, while long-term containment is only used for external attacks.
Explanation:Short-term containment is a fast, temporary action to stop immediate damage (e.g., network isolation), buying time. Long-term containment builds a more sustainable interim state — such as a patched, hardened, or rebuilt system on a clean segment — that can hold until full eradication and recovery are complete.
Bt Ir Playbook ExecutionDifficulty 2
A non-critical workstation is confirmed to be actively beaconing to an external address. Before eradicating anything, the responder wants to preserve evidence. What is the most appropriate immediate step?
  • aIsolate the workstation from the network (e.g., via a containment VLAN or blocking outbound traffic) while keeping it powered on to preserve volatile evidence for analysis.
  • bLeave the workstation exactly as-is with full network access, and revisit it after the next scheduled maintenance window, since maintenance windows are always the appropriate time to address any security concern.
  • cPower the workstation off completely to guarantee the malware cannot do anything further.
  • dReformat the workstation right away so it stops beaconing as quickly as possible.
Explanation:Network isolation stops the beaconing and further damage without destroying volatile evidence (running processes, memory, open connections) the way a full power-off or immediate reformat would. Leaving it fully connected ignores the active threat.
Bt Ir Playbook ExecutionDifficulty 1
What does the eradication phase of an incident primarily involve?
  • aReconnecting all affected systems to production traffic without further checks, since once the immediate incident is noticed, restoring full access is always the fastest path forward.
  • bRemoving the actual root cause of the compromise, such as malware, a rogue account, or the exploited vulnerability.
  • cNotifying customers and regulators about the incident.
  • dRunning a tabletop exercise to test how the team would have responded.
Explanation:Eradication removes what actually caused the incident so it cannot simply resurface — malicious files, backdoor accounts, and the exploited flaw itself. Reconnecting systems is recovery; notification is a communications task; tabletop exercises are a separate preparation activity.
Bt Ir Playbook ExecutionDifficulty 2
After eradicating malware from a server, the team is about to reintroduce it to production during recovery. What should they do first, before restoring full normal traffic?
  • aRoute full production traffic back immediately, since eradication is already confirmed done.
  • bSkip any further checks, since recovery simply means turning the system back on.
  • cBring the server back gradually with heightened monitoring, watching for any sign the same indicators of compromise reappear.
  • dRestore the server from the most recent backup without checking when that backup was taken relative to the compromise, assuming that recency alone is always enough proof of safety.
Explanation:Recovery is typically staged: systems come back under close monitoring so responders can catch any sign that eradication missed something, rather than assuming the job is finished the moment the malware file is deleted.

Test yourself against the 2850-question Security bank.

Start interview