Skip to content
Tech Interview Prep home
Technical interview guide

Incident Response Basics

The standard phases of handling a security incident, from detection through lessons learned.

Read
27 min
Practice MCQs
25
Interview QA
25
Edition
v3
Editorial status
Reviewed

Scope: NIST SP 800-61 Rev. 3 (2025), CSF 2.0-aligned guidance, and official CISA playbooks accessed 2026-08-31..

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

How do you triage and set severity for a suspected security incident?

QA-2

How do the NIST and SANS incident response lifecycles map to each other, and what operational distinction separates containment from eradication?

QA-3

Respond to suspected administrator-session compromise in the first hour.

QA-4

Lead response to a ransomware incident.

QA-5

Respond to a suspected multi-tenant data breach.

QA-6

Respond to compromise of a cloud access key or workload identity.

QA-7

Respond to a compromised dependency or build pipeline.

QA-8

Investigate suspected malicious-insider data access.

QA-9

Collect forensic evidence from a live compromised system.

QA-10

Maintain chain of custody for digital evidence.

QA-11

Build and maintain an incident timeline from conflicting evidence.

QA-12

Choose a containment strategy under uncertainty.

QA-13

Communicate during a major incident without creating confusion or unsupported claims.

QA-14

How do you decide whether and when to notify customers, regulators, or law enforcement?

QA-15

Plan safe recovery and return to service after compromise.

QA-16

Define evidence-based incident exit and closure criteria.

QA-17

How do you distinguish between an event, an alert, and an actual security incident during initial triage?

QA-18

What are the essential components and technical objectives of an incident summary report produced after containment and eradication?

QA-19

Respond when critical incident logs are missing or suspected tampered.

QA-20

Coordinate incident response with a compromised third-party provider.

QA-21

Respond to an actively exploited critical vulnerability before compromise is confirmed.

QA-22

Choose incident-response metrics that improve capability without rewarding bad behavior.

QA-23

Run a blameless post-incident review that produces accountable improvement.

QA-24

Track corrective actions until they demonstrably reduce incident risk.

QA-25

Lead end-to-end response to a major security incident.