Incident Response: Threat Hunting, Forensics Integration and Frameworks
Published:
Questions
30
Duration
30 min
Faculty-reviewed
0
Updated
09 Jun 2026
About this mock
This test challenges practitioners to apply advanced incident response concepts at the analysis level. Questions span mapping adversary behavior to the MITRE ATT&CK framework, constructing and evaluating hypothesis-driven threat hunting methodologies, and integrating memory and network forensic evidence into live IR workflows. Scenarios drawn from ransomware and APT campaign investigations require selecting appropriate playbook steps and understanding evidence-chain implications. Metric literacy covers MTTD and MTTR as operational and strategic levers. Legal and regulatory dimensions include breach-notification timelines, cross-jurisdictional obligations under GDPR, HIPAA, and comparable frameworks, and the role of legal hold in preserving forensic integrity. Candidates are expected to distinguish closely related techniques, apply principles to realistic fact patterns, and evaluate tradeoffs between investigative thoroughness and operational recovery pressures. Suitable for IR analysts, threat hunters, and digital forensics professionals operating in multi-jurisdictional or enterprise environments.
Sources & references
Questions in this mock are written and verified against the following sources. Citations are recorded per question and shown in the explanation after submission.
- cited in 7 questions
MITRE ATT&CK Enterprise Matrix
Technique T1543.003 – Create or Modify System Process: Windows Service
- cited in 3 questions
Applied Network Security Monitoring
Beaconing detection and C2 traffic analysis
- cited in 3 questions
SANS Institute: Incident Handler's Handbook
Automated response playbooks: design risks and gating controls
- cited in 3 questions
The Art of Memory Forensics
Linux and Mac memory forensics: process and module analysis
- cited in 2 questions
NIST SP 800-61 Rev. 2: Computer Security Incident Handling Guide
Containment, eradication, and recovery sequencing
- cited in 1 question
Guide to Integrating Forensic Techniques into Incident Response (NIST SP 800-86)
Legal considerations and evidence preservation during IR
- cited in 1 question
MITRE ATT&CK Framework
Using ATT&CK for detection coverage analysis and gap assessment
- cited in 1 question
Windows Registry Forensics (Harlan Carvey)
Registry key timestamps and correlation with execution artifacts
- cited in 1 question
HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D)
Sections 164.410 (business associate obligations) and 164.404–164.408 (covered entity obligations and media notification)
- cited in 1 question
The Practice of Network Security Monitoring
Threat hunting principles and data source alignment
- cited in 1 question
AWS Security Incident Response Guide
Logging and evidence collection for S3 incidents
- cited in 1 question
The Diamond Model of Intrusion Analysis (Caltagirone, Pendergast, Betz)
Core features: Adversary, Capability, Infrastructure, Victim
- cited in 1 question
PEAK Threat Hunting Framework (Splunk)
Hunt-type definitions: Hypothesis-Driven, Baseline, and Model-Assisted Threat Hunts
- cited in 1 question
GDPR: A Practical Guide for Information Professionals
Breach notification obligations under Articles 33 and 34
- cited in 1 question
OFAC Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments
Strict liability, due-diligence obligations, and designated ransomware actors
- cited in 1 question
Office of the Australian Information Commissioner: Notifiable Data Breaches Scheme
NDB scheme overview: eligible data breaches, assessment timeframe, and notification obligations
- cited in 1 question
Windows Forensic Analysis Toolkit
Prefetch analysis and execution-artifact forensics
How our mocks are built
Questions are written and edited by the ForensicSpot team and cited from peer-reviewed forensic textbooks, official syllabi and primary case law. Each one is verified before publishing. Detailed explanations show after you submit, so the test stays a real test. See a mistake? Tell us.
Common questions
What does the Incident Response: Threat Hunting, Forensics Integration and Frameworks mock cover?+
This test challenges practitioners to apply advanced incident response concepts at the analysis level. Questions span mapping adversary behavior to the MITRE ATT&CK framework, constructing and evaluating hypothesis-driven threat hunting methodologies, and integrating memory and network forensic evidence into live IR workflows. Scenarios drawn from ransomware and APT campaign investigations require selecting appropriate playbook steps and understanding evidence-chain implications. Metric literacy
How many questions and how long is the test?+
30 multiple-choice questions, 30 minutes total. Difficulty: hard. Tier: Premium.
Who is this mock for?+
Forensic science students and aspirants who want timed, exam-style practice with explanations and verified source citations on Incident Response and Management. Useful for postgraduate entrance preparation and for BSc / MSc forensic students testing their recall under time.
Are the questions reviewed?+
Each question carries a verified source citation. Faculty review for individual questions is in progress.
Do I need an account to take this mock?+
Yes, a free ForensicSpot account is required to start a timed attempt — this lets you save progress, see per-question explanations after submission, and track your topic-level performance over time.