Skip to content
Incident Response and Managementhard Premium

Incident Response: Threat Hunting, Forensics Integration and Frameworks

Published:

Questions

30

Duration

30 min

Faculty-reviewed

0

Updated

09 Jun 2026

Score, per-question explanations and topic breakdown shown right after you submit.

About this mock

This test challenges practitioners to apply advanced incident response concepts at the analysis level. Questions span mapping adversary behavior to the MITRE ATT&CK framework, constructing and evaluating hypothesis-driven threat hunting methodologies, and integrating memory and network forensic evidence into live IR workflows. Scenarios drawn from ransomware and APT campaign investigations require selecting appropriate playbook steps and understanding evidence-chain implications. Metric literacy covers MTTD and MTTR as operational and strategic levers. Legal and regulatory dimensions include breach-notification timelines, cross-jurisdictional obligations under GDPR, HIPAA, and comparable frameworks, and the role of legal hold in preserving forensic integrity. Candidates are expected to distinguish closely related techniques, apply principles to realistic fact patterns, and evaluate tradeoffs between investigative thoroughness and operational recovery pressures. Suitable for IR analysts, threat hunters, and digital forensics professionals operating in multi-jurisdictional or enterprise environments.

Sources & references

Questions in this mock are written and verified against the following sources. Citations are recorded per question and shown in the explanation after submission.

  • MITRE ATT&CK Enterprise Matrix

    Technique T1543.003 – Create or Modify System Process: Windows Service

    cited in 7 questions
  • Applied Network Security Monitoring

    Beaconing detection and C2 traffic analysis

    cited in 3 questions
  • SANS Institute: Incident Handler's Handbook

    Automated response playbooks: design risks and gating controls

    cited in 3 questions
  • The Art of Memory Forensics

    Linux and Mac memory forensics: process and module analysis

    cited in 3 questions
  • NIST SP 800-61 Rev. 2: Computer Security Incident Handling Guide

    Containment, eradication, and recovery sequencing

    cited in 2 questions
  • Guide to Integrating Forensic Techniques into Incident Response (NIST SP 800-86)

    Legal considerations and evidence preservation during IR

    cited in 1 question
  • MITRE ATT&CK Framework

    Using ATT&CK for detection coverage analysis and gap assessment

    cited in 1 question
  • Windows Registry Forensics (Harlan Carvey)

    Registry key timestamps and correlation with execution artifacts

    cited in 1 question
  • HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D)

    Sections 164.410 (business associate obligations) and 164.404–164.408 (covered entity obligations and media notification)

    cited in 1 question
  • The Practice of Network Security Monitoring

    Threat hunting principles and data source alignment

    cited in 1 question
  • AWS Security Incident Response Guide

    Logging and evidence collection for S3 incidents

    cited in 1 question
  • The Diamond Model of Intrusion Analysis (Caltagirone, Pendergast, Betz)

    Core features: Adversary, Capability, Infrastructure, Victim

    cited in 1 question
  • PEAK Threat Hunting Framework (Splunk)

    Hunt-type definitions: Hypothesis-Driven, Baseline, and Model-Assisted Threat Hunts

    cited in 1 question
  • GDPR: A Practical Guide for Information Professionals

    Breach notification obligations under Articles 33 and 34

    cited in 1 question
  • OFAC Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments

    Strict liability, due-diligence obligations, and designated ransomware actors

    cited in 1 question
  • Office of the Australian Information Commissioner: Notifiable Data Breaches Scheme

    NDB scheme overview: eligible data breaches, assessment timeframe, and notification obligations

    cited in 1 question
  • Windows Forensic Analysis Toolkit

    Prefetch analysis and execution-artifact forensics

    cited in 1 question

How our mocks are built

Questions are written and edited by the ForensicSpot team and cited from peer-reviewed forensic textbooks, official syllabi and primary case law. Each one is verified before publishing. Detailed explanations show after you submit, so the test stays a real test. See a mistake? Tell us.

Common questions

What does the Incident Response: Threat Hunting, Forensics Integration and Frameworks mock cover?+

This test challenges practitioners to apply advanced incident response concepts at the analysis level. Questions span mapping adversary behavior to the MITRE ATT&CK framework, constructing and evaluating hypothesis-driven threat hunting methodologies, and integrating memory and network forensic evidence into live IR workflows. Scenarios drawn from ransomware and APT campaign investigations require selecting appropriate playbook steps and understanding evidence-chain implications. Metric literacy

How many questions and how long is the test?+

30 multiple-choice questions, 30 minutes total. Difficulty: hard. Tier: Premium.

Who is this mock for?+

Forensic science students and aspirants who want timed, exam-style practice with explanations and verified source citations on Incident Response and Management. Useful for postgraduate entrance preparation and for BSc / MSc forensic students testing their recall under time.

Are the questions reviewed?+

Each question carries a verified source citation. Faculty review for individual questions is in progress.

Do I need an account to take this mock?+

Yes, a free ForensicSpot account is required to start a timed attempt — this lets you save progress, see per-question explanations after submission, and track your topic-level performance over time.

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.