CIS-SIR Practice Questions
Certified Implementation Specialist - Security Incident Response
50 practice questions across 6 topics • 15 free
Exam Overview
Practice Questions
60 questions from 6 topicsWhat is the MITRE ATT&CK framework in the context of Security Incident Response?
👆 Click an option above to select your answer
Which three MITRE ATT&CK matrices are used to describe adversary behaviors? (Choose three.)
👆 Click an option above to select your answer
What represents 'the why' of an ATT&CK technique?
👆 Click an option above to select your answer
What does TTP stand for in the MITRE ATT&CK framework?
👆 Click an option above to select your answer
What role does the TAXII client play in Security Operations?
👆 Click an option above to select your answer
What is an IoC in the context of Security Incident Response?
👆 Click an option above to select your answer
Where are SIR integrations configured in ServiceNow?
👆 Click an option above to select your answer
What role is required to configure SIR integrations like HPE ArcSight Logger?
👆 Click an option above to select your answer
What must be done before using a SIR integration from the ServiceNow Store?
👆 Click an option above to select your answer
What is the Security Incident Response Workspace used for?
👆 Click an option above to select your answer
How does integrating SIR with MITRE ATT&CK change incident handling?
👆 Click an option above to select your answer
What is the purpose of the Automated Malware playbook in Security Incident Response?
👆 Click an option above to select your answer
Which four stages are included in the Automated Malware playbook process definition? (Choose four.)
👆 Click an option above to select your answer
How can organizations use MITRE ATT&CK to understand their security posture?
👆 Click an option above to select your answer
What enables security teams to predict attacker behavior in intent-based response?
👆 Click an option above to select your answer
Practice by Topic
Focus on specific areas to strengthen your weak points
Exam Domains
Security Incident Response Overview and Data Visualization
15%Introducing Security Incident Response, data visualization, and Security Incident Response components
Security Incident Creation and Threat Intelligence
14%Creating security incidents, major security incident management, understanding threat intelligence, and MITRE ATT&CK Framework
Security Incident and Threat Intelligence Integrations
14%ServiceNow Store and Share, managing pre-built integrations, creating custom integrations, and Threat Intelligence Service Center
Security Incident Response Management
15%Security Incident Response Workspace, standard automated assignment options, escalation paths, security tags, and process definitions
Risk Calculations and Post Incident Response
12%Security incident calculator groups and risk scores, post incident reviews, and Event Management
Automation and Standard Processes
30%Automate Security Incident Response overview, security incident process automation using playbooks and runbooks, and User Reported Phishing
More Study Resources
Explore additional materials to boost your exam preparation