Incident › Module 4 › Lesson 5
Quiz — Detection
10 APPLY items on detection intake, analysis named, and evidence hygiene on $IR_LAB.
Opening
Detection and Analysis — Module Quiz
Ten APPLY items. Name detection and analysis on YOUR $IR_LAB — never unauthorized forensics, ransomware payloads, or stranger-network isolation. Original Cyberlium. Next: Containment Options.
Knowledge Check
APPLY: Detection intake triage fields include:
Multiple choice
Knowledge Check
APPLY: True or False: IR analysis uses falsifiable hypotheses tested against evidence.
True or False
Knowledge Check
APPLY: Chain of custody logs:
Multiple choice
Knowledge Check
APPLY: Tutorial images stranger-system disk without authorization — you:
Multiple choice
Knowledge Check
APPLY: Timeline building should use:
Multiple choice
Knowledge Check
APPLY: Cyberlium NEVER allows:
Multiple choice
Knowledge Check
APPLY: SHA-256 on evidence primarily:
Multiple choice
Knowledge Check
APPLY: True or False: Scope assessment asks which assets and data are affected.
True or False
Knowledge Check
APPLY: chmod 600 on detection notes means:
Multiple choice
Knowledge Check
APPLY: Next lesson after this quiz:
Multiple choice
Answer all 10 knowledge checks to continue. (0/10 answered)