Log analysis
Read event snippets, identify suspicious activity, and choose the best response.
Performance-based questions test whether you can apply security knowledge in realistic tasks. SecurePlus includes PBQ-style practice for logs, ordering, terminal interpretation, hotspot selection, and drag-and-drop concepts.
Read event snippets, identify suspicious activity, and choose the best response.
Place incident response, risk, or recovery steps in the correct sequence.
Practise the reasoning behind secure architecture and control placement.
Scenario: A user reports that their laptop may have malware. Put the incident response actions in a sensible first-response order.
1. Preserve evidence and document actions
2. Isolate the affected device from the network
3. Escalate to the security team
4. Begin eradication only after containment and analysis
A strong order starts with isolation and escalation, while preserving evidence and documenting actions throughout the response.