All Practice Exams

100+ Free CIR Practice Questions

Prepare for the PECB Certified Incident Responder (CIR) exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: CIR Exam

20Q, 3 hours

Exam Format

PECB

70%

Passing Score

PECB

USD 1000 exam-only

Exam Fee

PECB

PECB Certified Incident Responder (CIR) certification exam evaluates candidates on official PECB domains and standards. Note: this practice set is an English-language MCQ study adaptation.

Sample CIR Practice Questions

Try these sample questions to test your CIR exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1Which sequence correctly orders the main phases of the incident response lifecycle as used in the PECB Certified Incident Responder body of knowledge?
A.Preparation, detection, containment, recovery, eradication, lessons learned
B.Preparation, detection, containment, eradication, recovery, lessons learned
C.Detection, preparation, containment, eradication, lessons learned, recovery
D.Preparation, containment, detection, eradication, recovery, lessons learned
Explanation: The incident response lifecycle begins with preparation, followed by detection of the incident, containment to limit spread, eradication to remove the threat, recovery to restore normal operations, and finally lessons learned to improve future response. Swapping eradication and recovery is a common mistake: systems must be cleaned before they are safely restored.
2What is the primary goal of the containment phase of incident response?
A.To remove all malware and persistence mechanisms from affected systems
B.To restore business services from verified clean backups as quickly as possible
C.To limit the spread of the incident and prevent further damage while preserving evidence
D.To document root cause and improvements for the final incident report
Explanation: Containment is about stopping the bleeding: isolating affected hosts, disabling compromised accounts, or blocking malicious infrastructure so the incident cannot spread or cause further damage. Actions taken during containment must also avoid destroying evidence needed for later analysis.
3Which of the following is the clearest example of an indicator of compromise (IoC)?
A.A newly hired employee receiving a standard corporate laptop image
B.An unexpected outbound connection from a workstation to an IP address associated with known malware command-and-control infrastructure
C.A scheduled antivirus scan completing successfully on a file server
D.A user resetting their password through the self-service portal
Explanation: An indicator of compromise is a forensic artifact that suggests a system may have been breached, such as connections to known malicious infrastructure, unusual files, or suspicious registry changes. Outbound traffic to a known command-and-control address is a classic network-based IoC that warrants immediate investigation.
4Why is maintaining a chain of custody essential when collecting evidence during an incident investigation?
A.It encrypts all collected evidence so attackers cannot read it
B.It documents who handled the evidence, when, and how, preserving its integrity and admissibility for legal or disciplinary action
C.It guarantees that the evidence will identify the attacker with certainty
D.It allows responders to share evidence freely with any third party that requests it
Explanation: Chain of custody is the documented record of the seizure, custody, control, transfer, and analysis of evidence. It demonstrates that evidence has not been altered or tampered with, which is essential if the findings are later used in legal proceedings, regulatory actions, or internal disciplinary processes.
5A responder wants to inspect running processes on a Windows host, including parent-child process relationships and verified signatures. Which built-in or Sysinternals tool is best suited for this task?
A.Process Explorer
B.Notepad
C.Disk Defragmenter
D.Windows Fax and Scan
Explanation: Process Explorer (from Microsoft Sysinternals) provides a detailed real-time view of running processes, including parent-child hierarchies, loaded DLLs, handles, and signature verification. It is a standard tool for spotting suspicious processes such as unsigned binaries masquerading as system processes.
6Which Windows artifact records the execution of applications, including the executable's full path and run count, and is therefore useful for determining the source and execution path of a malicious file?
A.The Recycle Bin index
B.Windows Prefetch files
C.The Windows pagefile configuration
D.The desktop wallpaper registry value
Explanation: Prefetch files (stored under C:\Windows\Prefetch) are created by Windows to speed application launches and record the executable path, run count, and last execution times. Investigators use them to prove that a program ran on a host and to trace where it was executed from, such as a user's Downloads or Temp folder.
7During live evidence collection on a compromised but still-running server, which data should a responder capture FIRST, following the principle of order of volatility?
A.The contents of RAM and active network connections
B.Archived log files from the previous quarter
C.The contents of the hard disk's unallocated space
D.Backed-up system images stored on offline media
Explanation: The order of volatility principle dictates collecting the most ephemeral evidence first. RAM contents, active network connections, and running process state vanish when a system is powered off or rebooted, so they must be captured before disk-based artifacts, which persist across restarts.
8Which group is typically a key internal stakeholder that must be engaged early when an incident involves potential exposure of regulated personal data?
A.The organization's legal counsel and privacy or compliance function
B.The building facilities management team
C.The external marketing agency that designed the company website
D.The hardware vendor's sales representative
Explanation: Incidents involving personal data may trigger breach notification duties under privacy regulations, so legal counsel and the privacy/compliance function must be engaged early to assess obligations, timelines, and communication strategy. Effective incident response depends on coordinating with stakeholders beyond the technical team.
9What is the main purpose of the lessons learned (post-incident) phase?
A.To assign blame to the employee who clicked a malicious link
B.To evaluate the effectiveness of the response and identify improvements to processes, controls, and documentation
C.To delete all incident records so storage costs are minimized
D.To immediately restore all systems to production without further review
Explanation: The lessons learned phase reviews what happened, how well the response worked, and what should change, feeding improvements back into preparation such as updated playbooks, detection rules, and training. It is a blameless, improvement-focused activity, not a disciplinary exercise.
10When scoping an incident, which activity best determines the full extent of the compromise?
A.Assuming only the first reported machine is affected and closing the ticket
B.Identifying all affected assets, accounts, and data by correlating indicators across systems and logs
C.Reimaging the reported workstation immediately before any analysis
D.Waiting for additional users to call the help desk before investigating
Explanation: Scoping requires systematically identifying which systems, accounts, and data are affected, typically by correlating indicators of compromise across endpoints, network telemetry, and logs. Under-scoping an incident leads to incomplete eradication and attacker reinfection.

About the CIR Exam

The PECB Certified Incident Responder (CIR) certification evaluates professional competence in governance, implementation, auditing, and management according to PECB standards.

Questions

20 scored questions

Time Limit

3 hours

Passing Score

70%

Exam Fee

USD 1000 exam-only (PECB (Professional Evaluation and Certification Board))

CIR Exam Content Outline

~20%

Incident Response Planning & Preparation

Developing incident response plans, building IR teams, establishing communication channels, tool selection, and proactive readiness.

~25%

Detection, Triage, and Initial Analysis

Log collection, SIEM alert triage, network traffic analysis, host analysis, threat hunting, and severity categorization.

~25%

Containment and Eradication Strategies

Short-term vs long-term containment, isolating infected systems, malware removal, credential reset, and closing attack vectors.

~15%

Recovery and Service Restoration

System restoration from clean backups, validation testing, monitoring restored environments, and business continuity coordination.

~15%

Post-Incident Analysis and Continual Improvement

Conducting post-incident reviews, root cause analysis, documentation, updating IR playbooks, and reporting to leadership.

How to Pass the CIR Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 20 questions
  • Time limit: 3 hours
  • Exam fee: USD 1000 exam-only

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

CIR Study Tips from Top Performers

1Review the official PECB candidate handbook
2Practice scenario-based questions across all domains
3Pace yourself to answer all questions within the time limit

Frequently Asked Questions

What is the format of the PECB Incident Responder exam?

The official exam consists of 20 questions over 3 hours. This practice set provides 100 English-language MCQs as a study aid.

Is this practice test free?

Yes, 100% free with detailed explanations.