Practise vocabulary for incident classification, containment, eradication, notifications, and post-incident reviews.
0 / 6 completed
1 / 6
Containment in incident response means:
Containment happens before eradication: stop the bleeding first. Short-term containment (isolate affected host) then long-term containment (patch or rebuild systems). Some evidence may need to be preserved before containment for forensic purposes.
2 / 6
Eradication in the incident response lifecycle means:
Eradication follows containment: identify and remove all attacker footholds. This includes removing malware, rotating credentials, patching the initial access vulnerability, and auditing for persistence mechanisms the attacker may have installed.
3 / 6
Under GDPR, a personal data breach that 'is unlikely to result in a risk to the rights and freedoms of natural persons':
GDPR Article 33(1): notification to supervisory authority is required 'unless the personal data breach is unlikely to result in a risk'. However, all breaches — even low-risk ones — must be documented internally per Article 33(5).
4 / 6
Lateral movement in a security incident means:
Lateral movement techniques (MITRE ATT&CK Tactic: TA0008): pass-the-hash, pass-the-ticket, remote services exploitation, use of legitimate tools (PsExec, WMI). Detecting lateral movement early limits blast radius.
5 / 6
When writing an incident notification to affected customers, the correct approach is:
Customer-facing breach notifications should be empathetic, clear, and actionable. Avoid jargon like 'unauthorised actor gained access to production systems' — say 'an attacker accessed our systems'. Tell customers what to do (change your password, watch for phishing).
6 / 6
A 'lessons learned' session after a security incident should primarily focus on:
Post-incident reviews (PIRs) should be blameless and systems-focused: 'Our detection rules didn't catch this technique' not 'the analyst missed the alert'. The goal is improving processes, tools, and playbooks — not assigning blame.
What does the "Security Incident Response Vocabulary" exercise practise?How many questions are in this exercise?
This exercise has 6 questions, each multiple-choice with a full explanation shown after you answer.
What English level is this exercise for?
This exercise is tagged Intermediate. If the vocabulary feels difficult, browse the Cybersecurity category page for an easier module to start with.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free with no account, sign-up, or paywall.
Do I get feedback if I answer incorrectly?
Yes — whichever option you choose, right or wrong, you'll immediately see an explanation clarifying the correct term and why the other options don't fit.
Can I retry this exercise?
Yes — once you finish all the questions, a "Try again" button on the results screen resets the exercise so you can practise as many times as you like.
Do I need an account to track my progress?
No account is required. Your progress bar and score for this session are tracked in the browser as you go, but nothing is saved once you leave the page.
Is "Security Incident Response Vocabulary" part of a larger series?
Yes — it's one exercise in the Cybersecurity category on CoderSlingo. See the category page for the full list of related exercises on similar terminology.
Can I link directly to this exercise?
Yes — this exercise has its own permanent URL, so you can bookmark it or share the link directly with a colleague or study partner.
Where can I find more exercises like this one?
See the Cybersecurity category page for related exercises, or browse the main Exercises hub for other IT English topics.