5-question quiz on the key roles in an incident command structure. Advanced
0 / 16 completed
1 / 16
During a SEV-1 outage, someone on the bridge announces: "Sarah is IC for this incident." What is the Incident Commander's primary role?
Correct: B. The Incident Commander (IC) does not need to be the best technical person in the room — the IC's job is command and coordination. They maintain situational awareness, make calls when responders are blocked or disagree, control the pace, and ensure nothing falls through the cracks. Freeing the IC from technical work is intentional: it keeps their attention on the bigger picture.
The IC says: "Marcus, you're Operations Lead." What does the Operations Lead own during an incident?
Correct: B. The Operations Lead (Ops Lead) is the IC's technical proxy on the bridge. While the IC manages communication, pace, and decisions, the Ops Lead manages the engineers doing the work: assigns tasks, tracks who is investigating what, consolidates findings, and surfaces blockers to the IC. The role prevents the IC from becoming a technical bottleneck.
Overall response, decisions, roles, communication cadence
3 / 16
During a major incident, the IC assigns one person as "Comms Lead." What is the Communications Lead's function?
Correct: B. The Comms Lead (Communications Lead) is the bridge between the incident response room and the outside world. Without a dedicated Comms Lead, the IC gets inundated with update requests from stakeholders, which breaks focus on resolution. The Comms Lead owns the cadence, content, and channels of all outbound messaging.
Comms Lead owns
Does not own
Internal stakeholder updates, status page, exec briefing
An incident bridge has a designated Scribe. A team member asks: "Why do we need a Scribe if all the discussion is already in Slack?" What is the Scribe's function?
Correct: B. Slack threads during an incident are noisy, unstructured, and hard to reconstruct after the fact. The Scribe maintains a separate, timestamped incident log — recording when key decisions were made, what was tried, and what was found. This becomes the factual backbone of the post-mortem and helps people joining mid-incident get up to speed instantly.
Scribe captures
Example entry
Key finding
14:23 — DB connection pool exhaustion confirmed on replica-1
Decision
14:31 — IC decided to restart replica-1 as immediate mitigation
5 / 16
The IC says: "We need an SME for the payments service on the bridge immediately." Who is typically paged as a Subject Matter Expert (SME) during an incident?
Correct: B. An SME is called in when the incident involves a component that requires specialist knowledge the current bridge team doesn't have. The SME provides expertise on their specific domain — answering "what could cause this behaviour in payments?" — but does not take command. The IC continues to direct the response; the SME is a targeted technical resource.
IC role: Commands
SME role: Advises
Directs the overall response; makes decisions
Provides deep domain knowledge; answers technical questions
6 / 16
David, the IC for this escalated production issue, sends a Slack message to the team: 'Okay everyone, we're escalating. Emily, can you take ownership of coordinating the rollbacks across all environments and provide updates every 15 minutes?' What does Emily's role primarily involve during this incident?
The IC is delegating responsibility for a critical action – rolling back changes. Emily's task focuses on executing this directive and maintaining situational awareness, which is core to an Operations Lead's duties. Options A, C, and D represent other roles typically involved in incident response but aren't directly assigned by the IC in this scenario.
7 / 16
Ben, the Incident Commander, is reviewing a Pull Request describing a change to the authentication service. The PR includes detailed steps and justifications. Ben comments: 'This looks good, but can you add some more information about how this affects our existing user flows?' What aspect of the incident response does Ben's comment primarily address?
Ben's comment highlights a crucial step in managing an incident – understanding the potential consequences (impact) of the change. The IC's responsibility includes ensuring that all actions taken during an incident are aligned with the overall strategy and don't inadvertently cause further problems. Options A, C, and D relate to more granular aspects like code review or immediate fixes, but not strategic alignment.
8 / 16
During a major outage affecting the payment processing system, the IC, Olivia, assigns Daniel as the 'API Monitoring Lead.' What is Daniel's primary responsibility in this situation?
The IC's designation of Daniel as 'API Monitoring Lead' indicates a focus on observing the health and behavior of the impacted API. This aligns with operational monitoring – tracking key metrics and identifying deviations that signal an issue. Options A, C, and D represent other functions, such as development or access management, which are not central to this specific incident response role.
9 / 16
David, the IC for this escalated production issue, sends a Slack message to the team: 'Okay everyone, we're escalating. Emily, can you take ownership of coordinating the rollbacks across all environments and provide updates every 15 minutes?' What does Emily's role primarily involve during this incident?
The IC is delegating responsibility for a critical action – rolling back changes. Emily's task focuses on executing this directive and maintaining situational awareness, which is core to an Operations Lead's duties. Options A, C, and D represent other roles typically involved in incident response but aren't directly assigned by the IC in this scenario.
10 / 16
Ben, the Incident Commander, is reviewing a Pull Request describing a change to the authentication service. The PR includes detailed steps and justifications. Ben comments: 'This looks good, but can you add some more information about how this affects our existing user flows?' What aspect of the incident response does Ben's comment primarily address?
Ben's comment highlights a crucial step in managing an incident – understanding the potential consequences (impact) of the change. The IC's responsibility includes ensuring that all actions taken during an incident are aligned with the overall strategy and don't inadvertently cause further problems. Options A, C, and D relate to more granular aspects like code review or immediate fixes, but not strategic alignment.
11 / 16
During a major outage affecting the payment processing system, the IC, Olivia, assigns Daniel as the 'API Monitoring Lead.' What is Daniel's primary responsibility in this situation?
The IC's designation of Daniel as 'API Monitoring Lead' indicates a focus on observing the health and behavior of the impacted API. This aligns with operational monitoring – tracking key metrics and identifying deviations that signal an issue. Options A, C, and D represent other functions, such as development or access management, which are not central to this specific incident response role.
12 / 16
Alex, the Incident Commander for a critical database outage, sends this message to the bridge: 'John, please focus on identifying the root cause and documenting all steps taken. Sarah, I need you to manage communications with stakeholders – keep them updated on our progress every 30 minutes.
What is John's primary role in this scenario?
John's role as 'focus on identifying the root cause' aligns with a core responsibility of an Incident Commander – technical investigation. The IC delegates specific tasks (communications, documentation) to other team members. Options A and C misrepresent John's function; B incorrectly assumes the database is operational.
13 / 16
During a widespread service degradation impacting user logins, Liam, the Incident Commander, directs Maria to 'Establish a clear timeline of events.' What does this primarily involve?
Establishing a timeline is crucial for understanding the sequence of events during an incident. This helps in identifying dependencies, pinpointing the initial trigger, and informing recovery strategies. Options A, C, and D represent broader activities related to incident response and post-incident analysis but don't capture the immediate need for a chronological record.
14 / 16
Chloe is the Incident Commander for a recent surge in API errors. She asks David, the 'Monitoring Lead,' to 'Provide real-time dashboards showing request volume and error rates.' What does David *primarily* deliver?
David's role as 'Monitoring Lead' centers around providing immediate visibility into the incident. Real-time dashboards offering visualizations of key metrics (request volume, error rates) are essential for quickly assessing the scope and impact of the issue. Options A, C, and D represent supplementary data or response mechanisms, not David's primary deliverable.
15 / 16
During a major outage of the core payment service, Ben, the Incident Commander, needs to quickly assess the impact. He asks Emily, the 'Service Owner,' for an update. Emily responds: 'The system is currently unavailable, and we're seeing high error rates on transaction requests.' What does Emily's statement *primarily* communicate?
Emily's statement provides a succinct and critical update on the core payment service – its unavailability and high error rates. While further details would be needed, this initial communication is paramount for Ben to understand the severity of the situation. Options A, C, and D represent deeper analysis or action plans that Emily wouldn't provide at this stage.
16 / 16
The Incident Commander, Ryan, is coordinating a response to a DDoS attack. He asks Michael, the 'Network Lead,' for recommendations. Michael replies: 'I'm implementing rate limiting rules and increasing our firewall capacity.' What action is Michael taking?
Implementing rate limiting and increasing firewall capacity are direct actions taken to combat a DDoS attack – reducing the volume of malicious traffic. This aligns with Michael's role as Network Lead. Options A, C, and D represent broader network management activities that aren't directly addressing the immediate threat of the DDoS attack.
What will I practise in "IC Roles & Responsibilities — Incident Command Exercises"?
Practice English vocabulary for incident command roles: Incident Commander, Operations Lead, Communications Lead, Scribe, and Subject Matter Expert in professional incident response.
How many exercises are in this module?
This module has 16 multiple-choice exercises, each with instant feedback and a full explanation of the correct answer.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account, sign-up, or paywall.
Do I need to create an account to do these exercises?
No account is required. Just click an option to answer — your score for this session is tracked automatically in the progress bar above.
What happens if I choose the wrong answer?
You'll immediately see which answer was correct, plus a full explanation covering the vocabulary and reasoning behind it — mistakes are where most of the learning happens.
Can I retry the exercises if I want a higher score?
Yes — use the "Try again" button on the results screen to reset and go through all the questions again.
Is my progress saved if I close the page?
No. Progress is tracked only for your current visit; reloading or leaving the page resets the counter. This keeps the exercise simple and account-free.
Where can I find more Incident Command Language exercises?
Browse the full Incident Command Language hub for related drills, or check the "Next up" link below to continue with a connected topic.
How is this different from reading an article on the same topic?
Articles explain vocabulary and concepts in prose; this exercise tests and reinforces that vocabulary through active recall with immediate feedback — the two work best together.
Who writes these exercises?
Every exercise is written by the CoderSlingo team, drawing on real workplace English used in IT roles, then reviewed for accuracy and clarity.