
EC-CouncilAssociate C|CISO
Domain 4Objective 8
Computer Forensics and Incident Response ACCISO Practice Questions (Page 3)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 62 practice questions to prepare you well beyond it. (estimate)
62questions here
13free pages
11concepts
Questions 11–15
- 11
A company experiences a malware outbreak that affects multiple servers. The security team must contain the incident while minimizing business disruption. Which containment strategy is most appropriate?
Select an answer first - 12
A ransomware attack has encrypted files on several servers. The incident response team has isolated the affected servers. What is the NEXT step in the containment, eradication, and recovery process?
Select an answer first - 13
A company's intrusion detection system alerts on a workstation that is beaconing to a known command-and-control server. The workstation is used by an executive and contains sensitive documents. What is the FIRST step in the incident response process?
Select an answer first - 14
A forensic examiner receives a seized laptop from law enforcement. The examiner must create a forensic image without altering the original drive. Which procedure should the examiner follow?
Select an answer first - 15
Which of the following is an example of a high-severity incident that should be prioritized?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.