
EC-CouncilAssociate C|CISO
Domain 4Objective 8
Computer Forensics and Incident Response ACCISO Practice Questions (Page 5)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 62 practice questions to prepare you well beyond it. (estimate)
62questions here
13free pages
11concepts
Questions 21–25
- 21
A forensic examiner is preparing to analyze a hard drive that contains personal data of customers. The examiner is working under a court order. What ethical and legal consideration is MOST important?
Select an answer first - 22
After a security incident, the incident response team is writing a report for the company's board of directors. What is the most appropriate way to present the findings?
Select an answer first - 23
A company's web server is compromised and is serving malware to visitors. The incident response team needs to stop the immediate threat while preserving evidence for analysis. Which containment strategy is most appropriate?
Select an answer first - 24
What is the primary purpose of maintaining a chain of custody for digital evidence?
Select an answer first - 25
A security analyst detects unusual outbound traffic from a finance workstation to an unknown IP address. The workstation is part of a domain and contains sensitive data. Which action should the analyst take FIRST in the incident response process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.