
EC-CouncilAssociate C|CISO
Domain 4Objective 8
Computer Forensics and Incident Response ACCISO Practice Questions (Page 6)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 62 practice questions to prepare you well beyond it. (estimate)
62questions here
13free pages
11concepts
Questions 26–30
- 26
A company experiences a ransomware attack that encrypts files on multiple servers. The incident response team has isolated the affected servers. The company has backups, but the last backup was 24 hours old. The team needs to restore operations quickly while preserving evidence for law enforcement. What is the BEST course of action?
Select an answer first - 27
A security analyst is reviewing alerts from multiple sources. Which alert should be classified as the HIGHEST severity?
Select an answer first - 28
Why should a forensic report be written in a way that is understandable to non-technical audiences?
Select an answer first - 29
A forensic examiner has completed an investigation and is writing the final report. The report will be used in a civil lawsuit. The examiner must ensure the report is defensible in court. What is the MOST important element to include?
Select an answer first - 30
During a forensic analysis of a Windows system image, an examiner finds that a user's document folder appears empty, but the file system metadata suggests files were recently deleted. Which technique is most likely to recover the contents of these deleted files?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.