
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 8
Computer Forensics and Incident Response CCISO Practice Questions (Page 2)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
13concepts
Questions 6–10
- 6
A company has just completed the eradication and recovery phases of a phishing incident that led to unauthorized access to email accounts. The CISO wants to ensure the organization learns from the incident. Which activity is most aligned with the lessons learned phase?
Select an answer first - 7
A forensic examiner is collecting evidence from a company-owned server that is located in a jurisdiction with strict data privacy laws. The evidence may be used in a civil lawsuit. What is the MOST important legal consideration?
Select an answer first - 8
Which forensic analysis technique is used to examine the contents of a computer's RAM?
Select an answer first - 9
Which method is commonly used to detect security incidents?
Select an answer first - 10
Why is cross-functional collaboration important in an incident response team?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.