
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 8
Computer Forensics and Incident Response CCISO Practice Questions (Page 3)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
13concepts
Questions 11–15
- 11
Which legal consideration is most important when handling digital evidence?
Select an answer first - 12
Which phase of the incident response lifecycle involves restoring affected systems to normal operation?
Select an answer first - 13
A large e-commerce company experiences a distributed denial-of-service (DDoS) attack that is affecting customer transactions. The incident response team is activated. Which team role is PRIMARILY responsible for communicating with external stakeholders such as customers and regulatory bodies?
Select an answer first - 14
What is the primary purpose of a post-incident review?
Select an answer first - 15
A manufacturing company discovers that a disgruntled employee exfiltrated sensitive design documents to a personal cloud storage account before resigning. The employee's laptop has been collected, and the company wants to prevent further data loss while preserving evidence. The CISO must decide on a containment strategy. Which action BEST balances containment and evidence preservation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.