
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 8
Computer Forensics and Incident Response CCISO Practice Questions (Page 4)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
13concepts
Questions 16–20
- 16
During a malware investigation, an incident responder needs to collect evidence from a running Windows server without losing volatile data. Which action is MOST appropriate?
Select an answer first - 17
A company has just completed a post-incident review of a data breach. The review identified that the incident response team lacked clear communication channels with the legal department. What is the most appropriate action to address this finding?
Select an answer first - 18
Which tool is commonly used for disk imaging and forensic analysis?
Select an answer first - 19
Which factor is most important when determining the urgency of an incident response?
Select an answer first - 20
A forensic investigator needs to analyze a memory dump from a compromised server to identify a rootkit. Which tool is BEST suited for this task?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.