
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 8
Computer Forensics and Incident Response CCISO Practice Questions (Page 5)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
13concepts
Questions 21–25
- 21
What is a limitation of using a network protocol analyzer like Wireshark in incident response?
Select an answer first - 22
A manufacturing company discovers that a contractor's laptop, which was used to access the corporate network, may contain evidence of intellectual property theft. The laptop is running and the user is still logged in. The CISO wants to preserve evidence for potential litigation. Which action best balances forensic soundness and legal admissibility?
Select an answer first - 23
What is the purpose of maintaining a chain of custody for digital evidence?
Select an answer first - 24
A security analyst is investigating a suspected data breach. The analyst finds unusual outbound network traffic to an IP address in a foreign country. Which forensic technique would BEST help identify the malware responsible?
Select an answer first - 25
Which activity is part of forensic readiness?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.