
EC-CouncilCertified Cybersecurity Technician
Domain 7Objective 2
Computer Forensics CCT Practice Questions (Page 8)
Part of the Incident Response and Computer Forensics domain, which makes up ~10% of our current practice bank.
56questions here
12free pages
13concepts
Questions 36–40
- 36
When testifying in court, what should a forensic investigator do?
Select an answer first - 37
An incident responder is analyzing a memory dump from a compromised Windows server. The responder finds a process that is injecting code into another legitimate process. The injected code is encrypted in memory. What is the most effective way to analyze the injected code?
Select an answer first - 38
What is the primary goal of computer forensics?
Select an answer first - 39
A forensic examiner needs to extract data from a seized smartphone that is locked with a PIN. The device is powered on and the examiner wants to preserve evidence. Which approach is most appropriate?
Select an answer first - 40
An examiner is analyzing a Linux system (ext4 filesystem) involved in a policy violation. The examiner needs to determine when a specific file was last modified and when it was deleted. Which source provides the MOST reliable metadata for these events?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.