Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Cybersecurity Technician

Domain 7Objective 1

Incident Response CCT Practice Questions (Page 1)

Part of the Incident Response and Computer Forensics domain, which makes up ~10% of our current practice bank.

50questions here
10free pages
8concepts

Questions 1–5

  1. 1application · medium

    A security analyst receives two alerts: one indicates a single workstation has adware installed, and the other indicates a domain controller is showing signs of credential theft. The team has limited resources. Which incident should be prioritized?

    Select an answer first
  2. 2application · medium

    A small business has no formal incident response plan. After a malware infection, the owner wants to ensure the business can respond effectively to future incidents. What is the MOST important first step?

    Select an answer first
  3. 3application · medium

    During a malware investigation, an analyst needs to collect a compromised laptop's memory for analysis. Which action is most appropriate to preserve the evidence's integrity?

    Select an answer first
  4. 4expert · hard

    A large organization is responding to a data breach. The incident commander is focused on coordinating the response, but the communications lead is also preparing a press release. The legal team has not yet approved the release. The communications lead wants to issue the release immediately to control the narrative. What should the incident commander do?

    Select an answer first
  5. 5foundation · easy

    Why is it important to preserve evidence during incident response?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.