
EC-CouncilCertified Cybersecurity Technician
Domain 7Objective 1
Incident Response CCT Practice Questions (Page 10)
Part of the Incident Response and Computer Forensics domain, which makes up ~10% of our current practice bank.
50questions here
10free pages
8concepts
Questions 46–50
- 46
In the six-phase incident response lifecycle, what is the main goal of the 'lessons learned' phase?
Select an answer first - 47
A company wants to improve its ability to detect and respond to security incidents. Which initiative is MOST aligned with the preparation phase of incident response?
Select an answer first - 48
During a forensic investigation, an analyst needs to collect evidence from a running server. The analyst must preserve the evidence for potential legal action. Which action is MOST appropriate?
Select an answer first - 49
A security analyst discovers that an employee's account has been used to access sensitive data from an unusual location at an odd time. What is the FIRST step the analyst should take according to standard incident response procedures?
Select an answer first - 50
During a data breach investigation, an analyst collects a hard drive from a compromised server. Which practice is essential to maintain the chain of custody?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCT
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.