
EC-CouncilCertified Cybersecurity Technician
Domain 7Objective 1
Incident Response CCT Practice Questions (Page 2)
Part of the Incident Response and Computer Forensics domain, which makes up ~10% of our current practice bank.
50questions here
10free pages
8concepts
Questions 6–10
- 6
After an incident, the incident response team is writing the final report. The report will be shared with the board of directors, who are not technical. The report must also be detailed enough for the internal security team to use for future improvements. What is the BEST way to structure the report?
Select an answer first - 7
What is the main purpose of a post-incident review?
Select an answer first - 8
A company experiences a ransomware attack that encrypts critical files. The incident response team is considering whether to pay the ransom. Which action is MOST aligned with standard incident response procedures?
Select an answer first - 9
During an incident, a first responder collects a USB drive from a suspect's desk. The responder labels it with their initials, date, and time, then places it in a locked evidence locker. Later, the lead investigator retrieves the drive for analysis. What additional step is REQUIRED to maintain the chain of custody?
Select an answer first - 10
What is the purpose of a chain of custody in evidence handling during incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.