
EC-CouncilCertified Cybersecurity Technician
Domain 7Objective 1
Incident Response CCT Practice Questions (Page 4)
Part of the Incident Response and Computer Forensics domain, which makes up ~10% of our current practice bank.
50questions here
10free pages
8concepts
Questions 16–20
- 16
An incident response team is documenting a security incident. The team needs to create a report that will be shared with law enforcement. What information is MOST important to include?
Select an answer first - 17
A company has a limited incident response team. Two incidents occur: a low-severity malware infection on a single workstation and a suspected data exfiltration from a critical server. The team can only handle one incident at a time. What is the BEST approach?
Select an answer first - 18
A company's intrusion detection system alerts on a possible unauthorized access to a database containing customer records. The alert is confirmed as a true positive. What is the NEXT step in the incident response procedure?
Select an answer first - 19
During an incident, a first responder accidentally turns off a compromised server before a forensic image is taken. The server is later rebooted and used for normal operations. The incident response team is now preparing a report for potential litigation. What is the BEST way to handle this situation?
Select an answer first - 20
A security team receives two incident alerts: one is a low-severity phishing email that was not clicked, and the other is a high-severity malware infection on a critical server. Which incident should be handled first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.