Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Cybersecurity Technician

Domain 7Objective 1

Incident Response CCT Practice Questions (Page 7)

Part of the Incident Response and Computer Forensics domain, which makes up ~10% of our current practice bank.

50questions here
10free pages
8concepts

Questions 31–35

  1. 31application · medium

    After a malware incident is contained and eradicated, the incident response team holds a post-incident review. What is the PRIMARY purpose of this review?

    Select an answer first
  2. 32application · medium

    A user reports receiving a phishing email that appears to come from the company's CEO, requesting urgent wire transfer. The user did not click any links. The email is still in the user's inbox. What is the FIRST step in the incident response procedure?

    Select an answer first
  3. 33application · medium

    Following a ransomware incident, the incident response team completes the recovery phase and restores all systems. What is the primary purpose of conducting a post-incident review?

    Select an answer first
  4. 34application · medium

    During a major security incident, the incident response team is activated. The incident commander is coordinating the response, the lead investigator is analyzing the attack vector, and the communications lead is handling external communications. A new piece of evidence is discovered that could affect the investigation. Who should be responsible for documenting this evidence?

    Select an answer first
  5. 35foundation · easy

    What is the primary audience for an executive summary in an incident report?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.