
EC-CouncilCertified Network Defender
Domain 6Objective 1
Incident Response and Forensics Investigation CND Practice Questions (Page 1)
Part of the Incident Response, Forensics and Continuity domain, which makes up ~13% of our current practice bank.
66questions here
14free pages
15concepts
Questions 1–5
- 1
During an investigation of a suspected data exfiltration, you need to seize a laptop from a user's desk. The laptop is powered on and the user is logged in. Which step should you take to preserve evidence in a legally defensible manner?
Select an answer first - 2
Why must incident responders adhere to legal and ethical standards during an investigation?
Select an answer first - 3
During triage, which incident should be prioritized first?
Select an answer first - 4
A malware analyst is analyzing a suspicious binary. Static analysis reveals the binary is packed and contains anti-debugging checks. Dynamic analysis in a sandbox shows the binary creates a mutex named 'Global\MSUpdate' and attempts to connect to an IP address on port 445. What is the best next step to understand the malware's purpose?
Select an answer first - 5
A security analyst is correlating logs from a web server, a database server, and a firewall. The web server logs show a SQL injection attempt in the URL. The database logs show an unusual query that returned a large result set. The firewall logs show an outbound connection from the database server to an external IP. What is the most likely attack path?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.