
EC-CouncilCertified Network Defender
Domain 6Objective 1
Incident Response and Forensics Investigation CND Practice Questions (Page 12)
Part of the Incident Response, Forensics and Continuity domain, which makes up ~13% of our current practice bank.
66questions here
14free pages
15concepts
Questions 56–60
- 56
Why is it important to capture volatile memory data before powering off a compromised system?
Select an answer first - 57
What is the purpose of containment strategies in incident response?
Select an answer first - 58
A memory dump from a compromised Windows server reveals a suspicious process that is not present in the file system. The process has an open TCP connection to an external IP. The analyst needs to determine if the process is malicious. Which combination of analyses would provide the STRONGEST evidence?
Select an answer first - 59
What is the primary purpose of maintaining a chain of custody for digital evidence?
Select an answer first - 60
During a forensic investigation of a suspected data exfiltration, an analyst needs to collect evidence from a Linux server that is still running. The server hosts a critical application that cannot be stopped. Which evidence collection approach best preserves the integrity of the evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.