Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 6Objective 1

Incident Response and Forensics Investigation CND Practice Questions (Page 12)

Part of the Incident Response, Forensics and Continuity domain, which makes up ~13% of our current practice bank.

66questions here
14free pages
15concepts

Questions 56–60

  1. 56foundation · easy

    Why is it important to capture volatile memory data before powering off a compromised system?

    Select an answer first
  2. 57foundation · easy

    What is the purpose of containment strategies in incident response?

    Select an answer first
  3. 58expert · hard

    A memory dump from a compromised Windows server reveals a suspicious process that is not present in the file system. The process has an open TCP connection to an external IP. The analyst needs to determine if the process is malicious. Which combination of analyses would provide the STRONGEST evidence?

    Select an answer first
  4. 59foundation · easy

    What is the primary purpose of maintaining a chain of custody for digital evidence?

    Select an answer first
  5. 60application · medium

    During a forensic investigation of a suspected data exfiltration, an analyst needs to collect evidence from a Linux server that is still running. The server hosts a critical application that cannot be stopped. Which evidence collection approach best preserves the integrity of the evidence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.