
EC-CouncilCertified Network Defender
Domain 6Objective 1
Incident Response and Forensics Investigation CND Practice Questions (Page 13)
Part of the Incident Response, Forensics and Continuity domain, which makes up ~13% of our current practice bank.
66questions here
14free pages
15concepts
Questions 61–65
- 61
After completing a forensic investigation, an incident responder must write a report for both technical staff and executive management. What is the most important consideration when writing the report?
Select an answer first - 62
A network defender is analyzing a packet capture from a suspected intrusion. The capture shows a series of TCP SYN packets to a single host on multiple ports, followed by RST responses. What does this pattern most likely indicate?
Select an answer first - 63
Who is the primary audience for a forensic report?
Select an answer first - 64
A company has confirmed a ransomware infection on several servers. The incident response team has contained the spread by isolating the affected network segment. What should be the next step in the incident response lifecycle?
Select an answer first - 65
What is the purpose of running malware in a sandbox during dynamic analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.