Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 6Objective 1

Incident Response and Forensics Investigation CND Practice Questions (Page 13)

Part of the Incident Response, Forensics and Continuity domain, which makes up ~13% of our current practice bank.

66questions here
14free pages
15concepts

Questions 61–65

  1. 61application · medium

    After completing a forensic investigation, an incident responder must write a report for both technical staff and executive management. What is the most important consideration when writing the report?

    Select an answer first
  2. 62application · easy

    A network defender is analyzing a packet capture from a suspected intrusion. The capture shows a series of TCP SYN packets to a single host on multiple ports, followed by RST responses. What does this pattern most likely indicate?

    Select an answer first
  3. 63foundation · easy

    Who is the primary audience for a forensic report?

    Select an answer first
  4. 64application · easy

    A company has confirmed a ransomware infection on several servers. The incident response team has contained the spread by isolating the affected network segment. What should be the next step in the incident response lifecycle?

    Select an answer first
  5. 65foundation · easy

    What is the purpose of running malware in a sandbox during dynamic analysis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.