Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 6Objective 1

Incident Response and Forensics Investigation CND Practice Questions (Page 4)

Part of the Incident Response, Forensics and Continuity domain, which makes up ~13% of our current practice bank.

66questions here
14free pages
15concepts

Questions 16–20

  1. 16application · easy

    During an incident, you suspect a memory-resident malware on a Windows server. You need to capture volatile data for analysis. Which action should you take first?

    Select an answer first
  2. 17foundation · easy

    Why is hashing used when creating a forensic image?

    Select an answer first
  3. 18foundation · easy

    Which of the following is an example of a system artifact that can be analyzed in forensics?

    Select an answer first
  4. 19expert · hard

    An incident responder is collecting evidence from a compromised server that is part of a legal investigation. The server is running and the responder needs to capture volatile data. The responder also needs to create a forensic image of the disk. However, the server is in a remote location and cannot be physically accessed. Which approach is most appropriate?

    Select an answer first
  5. 20application · medium

    A forensic investigator needs to collect evidence from a computer that may contain personal data of European Union citizens. The investigation is in the United States. What must the investigator consider to remain legally compliant?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.