
EC-CouncilCertified Network Defender
Domain 6Objective 1
Incident Response and Forensics Investigation CND Practice Questions (Page 5)
Part of the Incident Response, Forensics and Continuity domain, which makes up ~13% of our current practice bank.
66questions here
14free pages
15concepts
Questions 21–25
- 21
When collecting digital evidence, what is the correct procedure for labeling evidence containers?
Select an answer first - 22
A forensic report is being prepared for a case involving a disgruntled employee accused of stealing trade secrets. The report must be clear enough for a jury with no technical background. Which approach is most effective?
Select an answer first - 23
During an investigation, an incident responder discovers that the compromised system contains personal data of customers. The organization is subject to GDPR. What is the most important legal consideration for the investigation?
Select an answer first - 24
What is the difference between static and dynamic malware analysis?
Select an answer first - 25
A hospital's network monitoring alerts on a workstation in the cardiology department that is beaconing to a known malware C2 domain. The workstation is used for patient admissions and cannot be taken offline without delaying critical care. The IR team has confirmed the beaconing is malicious but has not yet identified the full scope. Which action should the team take FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.