
EC-CouncilCertified Network Defender
Domain 6Objective 1
Incident Response and Forensics Investigation CND Practice Questions (Page 6)
Part of the Incident Response, Forensics and Continuity domain, which makes up ~13% of our current practice bank.
66questions here
14free pages
15concepts
Questions 26–30
- 26
An analyst is examining a forensic image of a compromised server. The analyst finds a suspicious script in the /tmp directory and a corresponding entry in the bash history. The script appears to download a payload from an external IP. Which forensic artifact would BEST help the analyst reconstruct the attack timeline?
Select an answer first - 27
A small company has no formal incident response plan. A malware infection is spreading across the network. Which immediate action best aligns with incident response fundamentals?
Select an answer first - 28
A company has just contained a ransomware outbreak. The malware has been removed from all affected systems, and the systems have been restored from backups. What is the NEXT step in the incident response process?
Select an answer first - 29
What is the correct sequence of phases in the incident response lifecycle?
Select an answer first - 30
What type of information can be obtained from analyzing a memory dump?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.