Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 6Objective 1

Incident Response and Forensics Investigation CND Practice Questions (Page 6)

Part of the Incident Response, Forensics and Continuity domain, which makes up ~13% of our current practice bank.

66questions here
14free pages
15concepts

Questions 26–30

  1. 26application · medium

    An analyst is examining a forensic image of a compromised server. The analyst finds a suspicious script in the /tmp directory and a corresponding entry in the bash history. The script appears to download a payload from an external IP. Which forensic artifact would BEST help the analyst reconstruct the attack timeline?

    Select an answer first
  2. 27application · medium

    A small company has no formal incident response plan. A malware infection is spreading across the network. Which immediate action best aligns with incident response fundamentals?

    Select an answer first
  3. 28application · medium

    A company has just contained a ransomware outbreak. The malware has been removed from all affected systems, and the systems have been restored from backups. What is the NEXT step in the incident response process?

    Select an answer first
  4. 29foundation · easy

    What is the correct sequence of phases in the incident response lifecycle?

    Select an answer first
  5. 30foundation · easy

    What type of information can be obtained from analyzing a memory dump?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.