Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 6Objective 1

Incident Response and Forensics Investigation CND Practice Questions (Page 8)

Part of the Incident Response, Forensics and Continuity domain, which makes up ~13% of our current practice bank.

66questions here
14free pages
15concepts

Questions 36–40

  1. 36foundation · easy

    What is the primary purpose of a post-incident review (lessons learned)?

    Select an answer first
  2. 37expert · hard

    A network forensic analyst is examining a pcap file from a suspected data exfiltration. The analyst sees a large amount of data being sent to an external IP over HTTPS. The analyst also sees DNS queries for a domain that resolves to that IP. Which action would BEST help confirm the exfiltration?

    Select an answer first
  3. 38foundation · easy

    What is the goal of the recovery phase in incident response?

    Select an answer first
  4. 39application · medium

    An incident responder is investigating a Windows workstation that is suspected of running malware. The malware is only present in memory and not on disk. The responder needs to identify the malicious process and its network connections. Which action should be taken FIRST?

    Select an answer first
  5. 40expert · hard

    An investigator is collecting evidence from a RAID server that is part of a database cluster. The server is still running and the database is in use. The investigator needs to preserve evidence without disrupting operations. Which approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.