
EC-CouncilCertified Network Defender
Domain 6Objective 1
Incident Response and Forensics Investigation CND Practice Questions (Page 9)
Part of the Incident Response, Forensics and Continuity domain, which makes up ~13% of our current practice bank.
66questions here
14free pages
15concepts
Questions 41–45
- 41
After a major incident, the IR team conducts a lessons-learned review. The team identifies that the incident detection was delayed because the SIEM alerts were not prioritized correctly. Which improvement would MOST directly address this issue?
Select an answer first - 42
After a major security incident, the incident response team completes the recovery phase. Which activity should be performed to improve future response efforts?
Select an answer first - 43
What is a key ethical consideration when handling personal data during a forensic investigation?
Select an answer first - 44
What is the primary purpose of network forensics?
Select an answer first - 45
A forensic analyst is examining a compromised Linux server. The memory dump shows a process named 'kworker' with a suspicious parent PID. The disk image shows a modified cron job that downloads a script from an external IP. The auth log shows a successful SSH login from an unknown IP at 3:00 AM. Which combination of findings best supports a conclusion that the server was compromised?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.