exam questions

Exam 312-38 All Questions

View all questions & answers for the 312-38 exam

Exam 312-38 topic 1 question 514 discussion

Actual exam question from ECCouncil's 312-38
Question #: 514
Topic #: 1
[All 312-38 Questions]

Which of the following is not part of the recommended first response steps for network defenders?

  • A. Restrict yourself from doing the investigation
  • B. Extract relevant data from the suspected devices as early as possible
  • C. Disable virus protection
  • D. Do not change the state of the suspected device
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Cyber_bunny
Highly Voted 11 months, 2 weeks ago
Selected Answer: B
The correct answer should be B - Extract relevant data from the suspected devices as early as possible. First Responder do not do any data extraction. It is done by the forensic team. Choices A, C and D are found in the list first responser steps for network defenders (do's and don'ts) Source - Certified Network Defender (CND) Version 2 eBook w/ iLabs (Volumes 1 through 4) Page 1457 - 1464
upvoted 7 times
...
ethacker
Most Recent 5 months, 3 weeks ago
Selected Answer: B
A. Restrict yourself from doing the investigation IS part of recommended first response steps. CND Book P.2137 C. Disable virus protection IS part of recommended first response steps. CND Book P.2139 D. Do not change the state of the suspected device IS part of recommended first response steps. CND Book P.2138 So option B. Extract relevant data from the suspected devices as early as possible must be the correct answer.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago