[Q27-Q51] Full 212-89 Practice Test and 170 unique questions with explanations waiting just for you!

Share

Full 212-89 Practice Test and 170 unique questions with explanations waiting just for you!

ECIH Certification Dumps 212-89 Exam for Full Questions - Exam Study Guide


EC-COUNCIL is a leading provider of cybersecurity certifications, and the ECIH certification is one of the many certifications offered by the organization. The organization is known for its rigorous certification process and high-quality training programs. EC-COUNCIL also provides various resources such as study materials, practice exams, and webinars to help candidates prepare for the ECIH certification exam.

 

NEW QUESTION # 27
Which of the following processes is referred to as an approach to respond to the security incidents that occur in an organization and enables the response team by ensuring that they know exactly what process to follow in case of security incidents?

  • A. Threat assessment
  • B. Incident response orchestration
  • C. Risk assessment
  • D. Vulnerability management

Answer: B


NEW QUESTION # 28
Installing a password cracking tool, downloading pornography material, sending emails to colleagues which irritates them and hosting unauthorized websites on the company's computer are considered:

  • A. Network based attacks
  • B. Inappropriate usage incidents
  • C. Malware attacks
  • D. Unauthorized access attacks

Answer: B


NEW QUESTION # 29
Ren is assigned to handle a security incident of an organization. He is tasked with forensics investigation to find the evidence needed by the management.
Which of the following steps falls under the investigation phase of the computer forensics investigation process?

  • A. Secure the evidence
  • B. Setup a computer forensics lab
  • C. Evidence assessment
  • D. Risk assessment

Answer: A


NEW QUESTION # 30
In which of the following types of fuzz testing strategies the new data will be generated from scratch and the amount of data to be generated are predefined based on the testing model?

  • A. Log-based fuzz testing
  • B. Generation-based fuzz testing
  • C. Mutation-based fuzz testing
  • D. Protocol-based fuzz testing

Answer: C


NEW QUESTION # 31
What is the best staffing model for an incident response team if current employees' expertise is very low?

  • A. Fully insourced
  • B. Fully outsourced
  • C. Partially outsourced
  • D. All the above

Answer: B


NEW QUESTION # 32
Sam received an alert through an email monitoring tool indicating that their company was targeted by a phishing attack. After analyzing the incident, Sam identified that most of the targets of the attack are high-prof le executives of the company.
What type of phishing attack is this?

  • A. Whaling
  • B. Pharming
  • C. Spear phishing
  • D. Puddle phishing

Answer: A


NEW QUESTION # 33
In which of the following stages of incident handling and response (IH&R) process do the incident handlers try to find out the root cause of the incident along with the threat actors behind the incidents, threat vectors, etc.?

  • A. Incident recording and assignment
  • B. Evidence gathering and forensics analysis
  • C. Incident triage
  • D. Post-incident activities

Answer: B

Explanation:
During the incident handling and response (IH&R) process, the stage of "Evidence gathering and forensics analysis" involves the collection of evidence, forensic analysis, and detailed investigation to uncover the root cause of the incident. This stage is crucial for understanding how the incident occurred, identifying the threat actors involved, the methods they used (threat vectors), and the extent of the impact. By analyzing evidence, incident responders can reconstruct the sequence of events, identify the vulnerabilities exploited, and determine the scope of the incident. This information is vital for resolving the incident effectively and taking steps to prevent future occurrences.
References:The importance of evidence gathering and forensic analysis in the incident handling and response process is emphasized in ECIH v3 courses and study materials. These resources provide guidance on how to conduct thorough investigations to understand the nature of security incidents fully and develop effective mitigation strategies.


NEW QUESTION # 34
Identify the malicious program that is masked as a genuine harmless program and gives the attacker unrestricted access to the users information and system. These programs may unleash dangerous programs that may erase the unsuspecting user's disk and send the victim's credit card numbers and passwords to a stranger.

  • A. Virus
  • B. Worm
  • C. Adware
  • D. Trojan

Answer: D


NEW QUESTION # 35
In a DDoS attack, attackers first infect multiple systems, which are then used to attack a particular target directly. Those systems are called:

  • A. Handlers
  • B. Honey Pots
  • C. Zombies
  • D. Relays

Answer: C


NEW QUESTION # 36
Performing Vulnerability Assessment is an example of a:

  • A. Post Incident Management
  • B. Incident Handling
  • C. Incident Response
  • D. Pre-Incident Preparation

Answer: D


NEW QUESTION # 37
Removing or eliminating the root cause of the incident is called:

  • A. Incident Protection
  • B. Incident Containment
  • C. Incident Classification
  • D. Incident Eradication

Answer: D


NEW QUESTION # 38
Which of the following is a type of malicious code or software that appears legitimate but can take control of your computer?

  • A. Trojan attack
  • B. Password attack
  • C. Phishing attack
  • D. DDoS

Answer: A

Explanation:
A Trojan attack involves a type of malicious code or software that appears legitimate but can take control of your computer. Trojans often disguise themselves as legitimate software or are hidden within legitimate software that has been tampered with. They differ from viruses and worms because they do not replicate.
However, once activated, Trojans can enable cyber-criminals to spy on you, steal your sensitive data, and gain backdoor access to your system. This can include unauthorized actions such as deleting files, monitoring user activities, or installing additional malicious software.
References:The ECIH v3 course details various forms of malware, including Trojans, their modes of operation, and their impact on information security. Understanding the nature of these threats is crucial for effective incident handling and response.


NEW QUESTION # 39
BadGuy Bob hid files in the slack space, changed the file headers, hid suspicious files in executables, and changed the metadata for all types of files on his hacker laptop. What has he committed?

  • A. Adversarial mechanics
  • B. Anti-forensics
  • C. Legal hostility
  • D. Felony

Answer: B


NEW QUESTION # 40
Which of the following risk mitigation strategies involves the execution of controls to reduce the risk factor and bring it to an acceptable level, or accepts the potential risk and continues operating the IT system?

  • A. Risk transference
  • B. Risk avoidance
  • C. Risk assumption
  • D. Risk planning

Answer: C


NEW QUESTION # 41
Rossi san incident manager (IM) at an organization, and his team provides support to all users in the
organization who are affected by threats or attacks. David, who is the organization's intemal auditor, is also part of Ross's incident response team.
Which of the following is David's responsibility?

  • A. Identify and report security loopholes to the management for necessary action.
  • B. Coordinate incident containment activities with the information security officer (ISO).
  • C. Preform the necessary action to block the network traffic from the suspected intruder.
  • D. Configure information security controls.

Answer: A


NEW QUESTION # 42
Eric works as a system administrator at ABC organization and previously granted several users with access privileges to the organizations systems with unlimited permissions. These privileged users could prospectively misuse their rights unintentionally, maliciously, or could be deceived by attackers that could trick them to perform malicious activities.
Which of the following guidelines would help incident handlers eradicate insider at tacks by privileged users?

  • A. Do not allow administrators to use unique accounts during the installation process
  • B. Do not control the access to administrators and privileged users
  • C. Do not enable default administrative accounts to ensure accountability
  • D. Do not use encryption methods to prevent administrators and privileged users from accessing backup tapes and sensitive information

Answer: C


NEW QUESTION # 43
Which among the following CERTs is an Internet provider to higher education institutions and various other research institutions in the Netherlands and deals with all cases related to computer security incidents in which a customer is involved either as a victim or as a suspect?

  • A. Funet CERT
  • B. SURFnet-CERT
  • C. NET-CERT
  • D. DFN-CERT

Answer: B


NEW QUESTION # 44
Joseph is an incident handling and response (IH&R) team lead in Toro Network Solutions Company. As a part of IH&R process, Joseph alerted the service providers, developers, and manufacturers about the affected resources.
Identify the stage of IH&R process Joseph is currently in.

  • A. Containment
  • B. Eradication
  • C. Recovery
  • D. Incident triage

Answer: A

Explanation:
When Joseph, the IH&R team lead, alerted service providers, developers, and manufacturers about the affected resources, he was engaged in the Containment stage of the Incident Handling and Response (IH&R) process.
Containment involves taking steps to limit the spread or impact of an incident and to isolate affected systems to prevent further damage. Alerting relevant stakeholders, including service providers and developers, is part of containment efforts to ensure that the threat does not escalate and that measures are taken to protect unaffected resources. This stage precedes eradication and recovery, focusing on immediate response actions to secure the environment.References:The ECIH v3 certification program outlines the IH&R process stages, explaining the roles and actions involved in containment, including communication with external and internal stakeholders to manage and mitigate the incident's effects.


NEW QUESTION # 45
Ensuring the integrity, confidentiality and availability of electronic protected health information of a patient is known as:

  • A. Sarbanes-Oxley Act
  • B. Social Security Act
  • C. Health Insurance Portability and Privacy Act
  • D. Gramm-Leach-Bliley Act

Answer: C


NEW QUESTION # 46
Racheal is an incident handler working at an organization called Inception Tech. Recently, numerous employees have been complaining about receiving emails from unknown senders. In order to prevent employees from spoof ng emails and keeping security in mind, Racheal was asked to take appropriate actions in this matter. As a part of her assignment, she needs to analyze the email headers to check the authenticity of received emails.
Which of the following protocol/authentication standards she must check in email header to analyze the email authenticity?

  • A. SNMP
  • B. ARP
  • C. DKIM
  • D. POP

Answer: C


NEW QUESTION # 47
Identify a standard national process which establishes a set of activities, general tasks and a management structure to certify and accredit systems that will maintain the information assurance (IA) and security posture of a system or site.

  • A. NIPACP
  • B. NIACAP
  • C. NIAAAP
  • D. NIASAP

Answer: B


NEW QUESTION # 48
The correct sequence of incident management process is:

  • A. Prepare, protect, triage, detect and respond
  • B. Prepare, protect, detect, respond and triage
  • C. Prepare, protect, detect, triage and respond
  • D. Prepare, detect, protect, triage and respond

Answer: C


NEW QUESTION # 49
Which of the following is a correct statement about incident management, handling and response:

  • A. Incident response is on the functions provided by incident handling
  • B. Triage is one of the services provided by incident response
  • C. Incident handling is on the functions provided by incident response
  • D. Incident response is one of the services provided by triage

Answer: A


NEW QUESTION # 50
The most common type(s) of intellectual property is(are):

  • A. Industrial design rights & Trade secrets
  • B. Copyrights and Trademarks
  • C. All the above
  • D. Patents

Answer: C


NEW QUESTION # 51
......

Authentic Best resources for 212-89 Online Practice Exam: https://certkiller.passleader.top/EC-COUNCIL/212-89-exam-braindumps.html