EC-COUNCIL EC Council Certified Incident Handler (ECIH v3) - 212-89 Exam Practice Test

Michael is a part of the computer incident response team of a company. One of his responsibilities is to handle email incidents. The company receives an email from an unknown source, and one of the steps that he needs to take is to check the validity of the email. Which of the following tools should he use?
Correct Answer: C
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Rica works as an incident handler for an international company. As part of her role, she must review the present security policy implemented. Upon inspection, Rica finds that the policy is wide open, and only known dangerous services/attacks or behaviors are blocked. Which of the following is the current policy that Rica identified?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Alexis works as an incident responder at XYZ organization. She was asked to identify and attribute the actors behind an attack that occurred recently. For this purpose, she is performing a type of threat attribution that deals with the identification of a specific person, society, or country sponsoring a well-planned and executed intrusion or attack on its target. Which of the following types of threat attributions is Alexis performing?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Aarav, an IT support specialist, identifies that multiple employees have engaged with an email promoting free shopping vouchers, which appears suspicious. To minimize the potential threat, he instructs staff to report the message, classify it as junk, and remove it from their inboxes. He further advises them not to interact with similar messages in the future, even if they seem to come from internal contacts. Which best practice is Aarav reinforcing?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
What is the primary goal of the identification phase in the incident handling process?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
After unearthing malware within their AI-based prediction systems, Future Tech Corp realized that their business projections were skewed. This malware was not just altering data but was equipped with machine learning capabilities, evolving its methods. With access to a dedicated AI security module and a database restoration tool, what's the primary step?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
The cybersecurity response team at a global enterprise receives an alert from an employee regarding a suspicious email that appears to be from a senior executive. During the investigation, the team analyzes the email header and notices that the sending IP address originates from a foreign country that has no affiliation with the organization. A WHOIS lookup confirms that the IP is registered under an unknown entity. What key element helped identify the suspicious activity?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A company has recently migrated its critical applications and data to the cloud environment to take advantage of scalability and cost savings. However, they are facing challenges ineffectively handling and responding to security incidents in the cloud. What is one of the key challenges in cloud incident handling and response?
Correct Answer: D
NovoMed, a pharmaceutical giant, recently launched a drug after 10 years of research. A week later, their systems were compromised. Forensics revealed encrypted data transfers to an unknown location. The encrypted data consisted of the drug's research files, trials, and participant data. Additionally, the company's communication systems received a message in broken English, hinting at releasing the drug's formula. Which is the most prudent course of action?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).