EC-Council ECIH (212-89) Certification Sample Questions

ECIH Dumps, 212-89 Dumps, 212-89 PDF, ECIH VCE, EC-Council 212-89 VCE, EC-Council ECIH v3 PDFThe purpose of this Sample Question Set is to provide you with information about the EC-Council Certified Incident Handler exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the 212-89 certification test. To get familiar with real exam environment, we suggest you try our Sample EC-Council ECIH Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual EC-Council Certified Incident Handler (ECIH) certification exam.

These sample questions are simple and basic questions that represent likeness to the real EC-Council 212-89 exam questions. To assess your readiness and performance with real time scenario based questions, we suggest you prepare with our Premium EC-Council ECIH Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

EC-Council 212-89 Sample Questions:

01. A departing engineer copies the undisclosed chemical formula that gives her employer its advantage over competitors, and carries it to a rival firm.
Which category of intellectual property has been stolen?
a) Trade secret
b) Copyright
c) Trademark
d) Patent
 
02. An incident handler is triaging a workstation suspected of running an e-mail-borne virus.
Which observation most directly indicates that the host is now spreading the infection to other systems?
a) Antivirus on the host has quarantined an infected e-mail attachment
b) The host's antivirus signature database has not been updated
c) Several operating system files on the host can no longer be opened
d) A surge of outbound e-mail from the host that the user did not send
 
03. An organization keeps no retention schedule for its security logs, has no documented evidence-handling procedure and has trained no first responder. Months after a breach it is asked to substantiate what happened.
Which consequence follows directly from this lack of forensic readiness?
a) The intrusion went undetected, because detection is a forensic-readiness capability
b) Eradication was impossible without a forensic image of the affected host
c) Containment failed, since a documented chain of custody is what stops an incident spreading
d) Evidence that would substantiate the breach was never preserved, so it cannot now be produced
 
04. Any information of probative value that is either stored or transmitted in a digital form during a computer crime is called:
a) Computer Emails
b) Digital investigation
c) Digital evidence
d) Digital Forensic Examiner
 
05. Business continuity planning is an umbrella under which several subordinate plans sit.
Which of these is the plan concerned specifically with restoring IT systems and infrastructure after a disruption?
a) Incident response plan
b) Disaster recovery plan
c) Crisis communication plan
d) Business resumption plan
 
06. Insider threats are classified by the insider's intent and situation.
Which of the following describes a negligent insider?
a) A staff member who deliberately copies proprietary data to a personal drive before resigning
b) A legitimate user whose credentials are under an external attacker's control
c) An employee who bypasses a security procedure for convenience, without intending harm
d) An employee recruited and paid by a competitor to extract confidential information
 
07. Insiders understand corporate business functions.
What is the correct sequence of activities performed by an insider to damage company assets?
a) Gain privileged access, install malware then activate
b) Gain privileged access, activate and install malware
c) Install malware, gain privileged access, then activate
d) Activate malware, gain privileged access then install malware
 
08. James is a professional hacker employed by an organization to exploit their cloud services. In order to achieve this, James created anonymous access to the cloud services to carry out various attacks such as password and key cracking, hosting malicious data, and DDoS attacks.
Which of the following threats is he posing to the cloud platform?
a) Data breach/loss
b) Abuse and nefarious use of cloud services
c) Insecure interface and APIs
d) Insufficient due diligence
 
09. Malicious code that is installed on a computer without the user's knowledge, in order to acquire information from that user's machine and send it to an attacker who can access it remotely, is called:
a) Trojan
b) Spyware
c) Logic Bomb
d) Worm
 
10. Zaimasoft, a prominent IT organization, was attacked by perpetrators who targeted the hardware directly and caused irreversible damage to it, leaving replacement or reinstallation as the only remaining option.
Identify the type of denial-of-service attack performed on Zaimasoft.
a) DRDoS
b) DoS
c) PDoS
d) DDoS

Answers:

Question: 01
Answer: a
Question: 02
Answer: d
Question: 03
Answer: d
Question: 04
Answer: c
Question: 05
Answer: b
Question: 06
Answer: c
Question: 07
Answer: a
Question: 08
Answer: b
Question: 09
Answer: b
Question: 10
Answer: c

Note: For any error in EC-Council Certified Incident Handler (ECIH) (212-89) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.8 / 5 (93 votes)