4.7/5 - (3 votes)

212-89 Exam Study Guide Free Practice Test LAST UPDATED DATE Jul 13, 2023

The New 212-89 2023 Updated Verified Study Guides & Best Courses

The EC-Council Certified Incident Handler (ECIH v2) exam is the certification exam for the ECIH program. 212-89 exam tests the candidate’s knowledge and skills in handling and responding to various types of security incidents. 212-89 exam is designed to test the candidate’s knowledge in areas such as incident handling process, incident response, and recovery, among others. 212-89 exam consists of 100 multiple-choice questions and has a duration of two hours. Candidates must score at least 70% to pass the exam and earn the ECIH certification. The ECIH certification is valid for three years and is globally recognized.

 

NO.112 Johnson is an incident handler and is working on a recent web application attack faced by his organization. As part of this process, he performed data preprocessing in order to analyze and detect the watering hole attack. Johnson preprocessed the outbound network traffic data collected from firewalls and proxy servers. He then started analyzing the user activities within a certain time period to create time ordered domain sequences to perform further analysis on sequential patterns. Identify the data-preprocessing step performed by Johnson.

 
 
 
 

NO.113 Miko was hired as an incident handler in XYZ company. His first task was to identify the PING sweep attempts inside the network. For this purpose, he used Wire shark to analyze the traffic.
What filter did he use to identify ICMP ping sweep attempts?

 
 
 
 

NO.114 Oscar receives an email from an unknown source containing his domain name oscar.com. Upon checking the link, he found that it contains a malicious URL that redirects to the website evil site.org.
What type of vulnerability is this?

 
 
 
 

NO.115 The following steps describe the key activities in forensic readiness planning:
1. Train the staff to handle the incident and preserve the evidence
2. Create a special process for documenting the procedure
3. Identify the potential evidence required for an incident
4. Determine the source of the evidence
5. Establish a legal advisory board to guide the investigation process
6. Identify if the incident requires full or formal investigation
7. Establish a policy for securely handing and storing the collected evidence
8. Define a policy that determines the pathway to legally extract electronic evidence with minimal disruption
Identify the correct sequence of steps involved in forensic readiness planning.

 
 
 
 

NO.116 Incident handling and response steps help you to detect, identify, respond and manage an incident. Which of
the following steps focus on limiting the scope and extent of an incident?

 
 
 
 

NO.117 The service organization that provides 24×7 computer security incident response services to any user, company, government agency, or organization is known as:

 
 
 
 

NO.118 Rossi san incident manager (IM) and his team provides support to all users in the organization that are affected by the threat or attack. David, who is the organizational internal auditor, is also part of the Ross’s incident response team.
Among the following duties, identify one of the responsibilities of David.

 
 
 
 

NO.119 Rica works as an incident handler for an international company. As part of her role, she must review the present security policy implemented. Upon inspection, Rica finds that the policy is wide open, and only known dangerous services/attacks or behaviors are blocked.
Which of the following is the current policy that Rica identified?

 
 
 
 

NO.120 Clark is investigating a cybercrime at TechSoft Solutions. While investigating the case, he needs to collect volatile information such as running services, their process IDs, start mode, state, and status.
Which of the following commands will help Clark to collect such information from running services?

 
 
 
 

NO.121 What command does a Digital Forensic Examiner use to display the list of all open ports and the associated IP addresses on a victim computer to identify the established connections on it:

 
 
 
 

NO.122 Which of the following options describes common characteristics of phishing emails?

 
 
 
 

NO.123 In which of the following phases of the incident handling and response (IH&R) process is the identified security incidents analyzed, validated, categorized, and prioritized?

 
 
 
 

NO.124 Which of the following port scanning techniques involves resetting the TCP connection between client and server abruptly before completion of the three-way handshake signals, making the connection half-open?

 
 
 
 

NO.125 Which of the following incident recovery testing methods works by creating a mock disaster, like fire to identify
the reaction of the procedures that are implemented to handle such situations?

 
 
 
 

NO.126 Michael is an incident handler at CyberTech Solutions. He is performing detection and analysis of a cloud security incident. He is also analyzing the file systems, slack spaces, and metadata within the storage units to find hidden malware and evidence of malice.
Identify the cloud security incident handled by Michael:

 
 
 
 

NO.127 Installing a password cracking tool, downloading pornography material, sending emails to colleagues which
irritates them and hosting unauthorized websites on the company’s computer are considered:

 
 
 
 

NO.128 Smith employs various malware detection techniques to thoroughly examine the network and its systems for suspicious and malicious malware files.
Among all techniques, which one involves analyzing the memory dumps or binary codes for the traces of malware?

 
 
 
 

NO.129 Which of the following may be considered as insider threat(s):

 
 
 
 

NO.130 Which of the following terms may be defined as “a measure of possible inability to achieve a goal, objective, or target within a defined security, cost plan and technical limitations that adversely affects the organization’s operation and revenues?

 
 
 
 

NO.131 A Host is infected by worms that propagates through a vulnerable service; the sign(s) of the presence of the worm include:

 
 
 
 

NO.132 The free, open source, TCP/IP protocol analyzer, sniffer and packet capturing utility standard across many industries and educational institutions is known as:

 
 
 
 

NO.133 An estimation of the expected losses after an incident helps organization in prioritizing and formulating their incident response. The cost of an incident can be categorized as a tangible and intangible cost. Identify the tangible cost associated with virus outbreak?

 
 
 
 

NO.134 The flow chart gives a view of different roles played by the different personnel of CSIRT. Identify the incident response personnel denoted by A, B, C, D, E, F and G.

 
 
 
 

Get Prepared for Your 212-89 Exam With Actual 205 Questions: https://www.braindumpstudy.com/212-89_braindumps.html

         

Related Links: www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw