EC-COUNCIL 212-89 Dumps Updated [Oct-2021] Get 100% Real Exam Questions! [Q38-Q58]

Share

[Oct-2021] Pass EC-COUNCIL 212-89 Exam in First Attempt Guaranteed!

Full 212-89 Practice Test and 165 unique questions with explanations waiting just for you, get it now!

NEW QUESTION 38
Agencies do NOT report an information security incident is because of:

  • A. Do not want to pay the additional cost of reporting an incident
  • B. Have full knowledge about how to handle the attack internally
  • C. All the above
  • D. Afraid of negative publicity

Answer: D

 

NEW QUESTION 39
The flow chart gives a view of different roles played by the different personnel of CSIRT. Identify the incident response personnel denoted by A, B, C, D, E, F and G.

  • A. A-Incident Analyst, B- Incident Coordinator, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Manager
  • B. A- Incident Manager, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Coordinator
  • C. A- Incident Coordinator, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Manager
  • D. A- Incident Coordinator, B- Constituency, C-Administrator, D-Incident Manager, E- Human Resource, F-Incident Analyst, G-Public relations

Answer: D

 

NEW QUESTION 40
A methodical series of techniques and procedures for gathering evidence, from computing equipment and various storage devices and digital media, that can be presented in a court of law in a coherent and meaningful format is called:

  • A. Forensic Readiness
  • B. Computer Forensics
  • C. Forensic Analysis
  • D. Steganalysis

Answer: B

 

NEW QUESTION 41
The ability of an agency to continue to function even after a disastrous event, accomplished through the
deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup
and recovery strategy is known as:

  • A. Business Continuity Plan
  • B. Contingency Planning
  • C. Disaster Planning
  • D. Business Continuity

Answer: D

 

NEW QUESTION 42
The state of incident response preparedness that enables an organization to maximize its potential to use
digital evidence while minimizing the cost of an investigation is called:

  • A. Digital Forensic Policy
  • B. Forensic Readiness
  • C. Computer Forensics
  • D. Digital Forensic Analysis

Answer: B

 

NEW QUESTION 43
The left over risk after implementing a control is called:

  • A. Critical risk
  • B. Low risk
  • C. Residual risk
  • D. Unaccepted risk

Answer: C

 

NEW QUESTION 44
Preventing the incident from spreading and limiting the scope of the incident is known as:

  • A. Incident Containment
  • B. Incident Protection
  • C. Incident Eradication
  • D. Incident Classification

Answer: A

 

NEW QUESTION 45
Lack of forensic readiness may result in:

  • A. System downtime
  • B. Data manipulation, deletion, and theft
  • C. All the above
  • D. Loss of clients thereby damaging the organization's reputation

Answer: C

 

NEW QUESTION 46
What command does a Digital Forensic Examiner use to display the list of all IP addresses and their associated MAC addresses on a victim computer to identify the machines that were communicating with it:

  • A. "arp" command
  • B. "ifconfig" command
  • C. "netstat -an" command
  • D. "dd" command

Answer: A

 

NEW QUESTION 47
The program that helps to train people to be better prepared to respond to emergency situations in their communities is known as:

  • A. Security Incident Response Team (SIRT)
  • B. All the above
  • C. Community Emergency Response Team (CERT)
  • D. Incident Response Team (IRT)

Answer: C

 

NEW QUESTION 48
According to US-CERT; if an agency is unable to successfully mitigate a DOS attack it must be reported within:

  • A. Four (4) hours of discovery/detection if the successful attack is still ongoing
  • B. One (1) hour of discovery/detection if the successful attack is still ongoing
  • C. Three (3) hours of discovery/detection if the successful attack is still ongoing
  • D. Two (2) hours of discovery/detection if the successful attack is still ongoing

Answer: D

 

NEW QUESTION 49
US-CERT and Federal civilian agencies use the reporting timeframe criteria in the federal agency reporting
categorization. What is the timeframe required to report an incident under the CAT 4 Federal Agency category?

  • A. Within four (4) hours of discovery/detection if the successful attack is still ongoing and agency is unable to
    successfully mitigate activity
  • B. Monthly
  • C. Weekly
  • D. Within two (2) hours of discovery/detection

Answer: C

 

NEW QUESTION 50
A security policy will take the form of a document or a collection of documents, depending on the situation or usage. It can become a point of reference in case a violation occurs that results in dismissal or other penalty. Which of the following is NOT true for a good security policy?

  • A. It must clearly define the areas of responsibilities of the users, administrators and management
  • B. It must be implemented through system administration procedures, publishing of acceptable use guide lines or other appropriate methods
  • C. It must be approved by court of law after verifications of the stated terms and facts
  • D. It must be enforceable with security tools where appropriate and with sanctions where actual prevention is not technically feasible

Answer: C

 

NEW QUESTION 51
Keyloggers do NOT:

  • A. Secretly records URLs visited in browser, keystrokes, chat conversations, ...etc
  • B. Run in the background
  • C. Alter system files
  • D. Send log file to attacker's email or upload it to an ftp server

Answer: C

 

NEW QUESTION 52
The steps followed to recover computer systems after an incident are:

  • A. System validation, restoration, operation and monitoring
  • B. System restoration, validation, operation and monitoring
  • C. System monitoring, validation, operation and restoration
  • D. System restoration, operation, validation, and monitoring

Answer: B

 

NEW QUESTION 53
Business continuity is defined as the ability of an organization to continue to function even after a disastrous event, accomplished through the deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy. Identify the plan which is mandatory part of a business continuity plan?

  • A. Business Recovery Plan
  • B. Forensics Procedure Plan
  • C. Sales and Marketing plan
  • D. New business strategy plan

Answer: A

 

NEW QUESTION 54
Installing a password cracking tool, downloading pornography material, sending emails to colleagues which
irritates them and hosting unauthorized websites on the company's computer are considered:

  • A. Network based attacks
  • B. Inappropriate usage incidents
  • C. Unauthorized access attacks
  • D. Malware attacks

Answer: B

 

NEW QUESTION 55
The type of relationship between CSIRT and its constituency have an impact on the services provided by the CSIRT. Identify the level of the authority that enables members of CSIRT to undertake any necessary actions on behalf of their constituency?

  • A. Mid-level authority
  • B. Half-level authority
  • C. Full-level authority
  • D. Shared-level authority

Answer: C

 

NEW QUESTION 56
In the Control Analysis stage of the NIST's risk assessment methodology, technical and none technical control
methods are classified into two categories. What are these two control categories?

  • A. Predictive and Detective controls
  • B. Detective and Disguised controls
  • C. Preventive and Detective controls
  • D. Preventive and predictive controls

Answer: C

 

NEW QUESTION 57
A computer forensic investigator must perform a proper investigation to protect digital evidence. During the
investigation, an investigator needs to process large amounts of data using a combination of automated and
manual methods. Identify the computer forensic process involved:

  • A. Examination
  • B. Analysis
  • C. Collection
  • D. Preparation

Answer: A

 

NEW QUESTION 58
......

Prepare for your EC-COUNCIL certification with the updated PassExamDumps 212-89 exam questions: https://drive.google.com/open?id=1I0bTRos2VAs3KEHV6Vsj8iPFJfAA3FqT

Get Latest 212-89 Dumps Exam Questions in here: https://www.passexamdumps.com/212-89-valid-exam-dumps.html