
[Jan-2024] EC-COUNCIL 212-89 Dumps – Reduce Your Chance of Failure in 212-89 Exam
To help you achieve your ultimate goal, we suggest the actual EC-COUNCIL 212-89 dumps for your EC Council Certified Incident Handler (ECIH v2) exam preparation to use as your guideline.
NEW QUESTION # 74
Michael is a part of the computer incident response team of a company. One of his responsibilities is to handle email incidents. The company receives an email from an unknown source, and one of the steps that he needs to take is to check the validity of the email.
Which of the following tools should he use?
- A. Email Dossier
- B. G Suite Toolbox
- C. Zendio
- D. Yes ware
Answer: A
NEW QUESTION # 75
The state of incident response preparedness that enables an organization to maximize its potential to use digital evidence while minimizing the cost of an investigation is called:
- A. Digital Forensic Analysis
- B. Computer Forensics
- C. Digital Forensic Policy
- D. Forensic Readiness
Answer: D
NEW QUESTION # 76
Based on the some statistics; what is the typical number one top incident?
- A. Un-authorized access
- B. Policy violation
- C. Malware
- D. Phishing
Answer: D
NEW QUESTION # 77
In which of the steps of NIST's risk assessment methodology are the boundary of the IT system, along with the resources and the information that constitute the system identified?
- A. System characterization
- B. Control analysis
- C. Likelihood Determination
- D. Control recommendation
Answer: A
NEW QUESTION # 78
A distributed Denial of Service (DDoS) attack is a more common type of DoS Attack, where a single system is targeted by a large number of infected machines over the Internet. In a DDoS attack, attackers first infect multiple systems which are known as:
- A. Worms
- B. Spyware
- C. Trojans
- D. Zombies
Answer: D
NEW QUESTION # 79
Which of the following can be considered synonymous:
- A. Precaution and countermeasure
- B. Vulnerability and Danger
- C. Threat and Threat Agent
- D. Hazard and Threat
Answer: D
NEW QUESTION # 80
Which is the incorrect statement about Anti-keyloggers scanners:
- A. Software tools
- B. Detect already installed Keyloggers in victim machines
- C. Run in stealthy mode to record victims online activity
Answer: C
NEW QUESTION # 81
The most common type(s) of intellectual property is(are):
- A. All the above
- B. Copyrights and Trademarks
- C. Patents
- D. Industrial design rights & Trade secrets
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION # 82
Which one of the following is Inappropriate Usage Incidents?
- A. Denial of Service Attack
- B. Insider Threat
- C. Access Control Attack
- D. Reconnaissance Attack
Answer: B
NEW QUESTION # 83
Which of the following processes is referred to as an approach to respond to the security incidents that occur in an organization and enables the response team by ensuring that they know exactly what process to follow in case of security incidents?
- A. Risk assessment
- B. Vulnerability management
- C. Threat assessment
- D. Incident response orchestration
Answer: D
NEW QUESTION # 84
In which of the following stages of the incident handling and response (IH&R) process do the incident handlers try to find the root cause of the incident along with the threat actors behind the incidents, threat vectors, etc.?
- A. Incident triage
- B. Incident recording and assignment
- C. Post-incident activities
- D. Evidence gathering and forensics analysis
Answer: D
NEW QUESTION # 85
If a hacker cannot find any other way to attack an organization, they can influence an employee or a disgruntled staff member.
What type of threat is this?
- A. Insider attack
- B. Phishing attack
- C. Identity the t
- D. Footprinting
Answer: A
NEW QUESTION # 86
Attackers or insiders create a backdoor into a trusted network by installing an unsecured access point inside a firewall. They then use any software or hardware access point to perform an attack.
Which of the following is this type of attack?
- A. Rogue access point attack
- B. Password-based attack
- C. Email infection
- D. Malware attack
Answer: A
NEW QUESTION # 87
An incident is analyzed for its nature, intensity and its effects on the network and systems. Which stage of the incident response and handling process involves auditing the system and network log files?
- A. Reporting
- B. Incident recording
- C. Containment
- D. Identification
Answer: D
NEW QUESTION # 88
Rica works as an incident handler for an international company. As part of her role, she must review the present security policy implemented. Upon inspection, Rica finds that the policy is wide open, and only known dangerous services/attacks or behaviors are blocked.
Which of the following is the current policy that Rica identified?
- A. Permissive policy
- B. Prudent policy
- C. Promiscuous policy
- D. Paranoid policy
Answer: A
NEW QUESTION # 89
Which of the following incident recovery testing methods works by creating a mock disaster, like fire to identify
the reaction of the procedures that are implemented to handle such situations?
- A. Procedure testing
- B. Facility testing
- C. Scenario testing
- D. Live walk-through testing
Answer: A
NEW QUESTION # 90
You are talking to a colleague who is deciding what information they should include in their organization's logs to help with security auditing.
Which of the following items should you tell them to NOT log?
- A. Timestamp
- B. userid
- C. Source IP address
- D. Session ID
Answer: D
NEW QUESTION # 91
The product of intellect that has commercial value and includes copyrights and trademarks is called:
- A. Logos
- B. Patents
- C. Intellectual property
- D. Trade secrets
Answer: C
NEW QUESTION # 92
Which of the following is NOT a digital forensic analysis tool:
- A. EAR/ Pilar
- B. Guidance Software EnCase Forensic
- C. Access Data FTK
- D. Helix
Answer: A
NEW QUESTION # 93
Oscar receives an email from an unknown source containing his domain name oscar.com. Upon checking the link, he found that it contains a malicious URL that redirects to the website evil site.org.
What type of vulnerability is this?
- A. SQL injection
- B. Unvalidated redirects and forwards
- C. Malware
- D. Botnet
Answer: B
NEW QUESTION # 94
Which of the following has been used to evade IDS and IPS?
- A. HTTP
- B. TNP
- C. Fragmentation
- D. SNMP
Answer: C
NEW QUESTION # 95
Otis is an incident handler working in an organization called Delmont. Recently, the organization faced several setbacks in business, whereby its revenues are decreasing. Otis was asked to take charge and look into the matter. While auditing the enterprise security, he found traces of an attack through which proprietary information was stolen from the enterprise network and passed on to their competitors.
Which of the following information se cunty incidents did Delmont face?
- A. Unauthorized access
- B. Email-based abuse
- C. Network and resource abuses
- D. Espionage
Answer: D
NEW QUESTION # 96
......
100% Free 212-89 Demo-Trial [Pdf], get it now: https://drive.google.com/open?id=1e1MWJeTnyBuNo8oMudCb3Nu4mrARREQQ
Accurate & Verified Answers As Seen in the Real Exam here: https://www.passexamdumps.com/212-89-valid-exam-dumps.html
