
EC-CouncilCertified Ethical Hacker
Domain 1Objective 8
Threat Intelligence and Incident Management CEH Practice Questions (Page 12)
Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
12concepts
Questions 56–60
- 56
A small business has no formal incident management process. After a ransomware attack, the owner realizes that employees did not know who to contact or what steps to take. Which action would best address this gap?
Select an answer first - 57
What is a common post-incident activity?
Select an answer first - 58
A company's SOC receives three incident reports simultaneously: (1) a phishing email that was not clicked, (2) a ransomware infection on a file server that is spreading, and (3) a low-severity policy violation by an employee. According to incident classification and triage, which incident should be handled first?
Select an answer first - 59
How does threat intelligence differ from raw threat data?
Select an answer first - 60
A company is developing an incident management program. The CISO wants to ensure that incidents are detected, contained, and resolved efficiently while minimizing business impact. Which component is most critical to establish first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CEH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.