
EC-CouncilCertified Incident Handler
Domain 2Objective 1
First Response ECIH Practice Questions (Page 1)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
47questions here
10free pages
7concepts
Questions 1–5
- 1
A Windows server in a DMZ is suspected of being compromised. The incident handler needs to preserve evidence while minimizing changes to the system. Which action should be taken FIRST?
Select an answer first - 2
A malware infection is detected on a server that hosts a critical application. The application cannot be offline for more than 30 minutes. The incident handler must contain the infection and preserve evidence. Which strategy best meets these constraints?
Select an answer first - 3
A small company has just experienced a suspected data breach. The CEO wants to immediately notify all customers and the press. The incident handler advises against this. What is the primary reason for delaying external communication?
Select an answer first - 4
Which of the following should be documented during first response actions?
Select an answer first - 5
What is the primary goal of the first response phase in incident handling?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.