Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Incident Handler

Domain 2Objective 1

First Response ECIH Practice Questions (Page 2)

Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.

47questions here
10free pages
7concepts

Questions 6–10

  1. 6expert · hard

    A malware infection is detected on a server that also hosts a critical application. The application cannot be stopped without significant business impact. The incident responder must contain the malware. What is the BEST approach?

    Select an answer first
  2. 7foundation · easy

    Which of the following is a common indicator of a security incident that might be noticed during initial response?

    Select an answer first
  3. 8application · medium

    During initial triage, an incident responder finds that a single workstation is infected with a known malware variant, while a server on the same subnet is also showing suspicious outbound connections. What should the responder do FIRST?

    Select an answer first
  4. 9foundation · easy

    What is the immediate goal of system isolation during a malware incident?

    Select an answer first
  5. 10application · medium

    During an incident, the incident handler discovers that a malware infection has affected 5 out of 200 workstations. The infected workstations are in the finance department. What should the incident handler do FIRST?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.