
EC-CouncilCertified Incident Handler
Domain 2Objective 1
First Response ECIH Practice Questions (Page 2)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
47questions here
10free pages
7concepts
Questions 6–10
- 6
A malware infection is detected on a server that also hosts a critical application. The application cannot be stopped without significant business impact. The incident responder must contain the malware. What is the BEST approach?
Select an answer first - 7
Which of the following is a common indicator of a security incident that might be noticed during initial response?
Select an answer first - 8
During initial triage, an incident responder finds that a single workstation is infected with a known malware variant, while a server on the same subnet is also showing suspicious outbound connections. What should the responder do FIRST?
Select an answer first - 9
What is the immediate goal of system isolation during a malware incident?
Select an answer first - 10
During an incident, the incident handler discovers that a malware infection has affected 5 out of 200 workstations. The infected workstations are in the finance department. What should the incident handler do FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.