
EC-CouncilCertified Incident Handler
Domain 2Objective 1
First Response ECIH Practice Questions (Page 3)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
47questions here
10free pages
7concepts
Questions 11–15
- 11
An incident responder is triaging multiple alerts. A critical server is showing signs of a ransomware infection, while a low-priority workstation has a minor malware infection. The responder has limited resources. What should be prioritized?
Select an answer first - 12
An incident handler has confirmed a data breach involving customer credit card numbers. According to the organization's incident response plan, which party should be notified FIRST?
Select an answer first - 13
What is the primary purpose of escalation in incident response?
Select an answer first - 14
An incident responder needs to collect evidence from a compromised Linux server. The server is still running. Which of the following should be collected FIRST?
Select an answer first - 15
A security analyst detects a possible malware infection on a single employee's laptop. The analyst has not yet confirmed the infection. According to best practices, what should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.