
EC-CouncilCertified Incident Handler
Domain 2Objective 1
First Response ECIH Practice Questions (Page 4)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
47questions here
10free pages
7concepts
Questions 16–20
- 16
Which of the following is considered volatile evidence that should be collected first during incident response?
Select an answer first - 17
A helpdesk ticket reports that three users received phishing emails with a malicious attachment. One user clicked the attachment, and the other two did not. The malware is known to spread via network shares. What should the incident handler do FIRST?
Select an answer first - 18
What is the purpose of triage during initial incident assessment?
Select an answer first - 19
Which factor is most important when determining the severity of an incident during initial assessment?
Select an answer first - 20
During triage, an incident handler finds that a compromised workstation has been used to access a file share containing sensitive customer data. The handler must decide whether to escalate the incident. Which factor is most important in determining the severity and escalation priority?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.