
EC-CouncilCertified Incident Handler
Domain 2Objective 1
First Response ECIH Practice Questions (Page 5)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
47questions here
10free pages
7concepts
Questions 21–25
- 21
Why is the first response phase considered critical in the incident handling process?
Select an answer first - 22
A company has a formal incident response plan. An incident is detected by the help desk. What is the FIRST step in the first response process?
Select an answer first - 23
A critical database server is showing signs of active malware activity, but it is also serving live customer transactions. The incident responder must balance containment with business continuity. Which action is MOST appropriate?
Select an answer first - 24
A user reports that their computer is running slowly and the antivirus has been disabled. The incident responder checks the system and finds multiple unknown processes running. What is the MOST appropriate next step?
Select an answer first - 25
An incident handler is responding to a suspected malware infection on a critical production server that cannot be taken offline for more than 10 minutes. The handler must preserve evidence while minimizing downtime. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.