
EC-CouncilCertified Incident Handler
Domain 2Objective 1
First Response ECIH Practice Questions (Page 6)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
47questions here
10free pages
7concepts
Questions 26–30
- 26
During first response, an incident handler collects a forensic image of a compromised laptop. The handler records the date, time, and hash values of the image in a log. What additional step is essential to maintain the chain of custody?
Select an answer first - 27
A malware outbreak is spreading rapidly across a company's network. The incident handler must contain the outbreak, but the CEO insists on keeping the email server online because it is critical to business operations. The email server is suspected to be infected. What is the best containment strategy?
Select an answer first - 28
An incident responder is collecting evidence from a compromised system. They have taken a memory dump and are about to image the hard drive. What should they do BEFORE imaging the drive?
Select an answer first - 29
A forensic analyst is called to a scene where a computer is still running and the screen shows an active chat session with an attacker. The analyst must preserve evidence. Which action is most appropriate?
Select an answer first - 30
During an incident, the incident response team discovers that the breach involves personally identifiable information (PII) of customers. According to the incident response plan, which stakeholders should be informed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.