Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Incident Handler

Domain 2Objective 1

First Response ECIH Practice Questions (Page 7)

Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.

47questions here
10free pages
7concepts

Questions 31–35

  1. 31application · medium

    An incident handler has collected a forensic image of a compromised server. The image is stored on an external hard drive. What is the best practice for maintaining the chain of custody?

    Select an answer first
  2. 32foundation · easy

    During initial response, which of the following is a sign that a system may be compromised?

    Select an answer first
  3. 33expert · hard

    An incident responder is assessing a potential data breach. The breach may involve sensitive customer data, but the extent is unknown. The responder must decide whether to escalate the incident. What is the MOST appropriate action?

    Select an answer first
  4. 34application · medium

    A server in a research lab is infected with ransomware that encrypts files on the local disk and attempts to spread to other servers. The incident handler must contain the threat while preserving evidence for investigation. Which action best meets both goals?

    Select an answer first
  5. 35application · medium

    A network administrator sees a sudden spike in outbound traffic from a workstation at 3:00 AM. The workstation is normally unused at that time. Which action is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.