
EC-CouncilCertified Incident Handler
Domain 2Objective 1
First Response ECIH Practice Questions (Page 8)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
47questions here
10free pages
7concepts
Questions 36–40
- 36
According to organizational procedures, what should be communicated during an incident escalation?
Select an answer first - 37
An incident responder is collecting evidence from a compromised server. They need to ensure the evidence is admissible in court. What is the MOST important action to take?
Select an answer first - 38
A network administrator notices a large amount of outbound traffic from a single workstation at 3:00 AM. The workstation is not typically used at that time. What should the administrator do FIRST?
Select an answer first - 39
A system administrator notices that a server's event logs show multiple failed login attempts followed by a successful login from an unusual IP address. What should the administrator do FIRST?
Select an answer first - 40
Which action is an example of immediate containment during a malware incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.