Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Incident Handler

Domain 2Objective 1

First Response ECIH Practice Questions (Page 9)

Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.

47questions here
10free pages
7concepts

Questions 41–45

  1. 41application · medium

    An incident responder is documenting their actions during an incident. Which of the following should be included in the documentation?

    Select an answer first
  2. 42application · medium

    An incident responder has confirmed a malware infection on a user's computer. The user is a senior executive. According to the incident response plan, what should the responder do?

    Select an answer first
  3. 43application · medium

    A company's incident response plan states that first responders should focus on 'preservation of evidence' and 'containment'. An employee reports a possible virus on their computer. What is the FIRST action the first responder should take?

    Select an answer first
  4. 44foundation · easy

    What is the recommended method for preserving non-volatile evidence from a compromised system?

    Select an answer first
  5. 45application · medium

    A system administrator notices that a database server's CPU usage is consistently high and that multiple failed login attempts have been logged from an unfamiliar IP address. Which indicator most strongly suggests a security incident?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.