
EC-CouncilCertified Incident Handler
Domain 2Objective 1
First Response ECIH Practice Questions (Page 9)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
47questions here
10free pages
7concepts
Questions 41–45
- 41
An incident responder is documenting their actions during an incident. Which of the following should be included in the documentation?
Select an answer first - 42
An incident responder has confirmed a malware infection on a user's computer. The user is a senior executive. According to the incident response plan, what should the responder do?
Select an answer first - 43
A company's incident response plan states that first responders should focus on 'preservation of evidence' and 'containment'. An employee reports a possible virus on their computer. What is the FIRST action the first responder should take?
Select an answer first - 44
What is the recommended method for preserving non-volatile evidence from a compromised system?
Select an answer first - 45
A system administrator notices that a database server's CPU usage is consistently high and that multiple failed login attempts have been logged from an unfamiliar IP address. Which indicator most strongly suggests a security incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.