Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Incident Handler

Domain 4Objective 2

Handling and Responding to Cloud Security Incidents ECIH Practice Questions (Page 1)

Part of the Web Application and Cloud Incidents domain, which makes up ~18% of our current practice bank.

48questions here
10free pages
6concepts

Questions 1–5

  1. 1foundation · easy

    What is the main purpose of conducting a lessons-learned meeting after a cloud security incident?

    Select an answer first
  2. 2expert · hard

    A company uses a SaaS CRM application. The security team discovers that a third-party integration has excessive permissions and may have accessed customer data. The incident handler must contain the incident. Which action is most appropriate?

    Select an answer first
  3. 3application · medium

    After a cloud security incident, the incident handler is conducting a post-incident review. What is the primary goal of this review?

    Select an answer first
  4. 4expert · hard

    After a cloud incident, the incident handler is conducting a post-incident review. The team found that the incident was detected late because monitoring alerts were not configured for a critical service. The company wants to improve detection for future incidents. Which action is most appropriate?

    Select an answer first
  5. 5application · medium

    After a ransomware incident in an IaaS environment, the incident handler has contained the threat and eradicated the malware. The company needs to recover its services. Which step should be taken first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.