
EC-CouncilCertified Incident Handler
Domain 4Objective 2
Handling and Responding to Cloud Security Incidents ECIH Practice Questions (Page 5)
Part of the Web Application and Cloud Incidents domain, which makes up ~18% of our current practice bank.
48questions here
10free pages
6concepts
Questions 21–25
- 21
A company uses a SaaS CRM and an IaaS environment. A security incident involves unauthorized access to the CRM data. The incident handler needs to preserve evidence and contain the incident. The company has legal requirements to preserve data for potential litigation. Which action is most appropriate?
Select an answer first - 22
An incident handler needs to acquire forensic evidence from a compromised cloud environment. The environment includes IaaS VMs, a PaaS database, and SaaS email. Which evidence collection approach is most comprehensive?
Select an answer first - 23
An organization wants to detect cloud security incidents early. They have a multi-cloud environment with IaaS and SaaS. Which monitoring strategy is most effective?
Select an answer first - 24
After a cloud security incident has been resolved, the incident handler is conducting a post-incident review. Which activity is most important for improving future incident response?
Select an answer first - 25
A company detects a data breach in a PaaS application. The attacker used a compromised service account to access a database. The incident handler must contain the incident, but the application must remain available for customers. Which action is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.