
EC-CouncilCertified Incident Handler
Domain 4Objective 2
Handling and Responding to Cloud Security Incidents ECIH Practice Questions (Page 6)
Part of the Web Application and Cloud Incidents domain, which makes up ~18% of our current practice bank.
48questions here
10free pages
6concepts
Questions 26–30
- 26
After a cloud incident, the incident handler is planning recovery. The organization has a multi-cloud environment. What is the most important factor to consider during recovery?
Select an answer first - 27
A company detects a compromised IaaS instance that is part of a production application. The instance is communicating with a known command-and-control server. The incident handler needs to contain the threat while minimizing downtime. Which action best achieves this?
Select an answer first - 28
Why is it important to preserve cloud logs (e.g., API logs, flow logs) as part of forensic evidence?
Select an answer first - 29
After a cloud security incident has been contained and eradicated, what is the first step in the recovery phase?
Select an answer first - 30
Which of the following is the most appropriate method to acquire forensic evidence from a cloud-based virtual machine?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.