
EC-CouncilCertified Incident Handler
Domain 3Objective 1
Handling and Responding to Email Security Incidents ECIH Practice Questions (Page 1)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
46questions here
10free pages
7concepts
Questions 1–5
- 1
Which containment strategy is most appropriate when a malware attachment has been opened on a user's workstation?
Select an answer first - 2
You receive an email that passes SPF and DKIM checks, but the DMARC policy is 'none'. The email contains a link to a website that asks for a password. The sender domain is similar to your company's domain but with a typo (e.g., 'company.com' vs 'cornpany.com'). How should you classify this email?
Select an answer first - 3
A user reports receiving an email that appears to be from the company CEO, requesting an urgent wire transfer. The email's Reply-To address is an external domain, and the display name is spoofed. You need to determine if the email is genuinely from the CEO. Which action provides the most reliable evidence?
Select an answer first - 4
An employee receives an email with a PDF attachment that, when opened, triggers a PowerShell script that downloads additional malware. The malware has already executed on the employee's workstation. What is the immediate containment step?
Select an answer first - 5
After a phishing campaign, you have identified that a malicious attachment was delivered to 50 users. You have already blocked the attachment hash at the gateway. What is the next eradication step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.