Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Incident Handler

Domain 3Objective 1

Handling and Responding to Email Security Incidents ECIH Practice Questions (Page 2)

Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.

46questions here
10free pages
7concepts

Questions 6–10

  1. 6application · medium

    A security analyst is reviewing an email that has a suspicious link. The email's headers show that the SPF and DKIM checks failed. What is the most likely classification of this email?

    Select an answer first
  2. 7expert · hard

    A company has experienced a spear-phishing attack that targeted the HR department, resulting in the exposure of employee PII. The incident response team has contained the incident and is preparing the incident report. The company's legal team requires that the report include enough detail to support potential legal action, but the company's public relations team wants to minimize the information disclosed to the public. What is the best approach?

    Select an answer first
  3. 8foundation · easy

    Which of the following should be included in an email security incident report?

    Select an answer first
  4. 9foundation · easy

    Which email authentication standard uses a digital signature to verify the sender's domain and detect spoofing?

    Select an answer first
  5. 10application · medium

    A ransomware attack encrypted email databases and the mail server is now restored from a clean backup. Users are able to log in, but some mailboxes are missing recent emails. What is the most appropriate recovery action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.