
EC-CouncilCertified Incident Handler
Domain 3Objective 1
Handling and Responding to Email Security Incidents ECIH Practice Questions (Page 3)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
46questions here
10free pages
7concepts
Questions 11–15
- 11
Your organization suffered a phishing attack that led to a data breach. You have completed containment and eradication. What should you include in the incident report to satisfy regulatory requirements?
Select an answer first - 12
After a malware outbreak via email attachments, you have contained the affected systems and identified the malicious emails in user mailboxes. What is the next step in the eradication phase?
Select an answer first - 13
A worm is spreading through email by sending itself to contacts in the address book. The incident response team needs to contain the outbreak. Which action is most effective?
Select an answer first - 14
A phishing email with a malicious link was sent to 200 employees. 15 clicked the link, and 3 entered credentials. The email gateway has already quarantined the original email, but the 15 affected workstations may have downloaded a payload. You must contain the incident while minimizing business disruption. Which action best balances containment and operational continuity?
Select an answer first - 15
During email triage, an incident handler receives a message that appears to come from the CEO, but the sender's display name is slightly altered and the domain is a lookalike. Which classification best describes this email-based security incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.