
EC-CouncilCertified Incident Handler
Domain 3Objective 1
Handling and Responding to Email Security Incidents ECIH Practice Questions (Page 5)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
46questions here
10free pages
7concepts
Questions 21–25
- 21
After eradicating a malware email campaign, you need to restore email services. Some users report that their mailboxes are missing emails that were quarantined during the incident. What is the most appropriate recovery action?
Select an answer first - 22
An analyst is investigating an email that claims to be from a bank. The email's headers show that the 'Received' field lists an IP address that is not associated with the bank's domain. What does this indicate?
Select an answer first - 23
After identifying a phishing email that has been opened by several users, what is the immediate containment step to prevent further spread?
Select an answer first - 24
Which activity is typically performed during the recovery phase of an email security incident?
Select an answer first - 25
A spear-phishing email with a malicious link was sent to the finance team. One user clicked the link and entered their credentials on a fake login page. The user's account has administrative privileges to the financial system. You need to contain the incident. Which action should you take FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.