
EC-CouncilCertified Incident Handler
Domain 3Objective 1
Handling and Responding to Email Security Incidents ECIH Practice Questions (Page 7)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
46questions here
10free pages
7concepts
Questions 31–35
- 31
After a malware outbreak via email attachments, the incident response team has contained the affected systems. What is the next step in the eradication phase?
Select an answer first - 32
During the eradication phase of an email security incident, what is the primary goal?
Select an answer first - 33
A ransomware attack encrypted the email server and the backups. The incident response team has restored the server from an offline backup, but some mailboxes are missing emails from the last few days. The team needs to eradicate the ransomware completely and recover the missing emails. What is the most effective approach?
Select an answer first - 34
An email contains a shortened URL. What is the safest method to inspect the destination without exposing the system to potential malware?
Select an answer first - 35
Which field in an email header is most useful for tracing the original IP address of the sender?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.