Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Incident Handler

Domain 3Objective 1

Handling and Responding to Email Security Incidents ECIH Practice Questions (Page 8)

Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.

46questions here
10free pages
7concepts

Questions 36–40

  1. 36foundation · easy

    After an email security incident has been contained and eradicated, what is the primary objective of the recovery phase?

    Select an answer first
  2. 37application · medium

    A data breach occurred via a phishing email that led to unauthorized access to customer data. The incident response team has completed the containment and eradication phases. What is the next step in the incident handling process?

    Select an answer first
  3. 38foundation · easy

    Which of the following is a common technique used to hide malicious code inside an email attachment?

    Select an answer first
  4. 39foundation · easy

    An email contains an attachment named 'Invoice_2025.exe'. What type of email-based security incident does this indicate?

    Select an answer first
  5. 40application · medium

    A user reports receiving an email that appears to be from a colleague, but the email contains an unusual attachment. You need to verify the authenticity of the email. Which header field should you examine first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.