
EC-CouncilCertified Incident Handler
Domain 5Objective 2
Handling and Responding to Endpoint Security Incidents ECIH Practice Questions (Page 3)
Part of the Insider Threats and Endpoint Incidents domain, which makes up ~20% of our current practice bank.
50questions here
10free pages
6concepts
Questions 11–15
- 11
An incident responder is documenting an endpoint security incident. Which information is essential to include in the incident report for legal purposes?
Select an answer first - 12
A malware infection has been contained on a critical database server. The malware is a rootkit that has modified kernel modules. The server is running a legacy application that is difficult to reinstall. The incident handler must eradicate the malware while minimizing downtime. What is the BEST approach?
Select an answer first - 13
An endpoint has been identified as communicating with a known malicious IP address. The system is a critical file server that cannot be taken offline during business hours. Which containment strategy balances the need to stop the communication while maintaining availability?
Select an answer first - 14
After containing an endpoint incident, the response team must remove all malicious artifacts from the affected system. Which activity is part of the eradication phase?
Select an answer first - 15
During routine monitoring, a security analyst notices that a user's workstation has been sending large volumes of data to an external IP address at 3:00 AM. The workstation also has a new scheduled task that runs a PowerShell script. Which classification best describes this endpoint security incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.