
EC-CouncilCertified Incident Handler
Domain 5Objective 2
Handling and Responding to Endpoint Security Incidents ECIH Practice Questions (Page 4)
Part of the Insider Threats and Endpoint Incidents domain, which makes up ~20% of our current practice bank.
50questions here
10free pages
6concepts
Questions 16–20
- 16
During the post-incident review, the team identifies that the incident was caused by a delayed patch deployment. What is the MOST effective way to implement the lesson learned?
Select an answer first - 17
An incident handler is documenting a data breach that involved multiple endpoints. The legal team requires a report that can be used in court. The report must include a timeline of events, evidence collected, and actions taken. What is the MOST important consideration when writing the report?
Select an answer first - 18
An incident responder needs to collect evidence from an endpoint in a forensically sound manner. Which action is most important to preserve the integrity of the evidence?
Select an answer first - 19
You are responding to an insider threat incident on a laptop. You must collect evidence while the laptop is still running. Which of the following actions are appropriate for preserving volatile evidence? (Select all that apply.)
Select an answer first - 20
An incident handler is collecting evidence from a compromised endpoint that is part of a legal investigation. The handler must ensure the evidence is preserved and admissible. Which of the following actions are appropriate? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.