Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Incident Handler

Domain 5Objective 2

Handling and Responding to Endpoint Security Incidents ECIH Practice Questions (Page 5)

Part of the Insider Threats and Endpoint Incidents domain, which makes up ~20% of our current practice bank.

50questions here
10free pages
6concepts

Questions 21–25

  1. 21application · medium

    A user reports that their workstation suddenly became unresponsive, and the screen shows a ransomware note demanding payment. The endpoint protection agent has been disabled, and the system is still connected to the corporate network. As the incident handler, what is the FIRST action you should take to prevent further spread?

    Select an answer first
  2. 22application · easy

    A user reports that their computer is running slowly and the hard drive is almost full. The IT team finds thousands of files with random names in the user's profile folder. The files appear to be encrypted. What is the most likely classification of this endpoint incident?

    Select an answer first
  3. 23application · medium

    A user reports that their Windows workstation is sluggish and shows high CPU usage from a process named 'svchost.exe' running from a temp folder. The security team checks the endpoint and finds a scheduled task that downloads and executes a script from a remote IP. The process has made outbound connections to that IP. What should the incident handler do FIRST to contain the threat while preserving evidence?

    Select an answer first
  4. 24foundation · easy

    During endpoint evidence collection, the responder must preserve volatile data. Which type of data is considered volatile and should be collected first?

    Select an answer first
  5. 25application · medium

    An endpoint is suspected of being compromised because it is running unusual processes and making outbound connections to a foreign IP address. Which of the following is the MOST reliable indicator of compromise (IOC) to confirm the incident?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.