Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Incident Handler

Domain 5Objective 2

Handling and Responding to Endpoint Security Incidents ECIH Practice Questions (Page 9)

Part of the Insider Threats and Endpoint Incidents domain, which makes up ~20% of our current practice bank.

50questions here
10free pages
6concepts

Questions 41–45

  1. 41application · medium

    After a data breach incident, the incident response team wants to improve future response efforts. Which activity is MOST aligned with the post-incident phase?

    Select an answer first
  2. 42application · medium

    You are collecting evidence from an infected endpoint for a potential legal case. Which of the following practices is ESSENTIAL to maintain the chain of custody?

    Select an answer first
  3. 43foundation · easy

    After an endpoint incident, the incident response team must produce a report for stakeholders. What is the primary purpose of this report?

    Select an answer first
  4. 44expert · hard

    A malware outbreak has infected 50 endpoints, but the organization cannot afford to reimage all of them immediately. The malware is known to be a fileless variant that resides in memory and uses PowerShell scripts. Which eradication strategy is MOST effective given the constraint of limited resources?

    Select an answer first
  5. 45application · medium

    After containing a malware outbreak on several endpoints, you need to eradicate the threat and restore the systems. Which approach is MOST effective for ensuring the malware is completely removed?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.