
EC-CouncilCertified Incident Handler
Domain 5Objective 2
Handling and Responding to Endpoint Security Incidents ECIH Practice Questions (Page 9)
Part of the Insider Threats and Endpoint Incidents domain, which makes up ~20% of our current practice bank.
50questions here
10free pages
6concepts
Questions 41–45
- 41
After a data breach incident, the incident response team wants to improve future response efforts. Which activity is MOST aligned with the post-incident phase?
Select an answer first - 42
You are collecting evidence from an infected endpoint for a potential legal case. Which of the following practices is ESSENTIAL to maintain the chain of custody?
Select an answer first - 43
After an endpoint incident, the incident response team must produce a report for stakeholders. What is the primary purpose of this report?
Select an answer first - 44
A malware outbreak has infected 50 endpoints, but the organization cannot afford to reimage all of them immediately. The malware is known to be a fileless variant that resides in memory and uses PowerShell scripts. Which eradication strategy is MOST effective given the constraint of limited resources?
Select an answer first - 45
After containing a malware outbreak on several endpoints, you need to eradicate the threat and restore the systems. Which approach is MOST effective for ensuring the malware is completely removed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.