Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Incident Handler

Domain 5Objective 1

Handling and Responding to Insider Threats ECIH Practice Questions (Page 1)

Part of the Insider Threats and Endpoint Incidents domain, which makes up ~20% of our current practice bank.

46questions here
10free pages
7concepts

Questions 1–5

  1. 1foundation · easy

    What is the primary goal of the containment phase in an insider threat response plan?

    Select an answer first
  2. 2foundation · easy

    An employee who accidentally clicks a phishing link and unknowingly provides their credentials to an attacker is best classified as which type of insider?

    Select an answer first
  3. 3application · medium

    During an insider threat investigation, the incident response team needs to collect the suspect's laptop as evidence. The laptop is currently powered on and the user is logged in. Which step should the team take to preserve digital evidence in a defensible manner?

    Select an answer first
  4. 4application · medium

    A company has experienced a data breach caused by a negligent employee who fell for a phishing email. To prevent similar incidents, which control would be MOST effective?

    Select an answer first
  5. 5foundation · easy

    Who should be notified first when an insider threat incident is suspected?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.