
EC-CouncilCertified Incident Handler
Domain 5Objective 1
Handling and Responding to Insider Threats ECIH Practice Questions (Page 3)
Part of the Insider Threats and Endpoint Incidents domain, which makes up ~20% of our current practice bank.
46questions here
10free pages
7concepts
Questions 11–15
- 11
What is the primary reason for reporting insider threat incidents to law enforcement?
Select an answer first - 12
A user's workstation is infected with malware that is sending internal documents to an external server. The user had no knowledge of the malware and did not intentionally exfiltrate data. How should the incident response team classify this insider?
Select an answer first - 13
A company has a high rate of false positives in its insider threat detection system, causing alert fatigue. The security team wants to reduce false positives without missing real threats. Which approach is MOST effective?
Select an answer first - 14
Which detection technique is specifically designed to identify unusual patterns of user behavior that may indicate an insider threat?
Select an answer first - 15
In the eradication phase of insider threat response, which action is typically performed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.