
EC-CouncilCertified Incident Handler
Domain 5Objective 1
Handling and Responding to Insider Threats ECIH Practice Questions (Page 4)
Part of the Insider Threats and Endpoint Incidents domain, which makes up ~20% of our current practice bank.
46questions here
10free pages
7concepts
Questions 16–20
- 16
Which control is most effective in reducing the risk of insider threats by limiting the amount of data an employee can access?
Select an answer first - 17
A security team is reviewing indicators of insider threats. Which combination of indicators would MOST strongly suggest a malicious insider?
Select an answer first - 18
During the containment phase of an insider threat incident, the incident handler must prevent further data exfiltration while preserving the ability to investigate. Which action BEST achieves this?
Select an answer first - 19
A company wants to detect employees who are about to leave and might exfiltrate sensitive data. They already have DLP on email and web. Which additional control would BEST detect unusual data access patterns before departure?
Select an answer first - 20
Following an insider threat incident where an employee with access to financial systems sold confidential data, the organization wants to implement controls to reduce the risk of similar incidents. Which control is most directly aimed at limiting the damage a single insider can cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.