
EC-CouncilCertified Incident Handler
Domain 5Objective 1
Handling and Responding to Insider Threats ECIH Practice Questions (Page 5)
Part of the Insider Threats and Endpoint Incidents domain, which makes up ~20% of our current practice bank.
46questions here
10free pages
7concepts
Questions 21–25
- 21
What is the purpose of maintaining a chain of custody during an insider threat investigation?
Select an answer first - 22
An insider threat investigation has confirmed that a senior engineer exfiltrated proprietary source code. The legal department has asked the incident response team to prepare a report for potential criminal prosecution. What is the most important requirement for this report?
Select an answer first - 23
During an insider threat investigation, the incident response team discovers that the suspect has been using a company-issued smartphone to photograph confidential documents. The team needs to collect the smartphone as evidence, but the suspect is a senior executive who claims the phone contains personal data and refuses to hand it over. Which action should the team take?
Select an answer first - 24
After a terminated employee's credentials were used to access the corporate VPN and download sensitive files, the security team discovers the account was not disabled until the next morning. Which preventive control would have most effectively reduced the risk of this incident?
Select an answer first - 25
During an insider threat investigation, the incident handler must collect evidence from a cloud-based email system. The organization uses Office 365. What is the BEST way to preserve the evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.