
EC-CouncilCertified Incident Handler
Domain 5Objective 1
Handling and Responding to Insider Threats ECIH Practice Questions (Page 6)
Part of the Insider Threats and Endpoint Incidents domain, which makes up ~20% of our current practice bank.
46questions here
10free pages
7concepts
Questions 26–30
- 26
During an insider threat investigation, the incident handler needs to collect a laptop's hard drive as evidence. What is the MOST important action to preserve the evidence's admissibility?
Select an answer first - 27
An incident handler is managing an insider threat case that involves a high-ranking executive. The executive's activities are under investigation, and the handler must report to the board. What is the BEST way to communicate the status?
Select an answer first - 28
An incident handler discovers that an employee has been selling customer data to a competitor. The handler has collected evidence and the legal team is involved. What is the MOST appropriate next step in communication?
Select an answer first - 29
An organization wants to detect insider threats that involve employees accessing sensitive data outside of their normal working hours. The security team has access to authentication logs, file access logs, and a user behavior analytics (UBA) platform. Which approach would best identify this behavior while minimizing false positives?
Select an answer first - 30
A company wants to implement a comprehensive insider threat detection program. Which of the following techniques should be included? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.