
EC-CouncilCertified Incident Handler
Domain 5Objective 1
Handling and Responding to Insider Threats ECIH Practice Questions (Page 7)
Part of the Insider Threats and Endpoint Incidents domain, which makes up ~20% of our current practice bank.
46questions here
10free pages
7concepts
Questions 31–35
- 31
After an insider threat incident, management wants to reduce the risk of similar events. Which combination of controls would be MOST effective?
Select an answer first - 32
Which type of insider threat is characterized by an employee who knowingly violates security policies to steal proprietary data for personal gain?
Select an answer first - 33
Which policy is specifically designed to reduce the risk of insider threats by ensuring that no single individual has unchecked control over critical functions?
Select an answer first - 34
A system administrator accidentally leaves a database backup file on a public file share while troubleshooting. A contractor later copies that file to a personal cloud drive. How should the incident handler classify the contractor's action?
Select an answer first - 35
An incident response team has identified a senior developer as a potential insider threat. The developer has been downloading source code to a personal device. The team needs to contain the threat, but the developer is currently working on a critical project that cannot be interrupted without significant business impact. Which approach best balances containment and business continuity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.