
EC-CouncilCertified Incident Handler
Domain 2Objective 2
Handling and Responding to Malware Incidents ECIH Practice Questions (Page 12)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
57questions here
12free pages
11concepts
Questions 56–57
- 56
During a malware incident, the incident response team needs to collect forensic evidence from a compromised server. The server is still running and the malware is active in memory. The team wants to preserve volatile data and also capture the malware for analysis. Which sequence of actions is MOST appropriate?
Select an answer first - 57
A security operations center (SOC) receives an alert from an endpoint detection and response (EDR) tool indicating that a workstation has executed a PowerShell script that downloaded a binary from an external IP address. The binary is unsigned and has never been seen before. Which triage action should the analyst take FIRST?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECIH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.