
EC-CouncilCertified Incident Handler
Domain 2Objective 2
Handling and Responding to Malware Incidents ECIH Practice Questions (Page 2)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
57questions here
12free pages
11concepts
Questions 6–10
- 6
Which of the following is a common characteristic of a malware incident that distinguishes it from other types of security incidents?
Select an answer first - 7
An employee inserts a USB flash drive found in the parking lot into their workstation, and malware infects the system. Which infection vector is this?
Select an answer first - 8
A security analyst notices that a server is sending large amounts of data to an external IP address. The server is also running a process that hides its presence from the task manager. The analyst suspects spyware. Which behavior is MOST characteristic of spyware?
Select an answer first - 9
During initial triage of a malware alert, which action is most appropriate to prioritize the response?
Select an answer first - 10
Which type of malware is characterized by self-replication and the ability to spread across networks without requiring user interaction?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.