Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Incident Handler

Domain 2Objective 2

Handling and Responding to Malware Incidents ECIH Practice Questions (Page 6)

Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.

57questions here
12free pages
11concepts

Questions 26–30

  1. 26application · medium

    After a malware incident has been fully contained and eradicated, the incident response team is conducting a post-incident review. Which activity is the PRIMARY focus of this phase?

    Select an answer first
  2. 27foundation · easy

    Which of the following best defines a malware incident in the context of incident response?

    Select an answer first
  3. 28expert · hard

    After a malware infection, the incident response team has identified the malware as a rootkit that hides its files and processes. The team has a clean backup from before the infection, but the backup is 30 days old. The server has been reimaged with the latest OS and applications. What is the MOST reliable way to ensure the rootkit is completely eradicated?

    Select an answer first
  4. 29application · medium

    A user reports that their workstation is running slowly and showing pop-up ads. The security team finds a process named 'svch0st.exe' in the user's profile directory and network connections to a known ad-serving domain. The file has a valid digital signature from a legitimate software vendor. What should the incident handler do FIRST?

    Select an answer first
  5. 30foundation · easy

    Which of the following is an example of a containment action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.