
EC-CouncilCertified Incident Handler
Domain 2Objective 2
Handling and Responding to Malware Incidents ECIH Practice Questions (Page 6)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
57questions here
12free pages
11concepts
Questions 26–30
- 26
After a malware incident has been fully contained and eradicated, the incident response team is conducting a post-incident review. Which activity is the PRIMARY focus of this phase?
Select an answer first - 27
Which of the following best defines a malware incident in the context of incident response?
Select an answer first - 28
After a malware infection, the incident response team has identified the malware as a rootkit that hides its files and processes. The team has a clean backup from before the infection, but the backup is 30 days old. The server has been reimaged with the latest OS and applications. What is the MOST reliable way to ensure the rootkit is completely eradicated?
Select an answer first - 29
A user reports that their workstation is running slowly and showing pop-up ads. The security team finds a process named 'svch0st.exe' in the user's profile directory and network connections to a known ad-serving domain. The file has a valid digital signature from a legitimate software vendor. What should the incident handler do FIRST?
Select an answer first - 30
Which of the following is an example of a containment action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.