
EC-CouncilCertified Incident Handler
Domain 2Objective 2
Handling and Responding to Malware Incidents ECIH Practice Questions (Page 7)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
57questions here
12free pages
11concepts
Questions 31–35
- 31
Which of the following is an example of a remediation action during the eradication phase?
Select an answer first - 32
A security operations center receives an alert about a workstation that is making repeated connections to a known malicious IP address. The workstation is also running a process that is not in the company's approved software list. Which triage action should the analyst take FIRST?
Select an answer first - 33
What is the main purpose of a post-incident review (lessons learned) after a malware incident?
Select an answer first - 34
After removing ransomware from a file server, the incident handler wants to ensure the malware does not reappear. The initial infection occurred through an unpatched vulnerability in the server's web management interface. Which action is MOST critical during the eradication phase?
Select an answer first - 35
What is the primary purpose of dynamic malware analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.