
EC-CouncilCertified Incident Handler
Domain 2Objective 2
Handling and Responding to Malware Incidents ECIH Practice Questions (Page 8)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
57questions here
12free pages
11concepts
Questions 36–40
- 36
A security analyst detects a trojan on a critical database server that is actively communicating with an external command-and-control server. The server cannot be taken offline because it supports a 24/7 customer-facing application. The trojan has not yet spread to other systems. Which containment strategy BEST balances risk and business continuity?
Select an answer first - 37
A malware analyst is examining a suspicious file that is packed with an unknown packer. Static analysis reveals nothing useful. The analyst decides to perform dynamic analysis in a sandbox. Which observation would MOST strongly indicate that the malware is using anti-sandbox techniques?
Select an answer first - 38
A malware analyst needs to preserve evidence from an infected laptop for potential legal action. The laptop is currently powered on and the malware process is running. Which step should be taken FIRST to ensure the evidence is legally sound?
Select an answer first - 39
After removing malware from a server, which action is most important before returning the server to production?
Select an answer first - 40
After containing a ransomware outbreak, the incident response team has identified the initial entry point as an unpatched vulnerability in a legacy web application. The team has removed the ransomware from all affected servers. What is the NEXT step in the eradication phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.