
EC-CouncilCertified Incident Handler
Domain 3Objective 2
Handling and Responding to Network Security Incidents ECIH Practice Questions (Page 1)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
53questions here
11free pages
8concepts
Questions 1–5
- 1
After a network intrusion, the incident handler has contained the affected systems and collected forensic evidence. The handler has identified the root cause as a vulnerable web application that was exploited. What should the handler do to eradicate the root cause?
Select an answer first - 2
During a network incident, the incident handler uses a tool to capture network traffic and saves the capture file. What documentation step is essential to ensure the evidence is admissible in court?
Select an answer first - 3
A network monitoring system alerts on multiple failed SSH login attempts from a single external IP address to several internal servers. The attempts are increasing in frequency. What is the MOST appropriate immediate response?
Select an answer first - 4
An incident response team is handling a network breach. The team lead needs to update the IT department and the executive team. What is the BEST way to handle these communications?
Select an answer first - 5
After containing a network intrusion, the incident handler has identified a backdoor user account and a scheduled task that re-establishes the backdoor. The handler has already isolated the affected server. What should the handler do next to eradicate the threat?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.