
EC-CouncilCertified Incident Handler
Domain 3Objective 2
Handling and Responding to Network Security Incidents ECIH Practice Questions (Page 10)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
53questions here
11free pages
8concepts
Questions 46–50
- 46
During a network incident, a security analyst identifies a compromised internal server that is communicating with an external C2 server. The analyst needs to contain the incident while preserving evidence for forensic analysis. Which action BEST achieves this?
Select an answer first - 47
A network administrator notices a sudden spike in outbound traffic from a single workstation to an external IP address on port 443, along with the workstation repeatedly attempting to resolve a domain name that is not in the organization's DNS records. Which classification best matches these symptoms?
Select an answer first - 48
During a network security incident, the incident response team needs to inform the organization's management about the incident's impact and the actions being taken. What is the most appropriate way to communicate this information?
Select an answer first - 49
A hospital's network is infected with ransomware that is spreading rapidly. The incident handler must contain the outbreak, but the hospital cannot afford to shut down its entire network because patient care depends on it. Which containment strategy is most appropriate?
Select an answer first - 50
An organization has limited incident response staff. Two incidents occur simultaneously: (1) a suspected data exfiltration from a finance server, and (2) a ransomware infection on a single user's workstation. The finance server is critical but the exfiltration appears slow. The workstation user is a CEO. What should the incident commander prioritize?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.