
EC-CouncilCertified Incident Handler
Domain 3Objective 2
Handling and Responding to Network Security Incidents ECIH Practice Questions (Page 11)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
53questions here
11free pages
8concepts
Questions 51–53
- 51
During an incident response, a security analyst takes notes about the actions performed, the time each action was taken, and the evidence collected. Why is this documentation important?
Select an answer first - 52
A company has fully eradicated a network worm from its environment. The affected servers have been cleaned and patched. What is the next step in the recovery process?
Select an answer first - 53
A SOC analyst is triaging three alerts: (1) a single workstation with a known malware signature, (2) a domain controller with failed login attempts, and (3) a web server with a high volume of 404 errors. Which alert should be prioritized as the most urgent?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECIH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.