
EC-CouncilCertified Incident Handler
Domain 3Objective 2
Handling and Responding to Network Security Incidents ECIH Practice Questions (Page 2)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
53questions here
11free pages
8concepts
Questions 6–10
- 6
After containing a network breach, the incident response team has identified the root cause as a vulnerable network service that was exploited. What is the MOST appropriate eradication step?
Select an answer first - 7
A security operations center (SOC) analyst sees a network alert indicating a host is beaconing to a known malicious domain. The host is a domain controller that also runs a critical legacy application. The analyst must decide on containment. What is the BEST action?
Select an answer first - 8
A company has just eradicated a malware infection from its network. Before restoring full production traffic, what is the MOST critical recovery step?
Select an answer first - 9
After a network incident has been contained and eradicated, the incident response team must restore the affected systems to normal operation. Which action is part of the recovery phase?
Select an answer first - 10
During a network incident, the incident handler is collecting evidence from multiple systems. What is the BEST practice for documenting the evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.