
EC-CouncilCertified Incident Handler
Domain 3Objective 2
Handling and Responding to Network Security Incidents ECIH Practice Questions (Page 3)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
53questions here
11free pages
8concepts
Questions 11–15
- 11
In incident communication, what is the primary reason for establishing a single point of contact (SPOC) for external parties, such as law enforcement or the media?
Select an answer first - 12
During a network incident, the incident handler collects packet captures, system logs, and memory dumps from affected hosts. The handler is preparing to document the incident. What is the most important documentation practice to follow?
Select an answer first - 13
A manufacturing company detects an internal host communicating with an external C2 server. The host is part of a production line that cannot be taken offline without halting manufacturing. The incident handler needs to contain the threat while preserving the ability to continue production. Which containment strategy is most appropriate?
Select an answer first - 14
After a network breach, the incident response team has eradicated the malware and removed the attacker's access. However, the root cause was an unpatched vulnerability in a third-party application that cannot be patched immediately because it would break a critical business process. What is the BEST eradication approach?
Select an answer first - 15
In incident documentation, what is the primary purpose of recording the chain of custody for evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.