
EC-CouncilCertified Incident Handler
Domain 3Objective 2
Handling and Responding to Network Security Incidents ECIH Practice Questions (Page 5)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
53questions here
11free pages
8concepts
Questions 21–25
- 21
After a network security incident has been resolved, the incident response team conducts a post-incident review. What is the primary goal of this review?
Select an answer first - 22
A security analyst discovers that a malware infection is spreading from one subnet to another through a shared network share. Which immediate containment action is most effective in limiting the spread?
Select an answer first - 23
A hospital's network team is handling three simultaneous incidents: (1) a ransomware outbreak on the administrative network, (2) a suspected malware infection on a single nurse-station computer, and (3) a phishing email reported by one user that has not been clicked. Which incident should be triaged as the highest priority?
Select an answer first - 24
A security analyst discovers that a network switch has been compromised and is forwarding traffic to an unknown destination. The analyst needs to contain the incident while preserving evidence. Which action is MOST appropriate?
Select an answer first - 25
During incident triage, a security analyst discovers a worm that is actively propagating across the internal network, infecting multiple servers that host critical business applications. Which factor should be given the highest priority when determining the urgency of this incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.