
EC-CouncilCertified Incident Handler
Domain 3Objective 2
Handling and Responding to Network Security Incidents ECIH Practice Questions (Page 6)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
53questions here
11free pages
8concepts
Questions 26–30
- 26
During a network incident, a security team identifies that a specific server is communicating with a known malicious IP address. Which containment action is the most immediate and targeted?
Select an answer first - 27
A company is responding to a network breach that may involve customer data. The incident handler needs to communicate with stakeholders. Which communication approach is most appropriate?
Select an answer first - 28
During the recovery phase of a network incident, the incident response team has restored the affected servers from backups. What is the next critical step to ensure the systems are safe to return to production?
Select an answer first - 29
After a network incident, the incident handler is writing the post-mortem report. What should be included to ensure the report is useful for improving future response?
Select an answer first - 30
An organization has three simultaneous network incidents: (1) a malware infection on a single non-critical workstation, (2) a suspected ransomware encryption on a file server containing critical business data, and (3) a phishing email reported by one user. Which incident should be triaged as the HIGHEST priority?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.