
EC-CouncilCertified Incident Handler
Domain 3Objective 2
Handling and Responding to Network Security Incidents ECIH Practice Questions (Page 7)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
53questions here
11free pages
8concepts
Questions 31–35
- 31
During a post-incident review, the team identifies that the incident was not detected quickly because the monitoring tools lacked proper alerting rules. What should be the primary outcome of this finding?
Select an answer first - 32
After a network intrusion, the incident response team has identified a backdoor account created by the attacker. What is the MOST effective eradication step?
Select an answer first - 33
A large organization experiences unusual network behavior: several internal hosts are sending large volumes of traffic to a single external IP on port 443, and the traffic pattern is periodic. The hosts are part of a research department that handles sensitive data. The incident handler must determine whether this is a security incident or legitimate activity. Which approach is most appropriate?
Select an answer first - 34
An organization is responding to a significant network breach. The incident commander needs to communicate status to executive leadership. What is the MOST appropriate communication approach?
Select an answer first - 35
After a network incident has been resolved, the incident response team is conducting a post-mortem. What is the PRIMARY goal of this review?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.