
EC-CouncilCertified Incident Handler
Domain 3Objective 2
Handling and Responding to Network Security Incidents ECIH Practice Questions (Page 8)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
53questions here
11free pages
8concepts
Questions 36–40
- 36
During a network incident, the incident handler is documenting actions taken. Which information is MOST critical to include in the documentation?
Select an answer first - 37
A security operations center receives two incident reports: one about a phishing email that was quarantined before any user clicked the link, and another about a ransomware infection that has encrypted files on a file server. Which incident should be prioritized for immediate response?
Select an answer first - 38
After containing a malware infection on a server, the incident response team needs to remove the root cause and all malicious artifacts from the system. Which action is part of the eradication phase?
Select an answer first - 39
A financial firm's SOC detects a sudden spike in outbound DNS queries from a single internal host to a known malware-related domain. The host is a non-critical file server used by the finance team. The incident handler must act quickly while minimizing business disruption. What should the handler do first?
Select an answer first - 40
A company is responding to a network incident that has been contained but not yet fully eradicated. The incident handler needs to update the executive team. What should the update include?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.