
EC-CouncilCertified Incident Handler
Domain 3Objective 2
Handling and Responding to Network Security Incidents ECIH Practice Questions (Page 9)
Part of the Email and Network Security Incidents domain, which makes up ~21% of our current practice bank.
53questions here
11free pages
8concepts
Questions 41–45
- 41
A company has just contained and eradicated a network worm. The recovery plan must restore services while minimizing the risk of reinfection. Which recovery strategy is MOST appropriate?
Select an answer first - 42
A company has contained a network intrusion and identified the root cause as a compromised service account that was used to install a backdoor. The service account is used by a critical business application that cannot be taken offline. The incident handler must eradicate the threat without disrupting the application. What is the best approach?
Select an answer first - 43
A company has a limited incident response team and is facing two incidents: (1) a ransomware infection on a file server that is not yet fully encrypted, and (2) a suspected data exfiltration from a database containing customer records. The ransomware is spreading slowly, while the data exfiltration appears to be ongoing. Which incident should be prioritized?
Select an answer first - 44
During the eradication phase of a network incident, the incident response team identifies that a backdoor was installed on multiple systems. What is the most thorough eradication action for these systems?
Select an answer first - 45
After a network incident, the incident response team is conducting a post-mortem. Which activity is MOST important to include?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.