Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Incident Handler

Domain 4Objective 1

Handling and Responding to Web Application Security Incidents ECIH Practice Questions (Page 1)

Part of the Web Application and Cloud Incidents domain, which makes up ~18% of our current practice bank.

39questions here
8free pages
6concepts

Questions 1–5

  1. 1expert · hard

    A post-incident review is being conducted after a web application breach. The incident response team successfully contained and eradicated the incident, but the review reveals that the team did not have a clear escalation path, leading to delays in involving senior management. The team also lacked a predefined communication plan for notifying affected customers. Which of the following improvements should be prioritized in the post-incident report?

    Select an answer first
  2. 2foundation · easy

    After containing a web application incident, the incident handler must eradicate the root cause. Which action is an example of eradication?

    Select an answer first
  3. 3foundation · easy

    A web application incident handler is triaging two incidents: Incident A involves a publicly accessible customer-facing portal that is defaced, and Incident B involves an internal admin panel that is slow but still functional. Which incident should be prioritized first?

    Select an answer first
  4. 4application · medium

    A web application's login page is returning 'Account Locked' errors for many users, and the application logs show a high number of failed login attempts from a single IP range. The incident handler is called. What is the most likely classification of this incident?

    Select an answer first
  5. 5expert · hard

    A security analyst is investigating an incident where a web application's search functionality is returning results from other users' accounts. The application logs show that the search queries contain URL-encoded characters and the application is using a shared database connection pool. The analyst suspects an insecure direct object reference (IDOR) vulnerability. The application is critical to the business, and the team needs to contain the incident while minimizing downtime. Which of the following actions is the MOST effective initial containment measure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.