Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Incident Handler

Domain 4Objective 1

Handling and Responding to Web Application Security Incidents ECIH Practice Questions (Page 2)

Part of the Web Application and Cloud Incidents domain, which makes up ~18% of our current practice bank.

39questions here
8free pages
6concepts

Questions 6–10

  1. 6application · medium

    An incident handler is collecting evidence from a compromised web server and needs to ensure the evidence is admissible in court. Which of the following actions is MOST important to maintain the chain of custody?

    Select an answer first
  2. 7foundation · easy

    During routine monitoring, a security analyst notices a series of HTTP 500 errors in the web server logs, followed by a spike in outbound traffic from the web server to an external IP address. Which symptom is most indicative of a web application security incident?

    Select an answer first
  3. 8foundation · easy

    A web application is under an active SQL injection attack. Which containment measure is most appropriate to immediately limit the attack's impact?

    Select an answer first
  4. 9foundation · easy

    An incident handler needs to collect evidence from a compromised web server. Which action is most consistent with forensic soundness?

    Select an answer first
  5. 10application · medium

    During a web application incident, an incident handler needs to collect evidence from a Linux web server. The server is still running, and the incident handler wants to preserve volatile data before shutting down the server. Which of the following actions should be performed FIRST?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.