
EC-CouncilCertified Incident Handler
Domain 4Objective 1
Handling and Responding to Web Application Security Incidents ECIH Practice Questions (Page 4)
Part of the Web Application and Cloud Incidents domain, which makes up ~18% of our current practice bank.
39questions here
8free pages
6concepts
Questions 16–20
- 16
An incident handler is collecting evidence from a compromised web application hosted on a cloud VM. The handler needs to preserve the evidence for potential legal action. Which action is MOST important to maintain the chain of custody?
Select an answer first - 17
A large online retailer uses a web application with a microservices architecture. The security team detects unusual outbound traffic from the application's payment processing service to an unknown external IP address. The application logs show that the payment service is making requests to a URL that is not part of the application's normal functionality. The team suspects a server-side request forgery (SSRF) vulnerability. The application is critical to business operations, and the team must balance immediate containment with continued service availability. Which of the following actions is the MOST appropriate initial response?
Select an answer first - 18
What is the primary purpose of the final incident report in a web application security incident?
Select an answer first - 19
A company's e-commerce site is suddenly returning HTTP 500 errors on the product search page. The web server logs show a sharp spike in requests containing long strings of percent-encoded characters, and the application's memory usage has tripled. The incident handler suspects a web attack. What should the handler do FIRST to confirm the nature of the incident?
Select an answer first - 20
A financial services company's public-facing web application suddenly begins returning HTTP 500 errors for all requests. The operations team notices that the application's error logs are filling with SQL syntax errors referencing a 'UNION SELECT' statement, and the database server's CPU utilization has spiked to 100%. The application team confirms they did not deploy any code changes in the last 24 hours. What is the most appropriate immediate classification and response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.