
EC-CouncilCertified Incident Handler
Domain 1Objective 2
Incident Handling and Response Process ECIH Practice Questions (Page 1)
Part of the Incident Handling Fundamentals domain, which makes up ~18% of our current practice bank.
38questions here
8free pages
5concepts
Questions 1–5
- 1
A mid-sized law firm is creating its incident response plan. The firm has a small IT team of three people, none of whom are dedicated security staff. The partners want to ensure that when a security incident occurs, the right people are notified quickly and the firm's legal obligations regarding client data are met. Which element is MOST important to include in the preparation phase of the plan?
Select an answer first - 2
A security analyst is investigating a potential data exfiltration incident. The analyst finds that a large amount of data was transferred to an external IP address over the past week. The analyst also notices that the source system is a file server that is scheduled for decommissioning next month. Which action is MOST appropriate?
Select an answer first - 3
Which activity is typically performed during the preparation phase of incident handling?
Select an answer first - 4
A company's security team notices that a user's account has been used to access sensitive files at unusual hours. The team suspects the account is compromised. Which action is MOST appropriate to confirm the suspicion?
Select an answer first - 5
A company's incident response team has contained a malware infection and is now in the eradication phase. The team has removed the malware from all affected systems. Which additional action is MOST important during eradication?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.