
EC-CouncilCertified Incident Handler
Domain 1Objective 2
Incident Handling and Response Process ECIH Practice Questions (Page 5)
Part of the Incident Handling Fundamentals domain, which makes up ~18% of our current practice bank.
38questions here
8free pages
5concepts
Questions 21–25
- 21
What is the main goal of the preparation phase in incident handling?
Select an answer first - 22
A university's IT team notices that several student accounts are sending phishing emails. The accounts were accessed from IP addresses in different countries within a short time. The team suspects a credential-stuffing attack. Which action is MOST appropriate to confirm and scope the incident?
Select an answer first - 23
After a data breach at a retail company, the incident response team completed the containment, eradication, and recovery phases. The team is now in the post-incident activity phase. The company's management wants to know what went wrong and how to prevent similar incidents. Which activity is MOST important to perform during this phase?
Select an answer first - 24
Which activity is typically performed during the post-incident activity phase?
Select an answer first - 25
After a ransomware incident, a hospital's IT team successfully restored systems from backups and resumed normal operations. During the post-incident review, the team discovers that the initial detection was delayed by 72 hours because the antivirus alerts were configured to notify only the help desk, who did not know how to escalate them. The incident response plan did not include a clear escalation path. Which post-incident activity is MOST important to perform to prevent a recurrence of this specific issue?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.