
EC-CouncilCertified Incident Handler
Domain 1Objective 1
Introduction to Incident Handling and Response ECIH Practice Questions (Page 6)
Part of the Incident Handling Fundamentals domain, which makes up ~18% of our current practice bank.
49questions here
10free pages
8concepts
Questions 26–30
- 26
What is the primary goal of effective communication during an incident?
Select an answer first - 27
During a ransomware incident, the incident response team discovers that the ransomware has encrypted files on a server that is subject to regulatory compliance. The legal team wants to preserve evidence for potential litigation, while the operations team wants to restore the server from backups as quickly as possible to minimize downtime. The incident manager must balance these conflicting needs. What is the most appropriate course of action?
Select an answer first - 28
During an incident investigation, an incident handler needs to collect evidence from a compromised server. What is the MOST important consideration when collecting evidence?
Select an answer first - 29
A small business has no formal incident response plan. After a malware infection, the owner wants to improve the company's ability to respond to future incidents. What is the MOST effective first step?
Select an answer first - 30
A company has a mature incident response program. The security team is evaluating whether to invest in additional threat intelligence feeds. What is the MOST relevant benefit of threat intelligence for incident handling?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.