
EC-CouncilCertified Incident Handler
Domain 1Objective 1
Introduction to Incident Handling and Response ECIH Practice Questions (Page 7)
Part of the Incident Handling Fundamentals domain, which makes up ~18% of our current practice bank.
49questions here
10free pages
8concepts
Questions 31–35
- 31
Which of the following is the correct sequence of the six phases in the incident handling process?
Select an answer first - 32
What is a key ethical consideration when handling an incident that involves personal data?
Select an answer first - 33
A company is updating its incident handling documentation. The security team wants to ensure that during a malware outbreak, the response team follows a consistent, step-by-step approach that includes specific technical actions and decision points. Which document should the team create or update?
Select an answer first - 34
An incident is classified as 'high severity' because it affects a critical business system and is spreading rapidly. What should the incident response team do first?
Select an answer first - 35
A hospital's IT team detects a phishing email that has been opened by several employees, but no malware has been detected yet. At the same time, a ransomware alert is confirmed on a server that stores patient records. The incident manager must prioritize responses. Which incident should be handled first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.