EC-COUNCIL EC Council Certified Incident Handler (ECIH v3) - 212-89무료 덤프문제 풀어보기
Which of the following methods help incident responders to reduce the false-positive alert rates and further provide benefits of focusing on topmost priority issues reducing potential risk and corporate liabilities?
정답: A
설명: (Fast2test 회원만 볼 수 있음)
During routine monitoring, a cloud-based application hosting provider detects an anomaly uggesting an ongoing DDoS attack targeting one of its hosted applications. The provider's incident response team must quickly mitigate the attack while ensuring minimal service disruption. Which of the following strategies should they prioritize?
정답: C
설명: (Fast2test 회원만 볼 수 있음)
A company's IoT network is experiencing a DDoS attack, disrupting critical operations. What is the best course of action for the incident response team in this scenario?
정답: C
Which of the following is a volatile evidence collecting tool?
정답: A
설명: (Fast2test 회원만 볼 수 있음)
Which of the following terms refers to the personnel that the incident handling and response (IH&R) team must contact to report the incident and obtain the necessary permissions?
정답: C
설명: (Fast2test 회원만 볼 수 있음)
In response to suspicious communications originating from executive accounts, the organization's response team traced the root cause to spoofed identity relays exploiting unsecured DNS entries.
The attack had triggered internal alerts but required deeper remediation to eliminate recurring forged message injections and restore the integrity of interdepartmental mail routing. What action reflects an appropriate eradication strategy in this context?
The attack had triggered internal alerts but required deeper remediation to eliminate recurring forged message injections and restore the integrity of interdepartmental mail routing. What action reflects an appropriate eradication strategy in this context?
정답: B
설명: (Fast2test 회원만 볼 수 있음)
In the aftermath of a cybersecurity incident at TechGuard Ltd., the response team identified a USB drive suspected of containing malicious code. To preserve its integrity for forensic analysis, what should the team do?
정답: B
A global retail enterprise operating across multiple e-commerce platforms and physical locations has recently been targeted by a well-orchestrated cyberattack that disrupted transaction processing systems and led to a temporary shutdown of online services. Following the incident, customer confidence dropped, and the board demanded immediate corrective and preventive measures to strengthen cybersecurity resilience. The Chief Information Security Officer (CISO) directed the incident response team to establish a forward-looking approach that not only mitigates such incidents but also ensures that all stakeholders are trained in advance. This includes defining clear roles and responsibilities, creating and training a dedicated response team, conducting simulation exercises, reviewing existing IP tools, auditing organizational assets, and developing a comprehensive set of policies and playbooks. Which phase of the IH&R process should the organization focus on to achieve this?
정답: A
설명: (Fast2test 회원만 볼 수 있음)
You are the cloud security incident response manager for a large organization. Your team has identified a potential security incident in the cloud environment. Upon investigation, you find that an unauthorized individual gained access to a critical database containing sensitive customer information. What is the MOST appropriate immediate action to take?
정답: B
Your manager hands you several items of digital evidence and asks you to investigate them in the order of volatility. Which of the following is the MOST volatile?
정답: A
설명: (Fast2test 회원만 볼 수 있음)
During the initial setup of an incident response team at a medium-sized organization, the newly hired incident handler is tasked with defining an effective process for managing security incidents.
Considering the broad range of possible incidents, from common threats to advanced persistent threats (APTs). which of the following is the MOST appropriate approach for this task?
Considering the broad range of possible incidents, from common threats to advanced persistent threats (APTs). which of the following is the MOST appropriate approach for this task?
정답: D
James has been appointed as an incident handling and response (IH&R) team lead and he was assigned to build an IH&R plan along with his own team in the company. Identify the IH&R process step James is currently working on.
정답: A
설명: (Fast2test 회원만 볼 수 있음)
Liam, a network engineer, configures firewalls to prevent outbound file transfers over unauthorized FTP and HTTP channels. Despite this, an insider used encrypted traffic via HTTPS to exfiltrate data. A review revealed that no deep packet inspection was in place. Which insider threat eradication control could have helped prevent this?
정답: C
설명: (Fast2test 회원만 볼 수 있음)
A multinational SaaS provider detects a major security breach involving unauthorized access to customer billing data in its EU and APAC servers. After triage and legal review, the IH&R team confirms data exfiltration impacting regulated regions. In response, the CISO, with legal and compliance teams, initiates a structured communication protocol--informing affected clients, notifying data protection authorities under laws such as GDPR, and preparing media responses with public affairs. All communications are securely routed, reviewed for legal accuracy, and sent only with executive approval to mitigate risk and misinformation. What type of communication is emphasized in this scenario?
정답: A
설명: (Fast2test 회원만 볼 수 있음)
Post an upgrade in their global communication systems, NewsNet Corp., a media conglomerate, experienced anomalies. Subsequent analysis revealed malware that subtly altered news content, skewing information. Having an AI-based content checker and a network segregation tool, what's the immediate approach?
정답: C
설명: (Fast2test 회원만 볼 수 있음)