212-89 Certified Incident Handler (ECIH) Practice Questions
Prepare for 212-89 with more than an answer.
- Exam fee
- $250 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 10
- Introduction to Incident Handling and Response10%
- Incident Handling and Response Process15%
- First Response10%
- Handling Malware Incidents15%
- Handling Email Security Incidents10%
- Handling Network Security Incidents15%
- Handling Web Application Security Incidents10%
- Handling Cloud Security Incidents10%
- Handling Insider Threats5%
- Handling Endpoint Security Incidents10%
- 13
Risk is defined as the probability of the occurrence of an incident. Risk formulation generally begins with the likeliness of an event’s occurrence, the harm it may cause and is usually denoted as Risk - Z(events)X (Probability of occurrence)/?
Show answer details
Correct answer: A
Risk is commonly formulated as Risk = Events × Probability × Magnitude, where Magnitude represents the potential impact or harm that could result from an incident. The magnitude component quantifies the severity of consequences, making the risk formula complete. Probability is already mentioned in the formula, while consequences and significance are general terms that do not fit the specific mathematical risk formulation structure.
- 14
An organization faced an information security incident where a disgruntled employee passed sensitive access control information to a competitor. The organization s incident response manager, upon investigation, found that the incident must be handled within a few hours on the same day to maintain business continuity and market competitiveness.
How would you categorize such information security incident?
Show answer details
Correct answer: A
High level incidents involve sensitive information disclosure to competitors, insider threats, or data breaches that require immediate senior management involvement and significant resources. The scenario describes a disgruntled employee passing sensitive access control information to a competitor, which represents a serious security breach requiring high-level incident response procedures. Middle and low level incidents involve less critical issues, while ultra-high incidents are typically reserved for catastrophic system-wide failures or major data breaches affecting thousands of records.
- 15
The process of rebuilding and restoring the computer systems affected by an incident to normal operational stage including all the processes, policies and tools is known as:
Show answer details
Correct answer: C
Incident Recovery is the process of rebuilding and restoring computer systems affected by an incident to normal operational status, including all processes, policies, and tools. This phase focuses specifically on system restoration and business continuity. Incident Management is the overall framework, Incident Response refers to the immediate reaction and containment actions, and Incident Handling encompasses the entire lifecycle but does not specifically refer to the restoration phase.
- 16
Computer viruses are malicious software programs that infect computers and corrupt or delete the data on them. Identify the virus type that specifically infects Microsoft Word files?
Show answer details
Correct answer: C
Macro viruses specifically infect Microsoft Office documents like Word files by embedding malicious code in the document macros. These viruses execute when the document is opened and macros are enabled, making them particularly dangerous for document-based attacks. Micro viruses and file infectors target executable files, while boot sector viruses infect the master boot record of storage devices, none of which specifically target Word document files.
- 17
Policies are designed to protect the organizational resources on the network by establishing the set rules and procedures. Which of the following policies authorizes a group of users to perform a set of actions on a set of resources?
Show answer details
Correct answer: A
Access control policies specifically authorize groups of users to perform defined sets of actions on designated resources, establishing who can access what and under what conditions. This is the fundamental purpose of access control in organizational security. Audit trail policies track user activities, while other policy types serve different security functions but do not directly authorize user actions on resources.
- 18
Which of the following is an incident tracking, reporting and handling tool:
Show answer details
Correct answer: B
RTIR (Request Tracker for Incident Response) is a specialized incident tracking, reporting, and handling tool designed specifically for security incident management teams. It provides structured workflows for incident lifecycle management, reporting capabilities, and collaboration features essential for incident response. CRAMM is a risk assessment methodology, NETSTAT is a network utility command, and EAR/Pilar are not incident tracking tools.
- 19
Incident management team provides support to all users in the organization that are affected by the threat or attack. The organization’s internal auditor is part of the incident response team. Identify one of the responsibilities of the internal auditor as part of the incident response team:
Show answer details
Correct answer: C
Internal auditors in incident response teams are responsible for identifying and reporting security loopholes to management for necessary actions, ensuring organizational compliance and control effectiveness. Their expertise in evaluating internal controls makes them valuable for identifying systemic weaknesses that led to incidents. Configuring security controls, blocking network traffic, and coordinating containment are operational tasks typically handled by security engineers and incident handlers rather than auditors.
- 20
Any information of probative value that is either stored or transmitted in a digital form during a computer crime is called:
Show answer details
Correct answer: A
Digital evidence refers to any information of probative value that is stored or transmitted in digital form during a computer crime, making it legally admissible in court proceedings. This encompasses all electronic data that can prove or disprove facts related to cyber incidents. Computer emails are just one type of digital evidence, digital investigation is the process of examining evidence, and digital forensic examiner is the person who analyzes the evidence, not the evidence itself.
