212-89: EC-Council Certified Incident Handler — Free Practice Questions
10 free sample questions from a bank of 165, with the correct answers and explanations. No signup required — start practising right now.
1Which of the following terms may be defined as "a measure of possible inability to achieve a goal, objective, or target within a defined security, cost plan and
technical limitations that adversely affects the organization's operation and revenues?
Risk
Vulnerability
Threat
Incident Response
Answer: A
2A distributed Denial of Service (DDoS) attack is a more common type of DoS Attack, where a single system is targeted by a large number of infected machines
over the Internet. In a DDoS attack, attackers first infect multiple systems which are known as:
Trojans
Zombies
Spyware
Worms
Answer: B
3The goal of incident response is to handle the incident in a way that minimizes damage and reduces recovery time and cost. Which of the following does NOT
constitute a goal of incident response?
Dealing with human resources department and various employee conflict behaviors.
Using information gathered during incident handling to prepare for handling future incidents in a better way and to provide stronger protection for systems and data.
Helping personal to recover quickly and efficiently from security incidents, minimizing loss or theft and disruption of services.
Dealing properly with legal issues that may arise during incidents.
Answer: A
4An organization faced an information security incident where a disgruntled employee passed sensitive access control information to a competitor. The
organization's incident response manager, upon investigation, found that the incident must be handled within a few hours on the same day to maintain business
continuity and market competitiveness. How would you categorize such information security incident?
High level incident
Middle level incident
Ultra-High level incident
Low level incident
Answer: B
5Business continuity is defined as the ability of an organization to continue to function even after a disastrous event, accomplished through the deployment of
redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy. Identify the plan which is mandatory part of a
business continuity plan?
Forensics Procedure Plan
Business Recovery Plan
Sales and Marketing plan
New business strategy plan
Answer: B
6The flow chart gives a view of different roles played by the different personnel of CSIRT. Identify the incident response personnel denoted by A, B, C, D, E, F and
G.
A-Incident Analyst, B- Incident Coordinator, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Manager
A- Incident Coordinator, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Manager
A- Incident Manager, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Coordinator
Answer: C
7Which of the following is an appropriate flow of the incident recovery steps?
System Operation-System Restoration-System Validation-System Monitoring
System Validation-System Operation-System Restoration-System Monitoring
System Restoration-System Monitoring-System Validation-System Operations
System Restoration-System Validation-System Operations-System Monitoring
Answer: D
8A computer Risk Policy is a set of ideas to be implemented to overcome the risk associated with computer security incidents. Identify the procedure that is NOT
part of the computer risk policy?
Procedure to identify security funds to hedge risk
Procedure to monitor the efficiency of security controls
Procedure for the ongoing training of employees authorized to access the system
Provisions for continuing support if there is an interruption in the system or if the system crashes
Answer: A
9Identify the network security incident where intended authorized users are prevented from using system, network, or applications by flooding the network with high
volume of traffic that consumes all existing network resources.
URL Manipulation
XSS Attack
SQL Injection
Denial of Service Attack
Answer: D
10Incident handling and response steps help you to detect, identify, respond and manage an incident. Which of the following steps focus on limiting the scope and
extent of an incident?