100% Free 212-89 Files For passing the exam Quickly UPDATED May 10, 2024
212-89 Dumps Questions Study Exam Guide
NEW QUESTION # 106
Mr.Smith is a lead incident responder of a small financial enterprise, which has a few branches in Australia. Recently, the company suffered a massive attack, losing$5M through an inter-banking system After an in-depth investigation, it was found that the incident occurred because the attackers penetrated the network through a minor vulnerability 6 months ago and maintained access without being detected by any user. They then tried to delete user fingerprints and performed a lateral movement to the computer of a person with privileges in the inter-banking system. The attackers finally gained access and performed fraudulent transactions.
In the above scenario, which of the following most accurately describes the type of attack?
- A. Ransom ware attack
- B. Phishing
- C. Denial-of-service attack
- D. APT attack
Answer: D
NEW QUESTION # 107
The largest number of cyber-attacks are conducted by:
- A. Business partners
- B. Outsiders
- C. Suppliers
- D. Insiders
Answer: B
NEW QUESTION # 108
US-CERT and Federal civilian agencies use the reporting timeframe criteria in the federal agency reporting categorization. What is the timeframe required to report an incident under the CAT 4 Federal Agency category?
- A. Weekly
- B. Within four (4) hours of discovery/detection if the successful attack is still ongoing and agency is unable to successfully mitigate activity
- C. Monthly
- D. Within two (2) hours of discovery/detection
Answer: A
NEW QUESTION # 109
Adam is an attacker who along with his team launched multiple attacks on target organization for financial benefits. Worried about getting caught, he decided to forge his identity. To do so, he created a new identity by obtaining information from different victims.
Identify the type of identity theft Adam has performed.
- A. Social identity theft
- B. Synthetic identity theft
- C. Medical identity theft
- D. Tax identity theft
Answer: B
NEW QUESTION # 110
In a DDoS attack, attackers first infect multiple systems, which are then used to attack a particular target directly. Those systems are called:
- A. Honey Pots
- B. Relays
- C. Handlers
- D. Zombies
Answer: D
NEW QUESTION # 111
One of your coworkers just sent you an email. She wonders if it is real, a part of your phishing campaign, a real phishing attack, or a mistake. One of the things you want to know is where the email originated from.
Where would you check in the email message to find that information?
- A. The user's received report
- B. Email's received report
- C. Email headers
- D. Inbox digest
Answer: C
NEW QUESTION # 112
The process of rebuilding and restoring the computer systems affected by an incident to normal operational stage including all the processes, policies and tools is known as:
- A. Incident Management
- B. Incident Recovery
- C. Incident Response
- D. Incident Handling
Answer: B
NEW QUESTION # 113
Digital evidence must:
- A. Not prove the attackers actions
- B. Be Volatile
- C. Cast doubt on the authenticity and veracity of the evidence
- D. Be Authentic, complete and reliable
Answer: D
NEW QUESTION # 114
Installing a password cracking tool, downloading pornography material, sending emails to colleagues which
irritates them and hosting unauthorized websites on the company's computer are considered:
- A. Inappropriate usage incidents
- B. Network based attacks
- C. Unauthorized access attacks
- D. Malware attacks
Answer: A
NEW QUESTION # 115
Multiple component incidents consist of a combination of two or more attacks in a system. Which of the following is not a multiple component incident?
- A. An attacker using email with malicious code to infect internal workstation
- B. An attacker redirecting user to a malicious website and infects his system with Trojan
- C. An insider intentionally deleting files from a workstation
- D. An attacker infecting a machine to launch a DDoS attack
Answer: C
NEW QUESTION # 116
The flow chart gives a view of different roles played by the different personnel of CSIRT. Identify the incident
response personnel denoted by A, B, C, D, E, F and G.
- A. A- Incident Coordinator, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-
Constituency, G-Incident Manager - B. A- Incident Coordinator, B- Constituency, C-Administrator, D-Incident Manager, E- Human Resource, F-
Incident Analyst, G-Public relations - C. A- Incident Manager, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-
Constituency, G-Incident Coordinator - D. A-Incident Analyst, B- Incident Coordinator, C- Public Relations, D-Administrator, E- Human Resource, F-
Constituency, G-Incident Manager
Answer: B
NEW QUESTION # 117
Absorbing minor risks while preparing to respond to major ones is called:
- A. Risk Avoidance
- B. Risk Transfer
- C. Risk Assumption
- D. Risk Mitigation
Answer: C
NEW QUESTION # 118
Which of the following is a type of malicious code or software that appears legitimate but can take control of your computer?
- A. Password attack
- B. Trojan attack
- C. Phishing attack
- D. DDoS
Answer: B
NEW QUESTION # 119
The left over risk after implementing a control is called:
- A. Residual risk
- B. Low risk
- C. Critical risk
- D. Unaccepted risk
Answer: A
NEW QUESTION # 120
Which of the following is an appropriate flow of the incident recovery steps?
- A. System Restoration-System Validation-System Operations-System Monitoring
- B. System Restoration-System Monitoring-System Validation-System Operations
- C. System Validation-System Operation-System Restoration-System Monitoring
- D. System Operation-System Restoration-System Validation-System Monitoring
Answer: A
NEW QUESTION # 121
Which of the following is host-based evidence?
- A. The date and time of the PC
- B. Router logs
- C. IDS logs
- D. Wiretaps
Answer: A
NEW QUESTION # 122
Which of the following is a term that describes the combination of strategies and services intended to restore data, applications, and other resources to the public cloud or dedicated service providers?
- A. Eradication
- B. Mitigation
- C. Cloud recovery
- D. Analysis
Answer: C
NEW QUESTION # 123
Which of the following digital evidence is temporarily stored on a digital device that requires a constant power supply and is deleted if the power supply is interrupted?
- A. Slack space
- B. Swap file
- C. Process memory
- D. Event logs
Answer: C
NEW QUESTION # 124
Johnson is an incident handler and is working on a recent web application attack faced by his organization. As part of this process, he performed data preprocessing in order to analyze and detect the watering hole attack. Johnson preprocessed the outbound network traffic data collected from firewalls and proxy servers. He then started analyzing the user activities within a certain time period to create time ordered domain sequences to perform further analysis on sequential patterns. Identify the data-preprocessing step performed by Johnson.
- A. Filtering invalid hostnames
- B. User-specific sessionization
- C. Identifying unpopular domains
- D. Hostname normalization
Answer: B
NEW QUESTION # 125
Installing a password cracking tool, downloading pornography material, sending emails to colleagues which irritates them and hosting unauthorized websites on the company's computer are considered:
- A. Inappropriate usage incidents
- B. Network based attacks
- C. Unauthorized access attacks
- D. Malware attacks
Answer: A
NEW QUESTION # 126
According to NITS, what are the 5 main actors in cloud computing?
- A. Provider, carrier, auditor, broker, and seller
- B. Consumer, provider, carrier, auditor, and broker
- C. None of these
- D. Buyer, consumer, carrier, auditor, and broker
Answer: B
NEW QUESTION # 127
The ability of an agency to continue to function even after a disastrous event, accomplished through the deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy is known as:
- A. Contingency Planning
- B. Business Continuity
- C. Business Continuity Plan
- D. Disaster Planning
Answer: B
NEW QUESTION # 128
If the browser does not expire the session when the user fails to logout properly, which of the following OWASP Top 10 web vulnerabilities is caused?
- A. A2: Broken authentication
- B. A7: Cross-site scripting
- C. A3: Sensitive data exposure
- D. A5: Broken access control
Answer: A
NEW QUESTION # 129
......
EC-COUNCIL ECIH certification is an ideal program for entry-level cybersecurity professionals, network administrators, security architects, and engineers. It is also recommended for IT professionals looking to advance their careers in security management, governance, and risk mitigation. EC Council Certified Incident Handler (ECIH v2) certification builds a strong base for individuals to enter into more advanced security certifications such as EC-Council Certified Ethical Hacker, Certified Network Defender or Certified Hacking Forensic Investigator.
212-89 Premium Exam Engine - Download Free PDF Questions: https://www.troytecdumps.com/212-89-troytec-exam-dumps.html
Instant Download 212-89 Free Updated Test Dumps: https://drive.google.com/open?id=1MkrUw5RtrJ-x1C258_EIQ7UrrSLS-Nfg