
The Realest Study Materials 212-89 Dumps Updated Jul 31, 2024
LATEST 212-89 Exam Practice Material
NEW QUESTION # 50
The free, open source, TCP/IP protocol analyzer, sniffer and packet capturing utility standard across many
industries and educational institutions is known as:
- A. nmap
- B. Wireshark
- C. Cain & Able
- D. Snort
Answer: B
NEW QUESTION # 51
Adam is an incident handler who intends to use DBCC LOG command to analyze a database and retrieve the active transaction log files for the specified database. The syntax of DBCC LOG command is DBCC LOG(, ), where the output parameter specifies the level of information an incident handler wants to retrieve. If Adam wants to retrieve the full information on each operation along with the hex dump of a current transaction row, which of the following output parameters should Adam use?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
NEW QUESTION # 52
Farheen is an incident responder at reputed IT Firm based in Florida. Farheen was asked to investigate a recent cybercrime faced by the organization. As part of this process, she collected static data from a victim system. She used dd, a command line tool, to perform forensic duplication to obtain an NTFS image of the original disk. She created a sector-by-sector mirror imaging of the disk and saved the output image file as image.dd. Identify the static data collection process step performed by Farheen while collecting static data.
- A. Comparison
- B. System preservation
- C. Physical presentation
- D. Administrative consideration
Answer: B
NEW QUESTION # 53
Which of the following techniques helps incident handlers to detect man-in-the-middle attack by finding the new APs and trying to connect an already established channel, even if the spoofed AP consists similar IP and MAC addresses as of the original AP?
- A. Network traffic monitoring
- B. General wireless traffic monitoring
- C. Access point monitoring
- D. Wireless client monitoring
Answer: C
NEW QUESTION # 54
What is the best staffing model for an incident response team if current employees' expertise is very low?
- A. All the above
- B. Fully outsourced
- C. Partially outsourced
- D. Fully insourced
Answer: B
NEW QUESTION # 55
An active vulnerability scanner featuring high speed discovery, configuration auditing, asset profiling, sensitive data discovery, and vulnerability analysis is called:
- A. nmap
- B. EtherApe
- C. Nessus
- D. CyberCop
Answer: C
NEW QUESTION # 56
An insider threat response plan helps an organization minimize the damage caused by malicious insiders. One of the approaches to mitigate these threats is setting up controls from the human resources department. Which of the following guidelines can the human resources department use?
- A. Implement a person-to-person rule to secure the backup process and physical media.
- B. Access granted to users should be documented and vetted by a supervisor.
- C. Monitor and secure the organization's physical environment.
- D. Disable the default administrative account to ensure accountability.
Answer: B
NEW QUESTION # 57
Otis is an incident handler working in an organization called Delmont. Recently, the organization faced several setbacks in business, whereby its revenues are decreasing. Otis was asked to take charge and look into the matter. While auditing the enterprise security, he found traces of an attack through which proprietary information was stolen from the enterprise network and passed onto their competitors. Which of the following information security incidents did Delmont face?
- A. Unauthorized access
- B. Network and resource abuses
- C. Email-based abuse
- D. Espionage
Answer: D
Explanation:
Espionage, in the context of information security incidents, refers to the unauthorized access and theft of proprietary information for competitive advantage. In the scenario described, where proprietary information was stolen from Delmont's enterprise network and passed onto their competitors, this directly aligns with the definition of espionage. The incident involves deliberate targeting and extraction of sensitive business information, which is then used by competitors to gain a market advantage. Such actions not only compromise the confidentiality of business-critical information but can also significantly impact the financial stability and competitive positioning of the victim organization.
References:The Certified Incident Handler (ECIH v3) curriculum by EC-Council discusses various information security incidents, including espionage, highlighting the need for comprehensive security measures, incident detection capabilities, and effective response strategies to protect against and respond to such threats.
NEW QUESTION # 58
A methodical series of techniques and procedures for gathering evidence, from computing equipment and various storage devices and digital media, that can be presented in a court of law in a coherent and meaningful format is called:
- A. Forensic Analysis
- B. Forensic Readiness
- C. Steganalysis
- D. Computer Forensics
Answer: D
NEW QUESTION # 59
The following steps describe the key activities in forensic readiness planning:
1. Train the staff to handle the incident and preserve the evidence
2. Create a special process for documenting the procedure
3. Identify the potential evidence required for an incident
4. Determine the source of the evidence
5. Establish a legal advisory board to guide the investigation process
6. Identify if the incident requires full or formal investigation
7. Establish a policy for securely handling and storing the collected evidence
8. Define a policy that determines the pathway to legally extract electronic evidence with minimal disruption Identify the correct sequence of steps involved in forensic readiness planning.
- A. 3-->4-->8-->7-->6-->1-->2-->5
- B. 3-->1-->4-->5-->8-->2-->6-->7
- C. 1-->2-->3-->4-->5-->6-->7-->8
- D. 2-->3-->1-->4-->6-->5-->7-->8
Answer: A
Explanation:
The correct sequence of steps involved in forensic readiness planning, based on the activities described, is as follows:
* Identify the potential evidence required for an incident.
* Determine the source of the evidence.
* Define a policy that determines the pathway to legally extract electronic evidence with minimal disruption.
* Establish a policy for securely handling and storing the collected evidence.
* Identify if the incident requires full or formal investigation.
* Train the staff to handle the incident and preserve the evidence.
* Create a special process for documenting the procedure.
* Establish a legal advisory board to guide the investigation process.This sequence ensures that an organization is prepared to handle incidents efficiently, with a focus on identifying relevant evidence and the legal context of its collection, followed by staff training and the establishment of guiding policies and advisory boards.References:Incident Handler (ECIH v3) courses and study guides include discussions on forensic readiness planning, highlighting the importance of preparing organizations for effective legal and technical handling of incidents.
NEW QUESTION # 60
Darwin is an attacker residing within the organization and is performing network sniffing by running his system in promiscuous mode. He is capturing and viewing all the network packets transmitted within the organization. Edwin is an incident handler in the same organization.
In the above situation, which of the following Nmap commands Edwin must use to detect Darwin's system that is running in promiscuous mode?
- A. nmap --script=sniffer-detect [Target IP Address/Range of IP addresses]
- B. nmap -sU -p 500
- C. nmap -sV -T4 -O -F -version-light
- D. nmap --script hostmap
Answer: A
Explanation:
The GPG18 and Forensic readiness planning (SPF) principles outline various guidelines to enhance an organization's readiness for forensic investigation and response. Principle 5, which suggests that organizations should adopt a scenario-based Forensic Readiness Planning approach that learns from experience gained within the business, emphasizes the importance of being prepared for a wide range of potential incidents by leveraging lessons learned from past experiences. This approach helps in continuously improving forensic readiness and response capabilities by adapting to the evolving threat landscape and organizational changes.
References:While specific documentation from GPG18 and SPF might detail these principles, the ECIH v3 program by EC-Council covers the concept of forensic readiness planning, including adopting scenario-based approaches and learning from past incidents as a fundamental aspect of enhancing an organization's incident response and forensic capabilities.
NEW QUESTION # 61
Which of the following is not a countermeasure to eradicate inappropriate usage incidents?
- A. Avoid VPN and other secure network channels
- B. Install firewall and IDS/IPS to block services that violate the organization's policy
- C. Always store the sensitive data in far located servers and restrict its access
- D. Register the user activity logs and keep monitoring them regularly
Answer: A
NEW QUESTION # 62
What is the name of the type of malicious software or malware designed to deny access to a computer system or data until money is paid?
- A. Ransomware
- B. Adware
- C. Spyware
- D. Virus
Answer: A
NEW QUESTION # 63
Identify a standard national process which establishes a set of activities, general tasks and a management
structure to certify and accredit systems that will maintain the information assurance (IA) and security posture
of a system or site.
- A. NIAAAP
- B. NIPACP
- C. NIASAP
- D. NIACAP
Answer: D
NEW QUESTION # 64
Raven is a part of an IH&R team and was informed by her manager to handle and lead the removal of the root cause for an incident and to close all attack vectors to prevent similar incidents in the future. Raven notifies the service providers and developers of affected resources. Which of the following steps of the incident handling and response process does Raven need to implement to remove the root cause of the incident?
- A. Containment
- B. Eracicotion
- C. Incident triage
- D. Evidence gathering and forensic analysis
Answer: B
NEW QUESTION # 65
________________ attach(es) to files
- A. Worms
- B. Spyware
- C. Viruses
- D. adware
Answer: C
NEW QUESTION # 66
Ren is assigned to handle a security incident of an organization. He is tasked with forensics investigation to find the evidence needed by the management.
Which of the following steps falls under the investigation phase of the computer forensics investigation process?
- A. Evidence assessment
- B. Setup a computer forensics lab
- C. Risk assessment
- D. Secure the evidence
Answer: D
NEW QUESTION # 67
John, a professional hacker, is attacking an organization, where he is trying to destroy the connectivity between an AP and client to make the target unavailable to other wireless devices.
Which of the following attacks is John performing in this case?
- A. Disassociation attack
- B. Routing attack
- C. EAP failure
- D. Denial-of-service
Answer: A
NEW QUESTION # 68
Tibson works as an incident responder for MNC based in Singapore. He is investigating a web application security incident recently faced by the company. The attack is performed on a MS SQL Server hosted by the company. In the detection and analysis phase, he used regular expressions to analyze and detect SQL meta-characters that led to SQL injection attack.
Identify the regular expression used by Tibson to detect SQL injection attack on MS SQL Server.
- A. ((\.|%2E)(\.|%2E)(\/|%2F|\\|%5C))
- B. ((\.\.\\)|(\.\.\/))
- C. /exec(\s|\+)+(s|x)p\w+/ix
- D. ((\%3C)|<)((\%2F)|\/)*(script)((\%3E)|>)
Answer: C
Explanation:
The regular expression/exec(\s|\+)+(s|x)p\w+/ixis designed to match patterns that resemble SQL injection attempts, specifically targeting MS SQL Server. This expression looks for the use of theexeccommand followed by one or more spaces or plus signs, and then patterns that start withsporxp, which are prefixes commonly used in SQL Server stored procedures and extended stored procedures. These are often targeted in SQL injection attacks to execute malicious SQL statements. The regular expression provided is a tool used by incident responders like Tibson to identify and analyze potential SQL injection attempts by looking for suspicious patterns in SQL queries.
NEW QUESTION # 69
The data on the affected system must be backed up so that it can be retrieved if it is damaged during incident response. The system backup can also be used for further investigations of the incident. Identify the stage of the incident response and handling process in which complete backup of the infected system is carried out?
- A. Incident recording
- B. Incident investigation
- C. Containment
- D. Eradication
Answer: C
NEW QUESTION # 70
Which is the incorrect statement about Anti-keyloggers scanners:
- A. Detect already installed Keyloggers in victim machines
- B. Run in stealthy mode to record victims online activity
- C. Software tools
Answer: B
NEW QUESTION # 71
Which of the following encoding techniques replaces unusual ASCII characters with
"%" followed by the character's two-digit ASCII code expressed in hexadecimal?
- A. Base64 encoding
- B. HTML encoding
- C. Unicode encoding
- D. URL encoding
Answer: D
NEW QUESTION # 72
Which of the following does NOT reduce the success rate of SQL injection?
- A. Automatically lock a user account after a predefined number of invalid login attempts within a predefined interval.
- B. Constrain legitimate characters to exclude special characters.
- C. Limit the length of the input field.
- D. Close unnecessary application services and ports on the server.
Answer: D
Explanation:
Reducing the success rate of SQL injection attacks is focused on minimizing vulnerabilities within the application's database interactions, rather than the broader server or network services. SQL injection prevention techniques typically involve input validation, parameterized queries, and the use of stored procedures, rather than changes to the network or server configuration.A) Closing unnecessary application services and ports on the server is a general security best practice to reduce the attack surface but does not directly impact the success rate of SQL injection attacks. This action limits access to potential vulnerabilities across the network and server but doesn't address the specific ways SQL injection exploits input handling within web applications.B) Automatically locking a user account after a predefined number of invalid login attempts within a predefined interval can help mitigate brute force attacks but has no direct effect on preventing SQL injection, which exploits code vulnerabilities to manipulate database queries.C) Constraining legitimate characters to exclude special characters and D) Limiting the length of the input field are both direct methods to reduce the risk of SQL injection. They focus on controlling user input, which is the vector through which SQL injection attacks are launched. By restricting special characters that could be used in SQL commands and limiting input lengths, an application can reduce the potential for malicious input to form a part of SQL queries executed by the backend database.
References:EC-Council's Certified Incident Handler (ECIH v3) program includes strategies for preventing various types of cyber attacks, including SQL injection, by emphasizing secure coding practices and application design.
NEW QUESTION # 73
......
Study HIGH Quality 212-89 Free Study Guides and Exams Tutorials: https://www.troytecdumps.com/212-89-troytec-exam-dumps.html
New 212-89 Actual Exam Dumps, EC-COUNCIL Practice Test: https://drive.google.com/open?id=15-1LrX-SfvfL9wLeKTDsNYV3O3hrJ-sY