Ultimate Guide to Prepare 212-89 Certification Exam for ECIH Certification in 2021 [Q88-Q108]

Share

Ultimate Guide to Prepare 212-89 Certification Exam for ECIH Certification in 2021

Use Real 212-89 Dumps - EC-COUNCIL Correct Answers updated on 2021


ECCouncil 212-89 Exam

The Incident Manager Certification certified by the EC Council is designed to provide the fundamental skills to manage and respond to cybersecurity incidents in an information system. A certified accident controller is a qualified professional who can handle various types of accidents, risk assessment methodologies, and various accident management laws and policies. A certified incident controller will be capable to generate an incident response and management policies and control various types of computer security incidents, such as network security incidents, malicious code incidents, and threats of internal attacks.

 

NEW QUESTION 88
A distributed Denial of Service (DDoS) attack is a more common type of DoS Attack, where a single system is targeted by a large number of infected machines over the Internet. In a DDoS attack, attackers first infect multiple systems which are known as:

  • A. Trojans
  • B. Zombies
  • C. Worms
  • D. Spyware

Answer: B

 

NEW QUESTION 89
The ability of an agency to continue to function even after a disastrous event, accomplished through the deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy is known as:

  • A. Business Continuity Plan
  • B. Disaster Planning
  • C. Business Continuity
  • D. Contingency Planning

Answer: C

 

NEW QUESTION 90
US-CERT and Federal civilian agencies use the reporting timeframe criteria in the federal agency reporting
categorization. What is the timeframe required to report an incident under the CAT 4 Federal Agency category?

  • A. Within four (4) hours of discovery/detection if the successful attack is still ongoing and agency is unable to
    successfully mitigate activity
  • B. Weekly
  • C. Monthly
  • D. Within two (2) hours of discovery/detection

Answer: B

 

NEW QUESTION 91
CSIRT can be implemented at:

  • A. Internal enterprise level
  • B. Vendor level
  • C. National, government and military level
  • D. All the above

Answer: D

 

NEW QUESTION 92
Multiple component incidents consist of a combination of two or more attacks in a system. Which of the
following is not a multiple component incident?

  • A. An attacker redirecting user to a malicious website and infects his system with Trojan
  • B. An attacker using email with malicious code to infect internal workstation
  • C. An attacker infecting a machine to launch a DDoS attack
  • D. An insider intentionally deleting files from a workstation

Answer: D

 

NEW QUESTION 93
A threat source does not present a risk if NO vulnerability that can be exercised for a particular threat source.
Identify the step in which different threat sources are defined:

  • A. Control analysis
  • B. Threat identification
  • C. System characterization
  • D. Identification Vulnerabilities

Answer: B

 

NEW QUESTION 94
The flow chart gives a view of different roles played by the different personnel of CSIRT. Identify the incident response personnel denoted by A, B, C, D, E, F and G.

  • A. A- Incident Coordinator, B- Constituency, C-Administrator, D-Incident Manager, E- Human Resource, F-Incident Analyst, G-Public relations
  • B. A-Incident Analyst, B- Incident Coordinator, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Manager
  • C. A- Incident Coordinator, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Manager
  • D. A- Incident Manager, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Coordinator

Answer: A

 

NEW QUESTION 95
Computer forensics is methodical series of techniques and procedures for gathering evidence from computing equipment, various storage devices and or digital media that can be presented in a course of law in a coherent and meaningful format. Which one of the following is an appropriate flow of steps in the computer forensics process:

  • A. Examination> Analysis > Preparation > Collection > Reporting
  • B. Preparation > Collection > Examination > Analysis > Reporting
  • C. Preparation > Analysis > Collection > Examination > Reporting
  • D. Analysis > Preparation > Collection > Reporting > Examination

Answer: B

 

NEW QUESTION 96
The goal of incident response is to handle the incident in a way that minimizes damage and reduces recovery time and cost. Which of the following does NOT constitute a goal of incident response?

  • A. Dealing with human resources department and various employee conflict behaviors.
  • B. Helping personal to recover quickly and efficiently from security incidents, minimizing loss or theft and disruption of services.
  • C. Dealing properly with legal issues that may arise during incidents.
  • D. Using information gathered during incident handling to prepare for handling future incidents in a better way and to provide stronger protection for systems and data.

Answer: A

 

NEW QUESTION 97
The correct sequence of incident management process is:

  • A. Prepare, protect, triage, detect and respond
  • B. Prepare, protect, detect, respond and triage
  • C. Prepare, detect, protect, triage and respond
  • D. Prepare, protect, detect, triage and respond

Answer: D

 

NEW QUESTION 98
In the Control Analysis stage of the NIST's risk assessment methodology, technical and none technical control methods are classified into two categories. What are these two control categories?

  • A. Predictive and Detective controls
  • B. Preventive and predictive controls
  • C. Preventive and Detective controls
  • D. Detective and Disguised controls

Answer: C

 

NEW QUESTION 99
The free, open source, TCP/IP protocol analyzer, sniffer and packet capturing utility standard across many industries and educational institutions is known as:

  • A. Snort
  • B. Wireshark
  • C. nmap
  • D. Cain & Able

Answer: B

 

NEW QUESTION 100
The main feature offered by PGP Desktop Email is:

  • A. None of the above
  • B. End-to-end email communications
  • C. End-to-end secure email service
  • D. Email service during incidents

Answer: C

 

NEW QUESTION 101
The correct order or sequence of the Computer Forensic processes is:

  • A. Preparation, collection, examination, analysis, and reporting
  • B. Preparation, analysis, collection, examination, and reporting
  • C. Preparation, analysis, examination, collection, and reporting
  • D. Preparation, examination, collection, analysis, and reporting

Answer: A

 

NEW QUESTION 102
The typical correct sequence of activities used by CSIRT when handling a case is:

  • A. Log, inform, maintain contacts, release information, follow up and reporting
  • B. Log, inform, release information, maintain contacts, follow up and reporting
  • C. Log, maintain contacts, release information, inform, follow up and reporting
  • D. Log, maintain contacts, inform, release information, follow up and reporting

Answer: A

 

NEW QUESTION 103
The IDS and IPS system logs indicating an unusual deviation from typical network traffic flows; this is called:

  • A. A Proactive
  • B. A Precursor
  • C. A Reactive
  • D. An Indication

Answer: D

 

NEW QUESTION 104
The Linux command used to make binary copies of computer media and as a disk imaging tool if given a raw
disk device as its input is:

  • A. "netstat" command
  • B. "nslookup" command
  • C. "find" command
  • D. "dd" command

Answer: D

Explanation:
Explanation/Reference:

 

NEW QUESTION 105
Which of the following incidents are reported under CAT -5 federal agency category?

  • A. Scans/ probes/ Attempted Access
  • B. Malicious code
  • C. Exercise/ Network Defense Testing
  • D. Denial of Service DoS

Answer: A

 

NEW QUESTION 106
Which of the following is NOT one of the common techniques used to detect Insider threats:

  • A. Spotting an increase in their performance
  • B. Observing employee tardiness and unexplained absenteeism
  • C. Spotting conflicts with supervisors and coworkers
  • D. Observing employee sick leaves

Answer: A

 

NEW QUESTION 107
Identify the network security incident where intended authorized users are prevented from using system, network, or applications by flooding the network with high volume of traffic that consumes all existing network resources.

  • A. Denial of Service Attack
  • B. XSS Attack
  • C. URL Manipulation
  • D. SQL Injection

Answer: A

 

NEW QUESTION 108
......


Becoming Certified Incident Handler

If you opt to become a Certified Incident Handler, your job scope will fall under one of Incident Management Team (IMT) or Incident Response Team (IRT). The ECIH certificate is meant to equip you with the skills you need to deal with and manage computer security issues within a certain information system. In the modern IT environments, a Certified Incident Handler is expected to become a knowledgeable professional who can manage different kinds of incidents and understand the methodologies of risk assessment, including the common policies associated with incident handling. In many organizations, an incident handler will be responsible for creating incident handling policies & dealing with different forms of incidents for security comprising insider attack threats and incidents for malicious code. Therefore, getting certified will earn you recognition as the designated and highly respected incident handler in your company.


The content of the exam for the EC-Council Certified Incident Handler certification revolves around nine domains. They all have different weights in the content. The specific knowledge and skills as well as percentage share of questions related to each subject area of EC-Council 212-89 are outlined below:

  • Forensic Readiness and First Response (13%). This subject area encompasses an understanding of digital evidence; forensic readiness; computer forensics; volatile evidence; preservation of electronic evidence anti-forensics; static evidence.
  • Incident Response and Handling (16%). This topic requires a solid understanding of information security; threat intelligence; computer security; risk management; incident handling; security policies.
  • Email Security Incidents (10%). Here the examinees need to show good comprehension of email security as well as familiarity with deceptive and suspicious email; email incident; phishing email.
  • Incidents Occurred in a Cloud Environment (8%). The last topic focuses on Cloud computing threats; eradication; security in Cloud computing; recovery in Cloud.
  • Network and Mobile Incidents (16%). This section comes with the individuals’ knowledge of inappropriate usage; network attacks; Denial-of-Service; unauthorized access; wireless network; eradication of mobile incidents and recovery; mobile platform vulnerabilities and risks.
  • Process Handling (14%). Within this domain, the applicants need to demonstrate competency in security auditing; incident handling and response; incident readiness; forensic investigation; security incidents; eradication and recovery.
  • Malware Incidents (8%). In the framework of this area, the students are required to be aware of malware, malware incident triage, as well as malicious code.
  • Application Level Incidents (8%). The objective entails your knowledge of web application threats and vulnerabilities; web attacks; eradication of web applications.
  • Insider Threats (7%). To deal with the questions from this domain, the learners should be conversant with insider threats; eradication; employee monitoring tools; detecting and preventing insider threats.

 

ECIH Certification -212-89 Exam-Practice-Dumps: https://www.troytecdumps.com/212-89-troytec-exam-dumps.html

212-89 Premium Files Test pdf - Free Dumps Collection: https://drive.google.com/open?id=1TycXsL1bP1jn4Z4uyXqQKBb_nxSSaAFD