Pre-Winter Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

212-89 EC Council Certified Incident Handler (ECIH v3) Questions and Answers

Questions 4

Following a security alert, the incident response team at a legal consulting firm suspects that an employee used a USB storage device to exfiltrate confidential client data. To confirm which USB device was connected and gather timestamps and identifiers, which method is most effective?

Options:

A.

Check Windows registry entries under Enum\USB.

B.

Scan network logs for USB file upload patterns.

C.

Review Windows SetupAPI.dev.log file entries.

D.

Use WHOIS lookup to trace USB activity.

Buy Now
Questions 5

Emma, a senior security engineer at a technology firm, discovered during a routine audit that several employees had been granted administrative access to sensitive systems, even though their roles did not require such access rights. One of these employees later accessed restricted financial data and attempted to modify audit logs. Which insider threat eradication measure would have best prevented this incident?

Options:

A.

User and Entity Behavior Analytics (UEBA)

B.

Principle of Least Privilege through access controls

C.

Enhanced password policy

D.

Network segmentation

Buy Now
Questions 6

Which of the following is an attack that occurs when a malicious program causes a user’s browser to perform an unwanted action on a trusted site for which the user is currently authenticated?

Options:

A.

Cross-site scripting

B.

Insecure direct object references

C.

Cross-site request forgery

D.

SQL injection

Buy Now
Questions 7

Lara, a SOC analyst, investigates multiple alerts generated by an IDS showing repeated login failures from a specific workstation to an internal application. When reviewing Windows Event Viewer logs, she discovers a user repeatedly attempting logins outside of working hours. Further checks reveal the user had installed an unauthorized remote desktop tool. Which of the following best describes this situation?

Options:

A.

Policy-enforced remote work attempt

B.

Unauthorized access incident from a third party

C.

Inappropriate usage due to policy violation and software installation

D.

DoS attack against an internal application

Buy Now
Questions 8

Which of the following techniques helps incident handlers to detect man-in-the-middle attack by finding the new APs and trying to connect an already established channel,

even if the spoofed AP consists similar IP and MAC addresses as of the original AP?

Options:

A.

Wireless client monitoring

B.

Network traffic monitoring

C.

General wireless traffic monitoring

D.

Access point monitoring

Buy Now
Questions 9

A cybersecurity team at a financial services firm detects abnormal behavior on several endpoints within the network, suggesting a possible breach. The anomalies include unexpected data transfers and processes running with unusual permissions. Given the potential for significant financial and reputational damage, the team needs to quickly validate whether these are indicators of a security incident or benign anomalies. What method should the team prioritize to detect and validate the incident effectively?

Options:

A.

Utilize an advanced behavioral analysis tool to differentiate between legitimate and malicious activities.

B.

Engage an external cybersecurity consultancy to conduct an independent assessment.

C.

Implement strict access-control measures to limit permissions on all endpoints immediately.

D.

Disconnect the affected endpoints from the network to prevent potential data exfiltration.

Buy Now
Questions 10

An attacker after performing an attack decided to wipe evidences using artifact wiping techniques to evade forensic investigation. He applied magnetic field to the digital

media device, resulting in an entirely clean device of any previously stored data.

Identify the artifact wiping technique used by the attacker.

Options:

A.

File wiping utilities

B.

Disk degaussing/destruction

C.

Disk cleaning utilities

D.

Syscall proxying

Buy Now
Questions 11

Eve’s is an incident handler in ABC organization. One day, she got a complaint about email hacking incident from one of the employees of the organization. As a part of

incident handling and response process, she must follow many recovery steps in order to recover from incident impact to maintain business continuity.

What is the first step that she must do to secure employee account?

Options:

A.

Restore the email services and change the password

B.

Enable two-factor authentication

C.

Enable scanning of links and attachments in all the emails

D.

Disabling automatic file sharing between the systems

Buy Now
Questions 12

Which of the following is a volatile evidence collecting tool?

Options:

A.

Netstat

B.

HashTool

C.

FTK Images

D.

ProDiscover Forensics

Buy Now
Questions 13

An IT security analyst at a logistics firm is alerted to unusual outbound traffic originating from an employee’s mobile device connected to the corporate VPN. Antivirus scans fail to remove the malware, indicating persistence. The organization cannot afford further data leakage. Which action should the incident handler take next?

Options:

A.

Disable the SIM card.

B.

Switch the device to airplane mode.

C.

Perform a factory reset or reinstall the mobile OS.

D.

Restrict background app refresh for social apps.

Buy Now
Questions 14

A global manufacturing company detected unauthorized privilege escalation on one of its OT workstations connected to critical production systems. The IH & R team must respond without alerting the attacker or risking deletion of forensic artifacts. The attacker ' s persistence mechanisms and data exfiltration activity are not yet fully identified. The CISO instructs the team to implement a strategy that limits the threat ' s lateral movement without tipping off the adversary. Which of the following containment actions best aligns with this objective?

Options:

A.

Restore the system using the latest verified backup image.

B.

Initiate a system-wide shutdown to prevent any further compromise.

C.

Disable select services and maintain a low profile using passive monitoring.

D.

Notify all employees immediately to change their credentials across the domain.

Buy Now
Questions 15

Zoe, a security analyst at a multinational technology firm, is tasked with enhancing the organization ' s threat detection capabilities. To proactively understand potential attack vectors, she deploys a high-interaction honeypot within the company ' s demilitarized zone (DMZ). The honeypot mimics critical systems, exposing deliberate but non-harmful vulnerabilities to simulate a real target environment. Zoe integrates this setup with intrusion detection systems and begins monitoring the logs for connection attempts, exploit patterns, and lateral movement techniques. Over the next few days, she observes multiple access attempts, port scans, and unauthorized login trials from various IP addresses, which she documents to identify trends in attacker behavior. What is the main purpose of Zoe ' s activity?

Options:

A.

Preventing malware execution using sandboxing

B.

Blocking DDoS traffic through ACL rules

C.

Deceiving attackers to study their behavior

D.

Testing the organization ' s backup and recovery systems

Buy Now
Questions 16

An AWS user notices unusual activity in their EC2 instances, including unexpected outbound traffic. When suspecting a security compromise, what is the most effective immediate step to take to contain the incident?

Options:

A.

Increase logging levels and monitor traffic for anomalies.

B.

Terminate all affected EC2 instances.

C.

Reboot the affected instances to disrupt unauthorized processes.

D.

Snapshot the affected instances for forensic analysis and then isolate them using network ACLs.

Buy Now
Questions 17

NovoMed discovers encrypted data transfers of drug research and participant data to an unknown location and receives an extortion-like message implying the formula may be released. What is the most prudent course of action?

Options:

A.

Immediately recall the drug from the market.

B.

Publicly announce the breach warning competitors and authorities.

C.

Negotiate with the attackers discreetly to buy time and retrieve data.

D.

Engage local law enforcement and international cybercrime agencies to trace the transfer’s origins.

Buy Now
Questions 18

A regional healthcare provider leveraging a platform-as-a-service (PaaS) cloud model detects suspicious activity involving unauthorized access to patient records. During the investigation, the incident response team attempts to retrieve system logs from virtual machines used during the breach. However, they realize that crucial log files are unavailable, as the short-lived instances were automatically terminated shortly after the event. This hampers their ability to reconstruct a complete activity trail and trace the attacker ' s movements. Which core cloud forensic challenge does this situation most likely reflect?

Options:

A.

Limited log access from containerized workloads.

B.

Metadata misalignment resulting from inconsistent log normalization.

C.

Evaporation of logs due to volatile storage.

D.

Log encryption hindered by poor key management practices.

Buy Now
Questions 19

BetaCorp, a multinational corporation, identified an employee selling company secrets to competitors. BetaCorp wants to prevent such incidents in the future. Which action will be most effective?

Options:

A.

Conduct surprise bag checks at office exits.

B.

Implement an Employee Monitoring Tool to track digital activities.

C.

Regularly change office locations of employees.

D.

Introduce random polygraph tests.

Buy Now
Questions 20

FinFusion, a leading finance firm, discovered a slow leak of financial data over several months. Surprisingly, the leak was attributed to a high-ranking executive who was selling data to competitors. Keen on avoiding future breaches, what should be FinFusion ' s foremost action?

Options:

A.

Use advanced Employee Monitoring Tools that offer real-time threat alerts.

B.

Limit executive access to sensitive databases.

C.

Require weekly reports from executives on their data access and usage.

D.

Install security cameras in executive offices.

Buy Now
Questions 21

Which of the following details are included in the evidence bags?

Options:

A.

Error messages that contain sensitive information and files containing passworos

B.

Software version information and web application source code

C.

Sensitive cirectories, personal, and organizational email adcress

D.

Date and time of seizure, exhibit number, anc name of incident responder

Buy Now
Questions 22

In an international bank, the IT security team identified unusual network traffic indicating a potential malware infection. Further analysis revealed that several high-value transaction servers were communicating with an external command-and-control server. The team needs to decide the immediate action to best handle this malware incident triage. What should they prioritize to mitigate the threat and safeguard sensitive data effectively?

Options:

A.

Initiate a controlled shutdown of the transaction servers to preserve their current state.

B.

Immediately update antivirus signatures on all network devices and servers.

C.

Perform a memory dump of the affected servers for in-depth forensic analysis.

D.

Disconnect the affected servers from the network to prevent further data exfiltration.

Buy Now
Questions 23

Ikeo Corp, hired an incident response team to assess the enterprise security. As part of the incident handling and response process, the IR team is reviewing the current security policies implemented by the enterprise. The IR team finds that employees of the organization do not have any restrictions on Internet access: they are allowed to visit any site, download any application, and access a computer or network from a remote location. Considering this as the main security threat, the IR team plans to change this policy as it can be easily exploited by attackers. Which of the following security policies is the IR team planning to modify?

Options:

A.

Paranoid policy

B.

Prudent policy

C.

Promiscuous policy

D.

Permissive policy

Buy Now
Questions 24

Which of the following terms refers to the personnel that the incident handling and response (IH & R) team must contact to report the incident and obtain the necessary permissions?

Options:

A.

Civil litigation

B.

Point of contact

C.

Criminal referral

D.

Ticketing

Buy Now
Questions 25

NeuroNet, a pioneer in neural network research, was alarmed when it identified an insider siphoning off critical research data. Post-investigation, it was determined that the employee was disgruntled because of recent management decisions. To minimize such threats in the future, which measure should NeuroNet prioritize?

Options:

A.

Implement a robust Data Loss Prevention (DLP) system.

B.

Conduct monthly one-on-one sessions between employees and HR.

C.

Introduce an anonymous feedback system for employees.

D.

Restrict all employees from accessing research data unless explicitly authorized.

Buy Now
Questions 26

After a recent cloud migration, AeroFlights, an airline company, spotted unauthorized data access. Preliminary checks hinted at malware that used cloud resources to spread, impacting flight schedules. Equipped with a cloud-specific security tool and a real-time scheduling monitor, what should be the primary action?

Options:

A.

Temporarily halt all flight operations until the issue is resolved.

B.

Deploy the cloud security tool to identify and counteract the malware.

C.

Notify passengers about possible delays and offer compensation.

D.

Monitor flight schedules in real-time to avoid potential disruptions.

Buy Now
Questions 27

A large multinational enterprise recently integrated a digital HR onboarding system to streamline applicant submissions and document collection. During a cybersecurity audit, it was revealed that attackers had set up a phishing site mimicking the official HR document submission portal. Several employees and new hires uploaded their resumes and downloaded pre-filled form templates, believing them to be legitimate. Upon opening the downloaded Word documents, the system silently connected to external servers and fetched additional template data without any user consent or visible macro execution warnings. This bypassed email gateway filters and endpoint antivirus tools, leading to lateral malware spread across systems used by HR, finance, and legal departments.

Digital forensic analysis showed that the documents did not contain visible scripts or macros but relied on hidden structural definitions to retrieve malicious payloads dynamically from attacker-controlled servers. Which of the following web-based malware distribution techniques best explains the observed behavior?

Options:

A.

Distribution of malware through remotely hosted RTF injection.

B.

Distribution of malware through spear-phishing emails that impersonate social media contacts.

C.

Distribution of malware through compromised browser extensions embedded in PDF rendering engines.

D.

Distribution of malware through peer-to-peer file propagation mechanisms within internal networks.

Buy Now
Questions 28

Drake is an incident handler in Dark CLoud Inc. He is intended to perform log analysis

in order to detect traces of malicious activities within the network infrastructure.

Which of the following tools Drake must employ in order to view logs in real time and

identify malware propagation within the network?

Options:

A.

Splunk

B.

HULK

C.

Hydra

D.

LOIC

Buy Now
Questions 29

Elena, a first responder at a multinational firm, receives multiple reports from employees claiming they were asked to update their payroll information through an email that appears to be from HR. The email includes a URL directing users to a login page identical to the company ' s intranet but hosted on an unfamiliar domain. Elena immediately informs the IH & R team, preserves the email headers, captures screenshots of the spoofed page, and blocks the domain at the network level. What type of email security incident is Elena handling?

Options:

A.

Email spamming

B.

Mail storm attack

C.

DNS cache poisoning

D.

Deceptive phishing attack

Buy Now
Questions 30

AlphaTech recently discovered signs of an advanced persistent threat (APT) in its infrastructure. The incident response team is trying to gather more information about the threat to form a comprehensive response strategy. While leveraging threat intelligence platforms, which of the following approaches would be most effective in gathering detailed and actionable insights about the APT?

Options:

A.

Searching for IOCs related to known APT campaigns and comparing them with observed patterns.

B.

Collaborating with industry peers to understand similar threats and observed TTPs.

C.

Obtaining historical data on common cyber threats to predict future movements.

D.

Gathering information from open-source forums and integrating it internally.

Buy Now
Questions 31

Eric is an incident responder and is working on developing incident-handling plans and procedures. As part of this process, he is performing an analysis on the organizational network to generate a report and develop policies based on the acquired results. Which of the following tools will help him in analyzing his network and the related traffic?

Options:

A.

Whois

B.

Burp Suite

C.

FaceNiff

D.

Wireshark

Buy Now
Questions 32

Olivia, a cybersecurity responder at a multinational firm, is alerted late at night by the NOC team about unusual latency and degraded performance across several critical applications hosted on the company’s internal servers. Upon initial inspection, she notices that the internal routers are experiencing an unusually high volume of ARP requests being broadcast across the network. The network bandwidth utilization has spiked, and multiple routers are reporting elevated CPU usage.

As she digs deeper into the diagnostics, Olivia finds that the NAT tables on edge routers are saturated with numerous entries coming from the same IP range within a short time frame. These entries appear to be initiating simultaneous connections to different ports across various endpoints. The firewall logs also show repeated attempts to access unused services, and the ISP reports an overflow of incoming requests from various geolocations.

Based on these symptoms, what should Olivia suspect?

Options:

A.

Rogue DHCP server activity

B.

Distributed DoS attack

C.

Data exfiltration

D.

Application vulnerability scanning

Buy Now
Questions 33

John is a professional hacker who is performing an attack on the target organization where he tries to redirect the connection between the IP address and its target server such that when the users type in the Internet address, it redirects them to a rogue website that resembles the original website. He tries this attack using cache poisoning technique. Identify the type of attack John is performing on the target organization.

Options:

A.

War driving

B.

Pharming

C.

Skimming

D.

Pretexting

Buy Now
Questions 34

Which of the following is NOT part of the static data collection process?

Options:

A.

Evidence oxa mi nation

B.

System preservation

C.

Password protection

D.

Evidence acquisition

Buy Now
Questions 35

A multinational SaaS provider detects a major security breach involving unauthorized access to customer billing data in its EU and APAC servers. After triage and legal review, the IH & R team confirms data exfiltration impacting regulated regions. In response, the CISO, with legal and compliance teams, initiates a structured communication protocol—informing affected clients, notifying data protection authorities under laws such as GDPR, and preparing media responses with public affairs. All communications are securely routed, reviewed for legal accuracy, and sent only with executive approval to mitigate risk and misinformation. What type of communication is emphasized in this scenario?

Options:

A.

Automated alert forwarding using SIEM-generated rules

B.

External communication intended for non-organizational entities

C.

Technical internal update focused on root cause analysis

D.

Containment communications shared during malware removal

Buy Now
Questions 36

The following steps describe the key activities in forensic readiness planning:

1. Train the staff to handle the incident and preserve the evidence

2. Create a special process for documenting the procedure

3. Identify the potential evidence required for an incident

4. Determine the source of the evidence

5. Establish a legal advisory board to guide the investigation process

6. Identify if the incident requires full or formal investigation

7. Establish a policy for securely handling and storing the collected evidence

8. Define a policy that determines the pathway to legally extract electronic evidence

with minimal disruption

Identify the correct sequence of steps involved in forensic readiness planning.

Options:

A.

2-- > 3-- > 1-- > 4-- > 6-- > 5-- > 7-- > 8

B.

3-- > 4-- > 8-- > 7-- > 6-- > 1-- > 2-- > 5

C.

3-- > 1-- > 4-- > 5-- > 8-- > 2-- > 6-- > 7

D.

1-- > 2-- > 3-- > 4-- > 5-- > 6-- > 7-- > 8

Buy Now
Questions 37

Jason is an incident handler dealing with malware incidents. He was asked to perform memory dump analysis in order to collect the information about the basic functionality of any program. As a part of his assignment, he needs to perform string search analysis to search for the malicious string that could determine harmful actions that a program

can perform. Which of the following string-searching tools Jason needs to use to do the intended task?

Options:

A.

PEView

B.

BinText

C.

Dependency Walker

D.

Process Explorer

Buy Now
Questions 38

Marley was asked by his incident handling and response (IH & R) team lead to collect volatile data such as system information and network information present in the

registries, cache, and RAM of victim’s system.

Identify the data acquisition method Marley must employ to collect volatile data.

Options:

A.

Validate data acquisition

B.

Static data acquisition

C.

Live data acquisition

D.

Remote data acquisition

Buy Now
Questions 39

Your company holds a large amount of customer PH. and you want to protect those data from theft or unauthorized modification. Among other actions, you classify and encrypt the data. In this process, which of the following OWASP security risks are you guarding against?

Options:

A.

Insecure deserialization

B.

Security misconfiguration

C.

Broken authentication

D.

Sensitive data exposure

Buy Now
Questions 40

OmegaTech was compromised by an insider who deliberately introduced vulnerabilities into its flagship product after being recruited by a rival company. OmegaTech wants to minimize such risks in the future. What should be its primary focus?

Options:

A.

Rotate job roles every six months.

B.

Introduce surprise loyalty tests.

C.

Implement a strict vetting process for every software release.

D.

Strengthen background checks and continually monitor employee behavior for anomalies.

Buy Now
Questions 41

Bonney’s system has been compromised by a gruesome malware.

What is the primary step that is advisable to Bonney in order to contain the malware

incident from spreading?

Options:

A.

Turn off the infected machine

B.

Leave it to the network administrators to handle

C.

Complaint to police in a formal way regarding the incident

D.

Call the legal department in the organization and inform about the incident

Buy Now
Questions 42

Sophia, a security analyst, notices that a sensitive folder on a file server was accessed during off-hours by an intern using authorized credentials. The access was not flagged because the intern ' s permissions had not been reviewed in months after their project ended. What process should have been enforced to avoid this insider threat?

Options:

A.

Data classification and encryption

B.

Account lockout policies

C.

Regular auditing of user access rights

D.

Surveillance camera monitoring

Buy Now
Questions 43

Which of the following is an attack that attempts to prevent the use of systems, networks, or applications by the intended users?

Options:

A.

Denial of service (DoS) attack

B.

Fraud and theft

C.

Unauthorized access

D.

Malicious code or insider threat attack

Buy Now
Questions 44

After experiencing a large-scale distributed denial-of-service (DDoS) attack that caused service outages, a national telecom provider recovered its web platform. The IH & R team must now implement post-recovery measures to enhance resilience against future DDoS attempts. Which action would be most effective?

Options:

A.

Remove antivirus to speed up application response

B.

Configure a CDN and implement blackhole routing

C.

Add guest user accounts for remote diagnostics

D.

Increase FTP access for easier maintenance

Buy Now
Questions 45

Joseph is an incident handling and response (IH & R) team lead in Toro Network Solutions Company. As a part of IH & R process, Joseph alerted the service providers,

developers, and manufacturers about the affected resources.

Identify the stage of IH & R process Joseph is currently in.

Options:

A.

Eradication

B.

Containment

C.

Incident triage

D.

Recovery

Buy Now
Questions 46

SafePay, an online payment portal, recently introduced an advanced search feature allowing users to search for their transaction history. A week later, an alarming number of users reported unauthorized transactions. Investigation showed that attackers were using advanced search strings, exploiting a previously unidentified vulnerability. What is SafePay ' s best immediate action?

Options:

A.

Implement multi-factor authentication for all user accounts.

B.

Disable the advanced search feature and revert to the older version.

C.

Increase the encryption level of user data stored in databases.

D.

Require users to re-authenticate before accessing the advanced search feature.

Buy Now
Questions 47

At a major healthcare provider, several staff members received emails impersonating the HR department, requesting them to update their personal information. When attempting to report the suspicious activity, employees used their regular email accounts. Unfortunately, their reports were overlooked because of internal email filtering and delays, which hampered the security team ' s response efforts.

Recognizing the flaw, the incident response team introduced alternative reporting methods that did not rely on the email system. They established a direct VoIP line and an SMS-based alert mechanism that employees could use to quickly escalate suspicious email activity without delay. These measures helped the team receive real-time alerts even when the mail system was under attack or unavailable. Which preparatory step was implemented by the team to ensure more reliable threat reporting?

Options:

A.

Establishing out-of-band communication

B.

Creating backup archives

C.

Training on phishing indicators

D.

Email content filtering

Buy Now
Questions 48

Which one of the following is Inappropriate Usage Incidents?

Options:

A.

Insider Threat

B.

Reconnaissance Attack

C.

Access Control Attack

D.

Denial of Service Attack

Buy Now
Questions 49

After a recent email attack, Harry is analyzing the incident to obtain important information related to the incident. While investigating the incident, he is trying to

extract information such as sender identity, mail server, sender’s IP address, location, and so on.

Which of the following tools Harry must use to perform this task?

Options:

A.

Clamwin

B.

Logly

C.

Yesware

D.

Sharp

Buy Now
Questions 50

SpaceTech Innovations, specializing in space exploration software, encountered malware that camouflaged itself within proprietary algorithms. This stealthy malware intermittently transmitted blueprints to an unknown receiver. With a state-of-the-art code analyzer and a network traffic analyzer at hand, what’s the ideal first step?

Options:

A.

Run the code analyzer to detect and remove the hidden malware.

B.

Use the network traffic analyzer to pinpoint and halt the blueprint transmission.

C.

Inform partners and stakeholders of potential data leaks.

D.

Update all proprietary software hoping to overwrite the malware.

Buy Now
Questions 51

Ethan, part of the IH & R team, receives a phishing email targeting employees with a link to reset passwords. He hovers over the link and notices a discrepancy between the visible URL and the hyperlink. He cross-verifies the sender’s email structure and subject tone to detect further red flags. Which phishing detection approach is Ethan using?

Options:

A.

Content encoding validation

B.

Firewall signature matching

C.

URL shortening detection

D.

Manual phishing email verification

Buy Now
Questions 52

Ethan, an incident handler, reviews traffic logs showing abnormal connections from internal devices to high-risk external domains. He traces these back to a misconfigured IoT device using outdated firmware. What kind of indicator was key in identifying the issue?

Options:

A.

Large ICMP payloads

B.

Unauthorized ARP broadcast

C.

Suspicious outbound connections

D.

Incorrect DNS caching

Buy Now
Questions 53

Sam. an employee of a multinational company, sends emails to third-party organizations with a spoofed email address of his organization. How can you categorize this type of incident?

Options:

A.

Network intrusion incident

B.

Inappropriate usage incident

C.

Unauthorized access incident.

D.

Denial-of-service incicent

Buy Now
Questions 54

A global logistics company recently experienced a targeted ransomware attack that began through a deceptive email campaign. The malicious software encrypted critical files on several systems tied to dispatch and finance operations. Fortunately, the organization had deployed an advanced security setup that could swiftly recognize abnormal behaviors, isolate compromised devices, and alert both the technical support desk and the security operations team.

In parallel, system logs were captured and analyzed using integrated threat detection tools, and a detailed file was automatically created with relevant data such as affected assets, user activity, and potential entry points. Security analysts then assessed the case, adapted containment measures based on the affected departments, and continued tracking suspicious activity across the network. Additional countermeasures were executed based on a mix of pre-approved workflows and expert decisions, ensuring the issue was contained without major disruption. Which combination of technologies is MOST likely supporting this workflow?

Options:

A.

A manual log management tool integrated with a physical ticketing desk for report creation

B.

A legacy antivirus solution configured to detect known malware only

C.

A cloud storage backup system with no direct link to detection or containment mechanisms

D.

A coordinated system combining incident response automation with orchestration capabilities

Buy Now
Questions 55

John, a professional hacker, is attacking an organization, where he is trying to destroy the connectivity between an AP and client to make the target unavailable to other

wireless devices.

Which of the following attacks is John performing in this case?

Options:

A.

Routing attack

B.

EAP failure

C.

Disassociation attack

D.

Denial-of-service

Buy Now
Questions 56

Malicious downloads that result from malicious office documents being manipulated are caused by which of the following?

Options:

A.

Clickjacking

B.

Impersonation

C.

Registry key manipulation

D.

Macro abuse

Buy Now
Questions 57

The cybersecurity response team at a global enterprise receives an alert from an employee regarding a suspicious email that appears to be from a senior executive. During the investigation, the team analyzes the email header and notices that the sending IP address originates from a foreign country that has no affiliation with the organization. A WHOIS lookup confirms that the IP is registered under an unknown entity. What key element helped identify the suspicious activity?

Options:

A.

Bounce-back analysis

B.

Spam filter logs

C.

DKIM verification

D.

Originating IP trace

Buy Now
Questions 58

Nervous Nat often sends emails with screenshots of what he thinks are serious incidents, but they always turn out to be false positives. Today, he sends another screenshot, suspecting a nation-state attack. As usual, you go through your list of questions, check your resources for information to determine whether the screenshot shows a real attack, and determine the condition of your network. Which step of IR did you just perform?

Options:

A.

Recovery

B.

Preparation

C.

Remediation

D.

Detection anc analysis (or identification)

Buy Now
Questions 59

Alexis works as an incident responder at XYZ organization. She was asked to identify and attribute the actors behind an attack that occurred recently. For this purpose, she is performing a type of threat attribution that deals with the identification of a specific person, society, or country sponsoring a well-planned and executed intrusion or attack on its target. Which of the following types of threat attributions is Alexis performing?

Options:

A.

Campaign attribution

B.

True attribution

C.

Nation-state attribution

D.

Intrusion set attribution

Buy Now
Questions 60

Rose is an incident-handling person and she is responsible for detecting and eliminating

any kind of scanning attempts over the network by any malicious threat actors. Rose

uses Wireshark tool to sniff the network and detect any malicious activities going on.

Which of the following Wireshark filters can be used by her to detect TCP Xmas scan

attempt by the attacker?

Options:

A.

tcp.dstport==7

B.

tcp.flags==0X000

C.

tcp.flags.reset==1

D.

tcp.flags==0X029

Buy Now
Questions 61

After experiencing a large-scale distributed denial-of-service (DDoS) attack that caused service outages and degraded performance to its online subscriber portal, a national telecom provider was able to recover and restore its web platform. With customer trust on the line and concerns about similar future incidents, the organization ' s IH & R team has been tasked with implementing robust post-recovery measures that enhance the resilience of web services against traffic-based disruptions. The team is evaluating several options to maintain service availability while mitigating the potential impact of recurring DDoS attempts. Which of the following actions would be most effective in strengthening the provider ' s defenses as part of the recovery process?

Options:

A.

Remove antivirus to speed up application response.

B.

Configure a CDN and implement blackhole routing.

C.

Add guest user accounts for remote diagnostics.

D.

Increase FTP access for easier maintenance.

Buy Now
Questions 62

Sophia, an incident handler at a cloud hosting provider, is investigating reports of intermittent web server slowdowns and timeouts. Upon analyzing router logs, she finds an unusually high number of incomplete connection attempts, causing the server’s memory and CPU resources to spike. Suspecting a form of resource exhaustion attack, she applies a protective configuration to the router that allows it to validate connection requests before they reach the server. Soon after this change, the number of partial connections decreases, and the server regains stable performance. What was the purpose of this action?

Options:

A.

To scan for malicious payloads

B.

To prevent brute-force logins

C.

To block SYN flood attempts

D.

To monitor port scans

Buy Now
Questions 63

Miko was hired as an incident handler in XYZ company. His first task was to identify the PING sweep attempts inside the network. For this purpose, he used Wireshark to analyze the traffic. What filter did he use to identify ICMP ping sweep attempts?

Options:

A.

tcp.typc == icmp

B.

icrrip.lype == icmp

C.

icmp.type == 8 or icmp.type ==0

D.

udp.lype — 7

Buy Now
Questions 64

Which of the following is the BEST method to prevent email incidents?

Options:

A.

Installing antivirus rule updates

B.

Disabling HTML in email content fields

C.

Web proxy filtering

D.

End-user training

Buy Now
Questions 65

Aaron, a digital first responder, is dispatched to an R & D lab after a suspected insider data breach involving intellectual property theft. Upon entering the lab, he observes fingerprint smudges on a workstation keyboard, oily residue on a DVD near the printer, and an unplugged USB drive on the desk. He documents the position of each item, uses gloves and evidence tags, covers surfaces to prevent contamination, and restricts access to the area. Which best practice is Aaron demonstrating?

Options:

A.

Preserving trace-level physical indicators for attribution

B.

Isolating system peripherals for digital chain-of-custody

C.

Safeguarding volatile system state for RAM acquisition

D.

Capturing live session activity from open peripherals

Buy Now
Questions 66

SafeGuard Inc., a cloud storage company, identified attackers exploiting a Server-Side Request Forgery (SSRF) vulnerability, leading to internal network reconnaissance. Which measure should SafeGuard Inc. prioritize to mitigate this vulnerability?

Options:

A.

Disable unused application features and services.

B.

Implement a Content Security Policy (CSP).

C.

Increase monitoring and logging of application activities.

D.

Restrict outbound traffic from the application server.

Buy Now
Questions 67

Eric works as a system administrator in ABC organization. He granted privileged users with unlimited permissions to access the systems. These privileged users can misuse

their rights unintentionally or maliciously or attackers can trick them to perform malicious activities.

Which of the following guidelines helps incident handlers to eradicate insider attacks by privileged users?

Options:

A.

Do not use encryption methods to prevent administrators and privileged users from accessing backup tapes and sensitive information

B.

Do not control the access to administrators and privileged users

C.

Do not enable the default administrative accounts to ensure accountability

D.

Do not allow administrators to use unique accounts during the installation process

Buy Now
Questions 68

DeltaCorp, a global e-commerce company, received an email sent to the financial department claiming to be from the CEO, requesting an urgent transfer of funds. To determine the legitimacy of this potentially deceptive email, which of the following should be the primary focus of the investigation?

Options:

A.

Inspect the email headers for spoofing or sender IP irregularities.

B.

Contact the vendor mentioned in the email.

C.

Review past emails for similar language.

D.

Scan the email server for malware.

Buy Now
Questions 69

During a security audit, analysts identified unusual GET requests to a financial application where external resources were fetched using numeric IPs combined with unexpected trailing characters. These inputs were not properly filtered by the system, allowing external content to be processed and embedded in server responses. The issue was traced to a feature that dynamically loads input-specified content without strict validation. Which type of attack/technique is most likely being analyzed in this scenario?

Options:

A.

Hidden field manipulation exploiting weak client-side validation logic.

B.

Stored cross-site scripting targeting input validation vulnerabilities.

C.

Command injection via improperly sanitized backend shell interaction.

D.

Remote file inclusion using parameter-level URL obfuscation techniques.

Buy Now
Questions 70

Ross is an incident manager (IM) at an organization, and his team provides support to all users in the organization who are affected by threats or attacks. David, who is the organization ' s internal auditor, is also part of Ross ' s incident response team. Which of the following is David ' s responsibility?

Options:

A.

Configure information security controls.

B.

Identify and report security loopholes to the management for necessary action.

C.

Coordinate incident containment activities with the information security officer (ISO).

D.

Perform the- necessary action to block the network traffic from the suspectoc intruder.

Buy Now
Questions 71

Which of the following are malicious software programs that infect computers and corrupt or delete the data on them?

Options:

A.

Worms

B.

Trojans

C.

Spyware

D.

Virus

Buy Now
Questions 72

Which of the following is the ECIH phase that involves removing or eliminating the root cause of an incident and closing all attack vectors to prevent similar incidents in the future?

Options:

A.

Recovery

B.

Containment

C.

Eradication

D.

Vulnerability management phase

Buy Now
Questions 73

Logan, an incident handler, ensures the chain of custody is documented while handling backup media post-attack. The goal is to preserve evidence integrity while restoring critical systems. Which recovery principle is Logan adhering to?

Options:

A.

Forensic compliance

B.

Network segmentation

C.

Immutable infrastructure

D.

Enhanced authentication

Buy Now
Questions 74

Lena, a SOC analyst, observes a pattern of unusual login attempts originating from multiple foreign IP addresses tied to shared drive links circulating within the organization. These links were embedded in emails appearing to come from the HR department and marked with urgent subject lines. Upon deeper inspection, Lena finds multiple similar messages still pending in the mail server ' s delivery queue. To prevent widespread exposure, she takes immediate action to eliminate these messages before they reach employees ' inboxes. Which incident response action best describes Lena ' s action?

Options:

A.

Flagging login anomalies for correlation in the SIEM.

B.

Initiating forensic triage on suspicious attachments.

C.

Preemptively purging queued phishing emails from the server.

D.

Isolating compromised mailboxes from the email relay.

Buy Now
Questions 75

DigitalSoft, a major software development firm, recently discovered unauthorized access to its codebase. The culprit was a disgruntled employee who had been overlooked for a promotion. The company wants to prevent such insider threats in the future. What is the most effective measure it can implement?

Options:

A.

Implement mandatory password changes every 30 days.

B.

Implement a strict hierarchy where only senior employees have access to sensitive data.

C.

Use biometric authentication for accessing sensitive data.

D.

Conduct regular audits of user access and use behavior analytics.

Buy Now
Questions 76

Following a high-profile breach investigation at a multinational corporation, an incident handler is tasked with the critical role of preserving, packaging, and transporting digital evidence from a server believed to be compromised and utilized as part of a global botnet operation. The challenge lay not only in the technical complexities of the operation but also in adhering to stringent legal and procedural frameworks to ensure the evidence remained admissible in court. The server, containing potentially millions of records of illicit transactions, represented a key piece of the puzzle in understanding the breadth of the breach. The incident handler had to navigate through multiple layers of security protocols to access the server, all while ensuring that the evidence was handled in a manner that prevented any form of tampering or degradation during the collection, packaging, and transport process. Which of the following options ensures the highest level of evidence integrity during its transport?

Options:

A.

On-site encryption of the server ' s data, followed by its upload to a secure cloud storage solution, with the entire process meticulously documented for future verification.

B.

Transferring the server data onto a newly secured drive using a write blocker, placing it within a tamper-evident bag, and employing GPS tracking for the transport process.

C.

Creating a forensic image of the server ' s drives, conducting verification of the image hashes, storing these images on encrypted drives, and completing a detailed log of the transport procedure.

D.

Encasing the server in anti-static packaging, labeling it meticulously with the chain-of-custody documentation, and securing it in a locked container for transportation.

Buy Now
Questions 77

Elena, a first responder at a multinational firm, receives multiple reports from employees claiming they were asked to update their payroll information through an email that appears to be from HR. The email includes a URL directing users to a login page identical to the company’s intranet but hosted on an unfamiliar domain. Elena immediately informs the IH & R team, preserves the email headers, captures screenshots of the spoofed page, and blocks the domain at the network level. What type of email security incident is Elena handling?

Options:

A.

DNS cache poisoning

B.

Mail storm attack

C.

Email spamming

D.

Deceptive phishing attack

Buy Now
Questions 78

Zaimasoft, a prominent IT organization, was attacked by perpetrators who directly targeted the hardware and caused irreversible damage to the hardware. In result, replacing or reinstalling the hardware was the only solution.

Identify the type of denial-of-service attack performed on Zaimasoft.

Options:

A.

ddos

B.

DoS

C.

PDoS

D.

DRDoS

Buy Now
Questions 79

QualTech Solutions is a leading security services enterprise. Dickson works as an incident responder with this firm. He is performing vulnerability assessment to identify

the security problems in the network, using automated tools to identify the hosts, services, and vulnerabilities present in the enterprise network.

Based on the above scenario, identify the type of vulnerability assessment performed by Dickson.

Options:

A.

Internal assessment

B.

Active assessment

C.

Passive assessment

D.

External assessment

Buy Now
Questions 80

Ren is assigned to handle a security incident of an organization. He is tasked with forensics investigation to find the evidence needed by the management. Which of the following steps falls under the investigation phase of the computer forensics investigation process?

Options:

A.

Secure the evidence

B.

Risk assessment

C.

Setup a computer forensics lab

D.

Evidence assessment

Buy Now
Questions 81

Which of the following best describes an email issued as an attack medium, in which several messages are sent to a mailbox to cause overflow?

Options:

A.

Email-bombing

B.

Masquerading

C.

Spoofing

D.

Smurf attack

Buy Now
Questions 82

A global retail enterprise operating across multiple e-commerce platforms and physical locations has recently been targeted by a well-orchestrated cyberattack that disrupted transaction processing systems and led to a temporary shutdown of online services. Following the incident, customer confidence dropped, and the board demanded immediate corrective and preventive measures to strengthen cybersecurity resilience. The Chief Information Security Officer (CISO) directed the incident response team to establish a forward-looking approach that not only mitigates such incidents but also ensures that all stakeholders are trained in advance. This includes defining clear roles and responsibilities, creating and training a dedicated response team, conducting simul-ation exercises, reviewing existing IR tools, auditing organizational assets, and developing a comprehensive set of policies and playbooks. Which phase of the IH & R process should the organization focus on to achieve this?

Options:

Buy Now
Questions 83

A multinational corporation with a diverse computing environment experiences a sophisticated malware attack targeting its endpoint devices. The malware is designed to evade traditional antivirus solutions and establish a persistent backdoor for data exfiltration. This incident underscores the complex landscape of endpoint security and the evolving threat vectors. In this context, what is the most critical reason for establishing a robust endpoint security incident handling and response capability?

Options:

A.

To facilitate real-time threat intelligence sharing across the industry.

B.

To ensure compliance with international data protection regulations.

C.

To mitigate financial losses associated with data breaches and system downtime.

D.

To enable rapid containment and eradication of threats to maintain business continuity.

Buy Now
Questions 84

EduTech University noticed unauthorized access to student records, including academic and financial details. As the semester ' s examinations approached, there were concerns about potential leaks or manipulations of question papers. In this complex digital scenario, what is the optimal step for the first responder?

Options:

A.

Capture logs from the academic servers, focusing on recent access and modifications.

B.

Collaborate with faculty to develop alternative exam papers as a backup.

C.

Isolate the academic systems, ensuring the integrity of upcoming examinations.

D.

Notify students and staff, urging them to change their university portal passwords.

Buy Now
Questions 85

During routine checks, EduSoft, an educational software provider, identified malware within their digital examination tools. This malware not only provided answers to students but mined personal data. With a digital forensic tool and an encryption protocol tool, what ' s the ideal primary action?

Options:

A.

Disable the examination tool until further notice.

B.

Alert educational institutions about the compromised software.

C.

Use the forensic tool to ascertain the malware ' s source and method of operation.

D.

Deploy the encryption tool to safeguard students ' data.

Buy Now
Questions 86

Which of the following is a technique used by attackers to make a message difficult to understand through the use of ambiguous language?

Options:

A.

Steganography

B.

Spoofing

C.

Encryption

D.

Obfuscation

Buy Now
Questions 87

Following an internal audit at a mid-sized software development firm, it was discovered that several employees had been sharing system login credentials using personal messaging applications that were not approved by the organization. The audit further revealed that no structured guidance, awareness training, or acceptable usage policies had been provided regarding how and where confidential organizational information should be transmitted. Which of the following preparation steps would have most effectively prevented this situation?

Options:

A.

Provide awareness sessions on identifying unauthorized surveillance tools in secure areas.

B.

Schedule recurring data backups to secondary storage locations for disaster recovery.

C.

Establish defined protocols for appropriate digital channels when handling sensitive internal content.

D.

Deploy deception systems that simulate internal resources to lure potential insider threats.

Buy Now
Questions 88

Eric works as a system administrator at ABC organization and previously granted several users with access privileges to the organizations systems with unlimited permissions. These privileged users could prospectively misuse their rights unintentionally, maliciously, or could be deceived by attackers that could trick them to perform malicious activities. Which of the following guidelines would help incident handlers eradicate insider attacks by privileged users?

Options:

A.

Do not allow administrators to use unique accounts during the installation process

B.

Do not enable default administrative accounts to ensure accountability

C.

Do not control the access to administrator ano privileged users

D.

Do not use encryption methods to prevent, administrators and privileged users from accessing backup tapes and sensitive information

Buy Now
Questions 89

NeuroNet, a pioneer in neural network research, identified an insider siphoning off critical research data. Post-investigation revealed employee dissatisfaction as the motive. To minimize such threats in the future, which measure should NeuroNet prioritize?

Options:

A.

Restrict all employees from accessing research data unless explicitly authorized.

B.

Conduct monthly one-on-one sessions between employees and HR.

C.

Implement a robust Data Loss Prevention (DLP) system.

D.

Introduce an anonymous feedback system for employees.

Buy Now
Questions 90

A user downloaded what appears to be genuine software. Unknown to her, when she installed the application, it executed code that provided an unauthorized remote attacker access to her computer. What type of malicious threat displays this characteristic?

Options:

A.

Backdoor

B.

Trojan

C.

Spyware

D.

Virus

Buy Now
Questions 91

A national research agency was recently subjected to a comprehensive cybersecurity compliance audit. During the audit, reviewers evaluated how the agency ' s incident response unit manages harmful code samples during investigations. The assessment revealed that team members often interacted with dangerous file payloads directly on enterprise-connected systems used for general operations. Furthermore, no precautionary renaming was applied to prevent accidental triggering, and sensitive materials were placed in areas accessible by non-specialized personnel. The auditors flagged these practices as severely noncompliant with safe sample processing protocols and recommended urgent changes to prevent operational fallout or accidental outbreaks. Which best practice for secure handling of malicious code was most clearly disregarded in this case?

Options:

A.

Storing malware samples with non-executable file extensions in isolated environments.

B.

Encrypting all malware sample files using symmetric encryption.

C.

Create vulnerability documentation for each malware sample to support threat profiling and archival.

D.

Tagging malware sample files with platform-specific behavior indicators for improved categorization.

Buy Now
Questions 92

QualTech Solutions is a leading security services enterprise. Dickson, who works as an incident responder with this firm, is performing a vulnerability assessment to identify the security problems in the network by using automated tools for identifying the hosts, services, and vulnerabilities in the enterprise network. In the above scenario, which of the following types of vulnerability assessment is Dickson performing?

Options:

A.

Active assessment

B.

External assessment

C.

Internal assessment

D.

Passive assessment

Buy Now
Questions 93

Which of the following is an Inappropriate usage incident?

Options:

A.

Access-control attack

B.

Reconnaissance attack

C.

Insider threat

D.

Denial-of-service attack

Buy Now
Questions 94

Your company sells SaaS, and your company itself is hosted in the cloud (using it as a PaaS). In case of a malware incident in your customer ' s database, who is responsible for eradicating the malicious software?

Options:

A.

Your company

B.

Building management

C.

The PaaS provider

D.

The customer

Buy Now
Questions 95

James is a professional hacker and is employed by an organization to exploit their cloud services. In order to achieve this, James created anonymous access to the cloud services to carry out various attacks such as password and key cracking, hosting malicious data, and DDoS attacks. Which of the following threats is he posing to the cloud platform?

Options:

A.

Insecure interface and APIs

B.

Data breach/loss

C.

Insufficient duo diligence

D.

Abuse end nefarious use of cloud services

Buy Now
Questions 96

After experiencing a web application attack, HealthFirst, a health records management company, traced the breach to an insecure Direct Object Reference (IDOR) vulnerability. They seek to patch this vulnerability and fortify their application against future incidents. What should be their primary action?

Options:

A.

Conduct regular penetration testing on the application.

B.

Introduce a Web Application Firewall (WAF) with default rules.

C.

Implement role-based access controls (RBAC) for data access.

D.

Encrypt all data at rest and in transit.

Buy Now
Questions 97

A network administrator reviews firewall and IDS/IPS configurations to ensure logging is properly set, updates logging to centralize alerts from all network devices, and confirms that all response team members know their responsibilities. Which preparatory activity is he performing?

Options:

A.

Hardening backup systems.

B.

Coordinating external law enforcement.

C.

Conducting vulnerability scanning.

D.

Ensuring network monitoring readiness.

Buy Now
Questions 98

An IT security analyst at a logistics firm is alerted to unusual outbound traffic originating from an employee ' s mobile device, which is actively connected to the corporate VPN. Initial investigation confirms the presence of malware. Although antivirus scans are run multiple times, the malicious activity continues, suggesting the infection is deeply embedded or resistant to standard removal methods. The organization cannot afford further data leakage or operational disruptions caused by this device. Which action should the incident handler take next to ensure complete removal of the persistent threat and restore device integrity?

Options:

A.

Disable the SIM card.

B.

Switch the device to airplane mode.

C.

Perform a factory reset or reinstall the mobile OS.

D.

Restrict background app refresh for social apps.

Buy Now
Questions 99

During an internal audit following a surge in unauthorized financial transactions, a multinational investment firm ' s IR team uncovers evidence of an orchestrated campaign targeting senior staff. The attackers had pieced together fragments of sensitive data by mining executive digital footprints, reviewing online publications, and analyzing company-related mentions on external platforms. Later, they engaged directly with employees under fabricated personas, conducting scripted interviews to extract missing identifiers. With the assembled profile data, the adversaries submitted diversion requests for financial correspondence and used these to impersonate executives and execute fraudulent transfers. Forensic analysis revealed no signs of malware infection or system-level compromise. Which technique best aligns with the adversary ' s method of obtaining the initial sensitive information?

Options:

A.

Phishing through spoofed emails embedded with malicious macros targeting employee laptops

B.

Social engineering using open-source intelligence followed by pretexting

C.

Pharming attack that redirected login traffic from internal systems to malicious replicas

D.

Skimming magnetic card data through modified payment devices in the company cafeteria

Buy Now
Questions 100

A mid-sized healthcare organization undergoing digital modernization is working toward ISO/IEC 27001 certification. During a readiness review, the CISO identifies gaps: staff lack clear channels to raise concerns about system weaknesses, outcome tracking after adverse events is inconsistent, and there is no formalized way to assess what went right or wrong following disruptions. To comply with ISO/IEC 27001 Annex A.16, which action should be prioritized?

Options:

A.

Conduct tabletop exercises to simulate insider threat scenarios.

B.

Implement a centralized SIEM dashboard for real-time alerting.

C.

Define and implement structured procedures for flaw escalation and integrating post-incident response knowledge.

D.

Deploy EDR agents across endpoints for automatic quarantine.

Buy Now
Questions 101

Daniel, a SOC analyst, detects multiple incoming TCP requests to the organization’s mail server from different IPs. However, none of the requests complete the handshake. He suspects a potential attempt to exhaust server resources and confirms this with netstat logs. Which type of protocol-level incident is Daniel identifying?

Options:

A.

TCP session hijacking

B.

UDP reflection

C.

DNS cache poisoning

D.

SYN flood attack

Buy Now
Questions 102

Liam, a certified digital forensics technician, is dispatched to a corporate office after a suspected insider breach involving unauthorized data exfiltration. Upon arrival, he immediately begins organizing the collection process. He carefully labels each seized device—including laptops, USB drives, and smartphones—with exhibit tags that include his initials, the date and time of seizure, and a unique exhibit number. For each item, he records detailed descriptions in an official evidence logbook, noting the device make, serial number, condition, and where it was found. He also ensures that all items are photographed in their original positions before being moved. As he prepares them for secure packaging and transport, Liam initials each log entry and keeps a running record of who will take charge of the evidence next. Which aspect of evidence handling is Liam demonstrating?

Options:

A.

Installing endpoint detection software

B.

Imaging volatile memory

C.

Executing malware removal procedures

D.

Creating a chain of custody record

Buy Now
Questions 103

David, an incident responder, investigates an email-based breach where the CFO ' s email account was compromised and used to send invoice modification requests to vendors. Logs reveal the attacker accessed the account using valid credentials after the CFO clicked on a fake Microsoft 365 login prompt sent via email. Which technique did the attacker most likely use?

Options:

A.

Mail bombing

B.

Pharming

C.

Spimming

D.

Spear phishing

Buy Now
Questions 104

Which of the following is not a countermeasure to eradicate inappropriate usage

incidents?

Options:

A.

Avoid VPN and other secure network channels

B.

Register the user activity logs and keep monitoring them regularly

C.

Install firewall and IDS/IPS to block services that violate the organization’s policy

D.

Always store the sensitive data in far located servers and restrict its access

Buy Now
Questions 105

Francis is an incident handler and security expert. He works at MorisonTech Solutions based in Sydney, Australia. He was assigned a task to detect phishing/spam mails for the client organization.

Which of the following tools can assist Francis to perform the required task?

Options:

A.

Netcraft

B.

Nessus

C.

BTCrack

D.

Cain and Abel

Buy Now
Questions 106

Tara, a certified first responder in a digital forensics team, is dispatched to investigate a suspected insider attack targeting a critical workstation in the finance department. Upon arriving at the scene, she takes a methodical approach: she begins labeling all connected network cables, photographs the back panel of the workstation, documents cable connections, and records the power status of each connected device, including peripherals like external drives and monitors. She also notes the orientation and placement of equipment on the desk and the surrounding environment.

These actions are part of her protocol to ensure that, if the devices need to be moved for forensic analysis, investigators can accurately replicate the system’s physical setup at the time of the incident. What is Tara aiming to achieve with these actions?

Options:

A.

Create a physical reconstruction reference

B.

Maintain the continuity of system uptime

C.

Capture device logs in real-time

D.

Execute evidence integrity hashing

Buy Now
Exam Code: 212-89
Exam Name: EC Council Certified Incident Handler (ECIH v3)
Last Update: Oct 6, 2026
Questions: 356
212-89 pdf

212-89 PDF

$25.5  $84.99
212-89 Engine

212-89 Testing Engine

$30  $99.99
212-89 PDF + Engine

212-89 PDF + Testing Engine

$40.5  $134.99