EC-COUNCIL EC Council Certified Incident Handler (ECIH v3) - 212-89 Exam Practice Test

John, a system administrator, has been with the company for several years and has access to sensitive company data. However, he has recently become disgruntled due to a denied promotion. He decides to seek revenge on the company by compromising its resources. Which type of insider threat does John represent?
Correct Answer: B Vote an answer
In which of the following types of insider threats an insider who is uneducated on potential security threats or simply bypasses general security procedures to meet workplace efficiency?
Correct Answer: B Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Nina, an experienced network incident responder working for a financial services firm, receives a series of high-priority alerts from Splunk Enterprise Security. The alerts are triggered by anomalous HTTP traffic patterns coming from a workstation within the internal network.
Specifically, the system flagged repeated attempts to access untrusted external UPLs, followed by the download of executable (.exe) files during non-business hours. Suspecting malicious activity, Nina begins investigating the web proxy logs and correlates them with endpoint detection logs. Her analysis confirms that the downloaded executables were not digitally signed and were flagged as malware by the organization's endpoint protection system shortly after execution. She also finds evidence that the malware attempted to establish outbound communication, likely for command-and-control (C2) purposes.
Nina immediately initiates containment by isolating the affected endpoint from the network She proceeds to perform a wider investigation using system wide and firewall logs to assess if the malware spread laterally or exfiltrated any sensitive data. What is the most likely cause of this incident?
Correct Answer: D Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which of the following is an attack that occurs when a malicious program causes a user's browser to perform an unwanted action on a trusted site for which the user is currently authenticated?
Correct Answer: B Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Malicious Micky has moved from the delivery stage to the exploitation stage of the kill chain. This malware wants to find and report to the command center any useful services on the system.
Which of the following recon attacks is the MOST LIKELY to provide this information?
Correct Answer: C Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
An international logistics firm runs a smart hub where IT systems interface with warehouse automation for tasks like sorting, routing, and conveyor coordination via programmable units and dashboards. A recent cyberattack, initiated through a compromised third-party remote maintenance tunnel, disrupted communication between backend scheduling applications and embedded automation units, leading to halted processing lines and shipment delays.
After isolating affected segments, removing malicious components, and restoring critical workflows, the recovery team begins validating the reinstated operations. While reviewing logs and configurations, they find excessive permissions granted between internal authentication servers and embedded automation modules. They also detect anomalies in authentication tokens used to verify communications across system interfaces, including unidentified fingerprints not matching the original rollout configuration. Which action should be prioritized as part of a secure restoration plan?
Correct Answer: B Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
As an Incident Handler, you are overseeing a large organization that heavily relies on email communication. Recent studies have revealed a substantial increase in phishing and malicious email attachment attacks, leading to heightened concerns over email security. Which of the following approaches would provide the most comprehensive protection against these emerging email security threats?
Correct Answer: D Vote an answer
During an email security incident, the Incident Handler & Response (IH&R) team in a certain organization decided to use Pretty Good Privacy (PGP) protocols via the Gpg4win tool to secure email communications. While creating a backup of keys, one of the IH&R team members forgot to make a note of the location of the backup files. What could be the potential impact of this mistake?
Correct Answer: D Vote an answer
Ikeo Corp, hired an incident response team to assess the enterprise security. As part of the incident handling and response process, the IR team is reviewing the current security policies implemented by the enterprise. The IR team finds that employees of the organization do not have any restrictions on Internet access: they are allowed to visit any site, download any application, and access a computer or network from a remote location. Considering this as the main security threat, the IR team plans to change this policy as it can be easily exploited by attackers. Which of the following security policies is the IR team planning to modify?
Correct Answer: D Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
An EC-Council Certified Incident Handler (ECIH) is dealing with a significant cyberattack on a multinational corporation's cloud infrastructure. During the initial investigation, the handler discovered a piece of malware embedded in a virtual machine. Which of the following should be the ECIH's first step in preserving, packaging, and transporting digital evidence?
Correct Answer: B Vote an answer