[Mar 14, 2024] Uplift Your 212-89 Exam Marks With The Help of 212-89 Dumps [Q113-Q137]

Share

[Mar 14, 2024] Uplift Your 212-89 Exam Marks With The Help of 212-89 Dumps

Use EC-COUNCIL 212-89 Dumps To Succeed Instantly in 212-89 Exam

NEW QUESTION # 113
Contingency planning enables organizations to develop and maintain effective methods to handle emergencies. Every organization will have its own specific requirements that the planning should address. There are five major components of the IT contingency plan, namely supporting information, notification activation, recovery and reconstitution and plan appendices. What is the main purpose of the reconstitution plan?

  • A. To define the notification procedures, damage assessments and offers the plan activation
  • B. To provide the introduction and detailed concept of the contingency plan
  • C. To restore the original site, tests systems to prevent the incident and terminates operations
  • D. To provide a sequence of recovery activities with the help of recovery procedures

Answer: C


NEW QUESTION # 114
Based on the some statistics; what is the typical number one top incident?

  • A. Malware
  • B. Phishing
  • C. Un-authorized access
  • D. Policy violation

Answer: B


NEW QUESTION # 115
In which of the following phases of the incident handling and response (IH&R) process is the identified security incidents analyzed, validated, categorized, and prioritized?

  • A. Notification
  • B. Incident triage
  • C. Containment
  • D. Incident recording and assignment

Answer: B


NEW QUESTION # 116
An organization faced an information security incident where a disgruntled employee passed sensitive access
control information to a competitor. The organization's incident response manager, upon investigation, found
that the incident must be handled within a few hours on the same day to maintain business continuity and
market competitiveness. How would you categorize such information security incident?

  • A. High level incident
  • B. Middle level incident
  • C. Ultra-High level incident
  • D. Low level incident

Answer: A


NEW QUESTION # 117
A malware code that infects computer files, corrupts or deletes the data in them and requires a host file to
propagate is called:

  • A. Virus
  • B. RootKit
  • C. Worm
  • D. Trojan

Answer: A


NEW QUESTION # 118
In the cloud environment, an authorized security professional executes approved sanitation procedures using approved utilities to permanently remove data spilled from contaminated information systems and applications in the cloud.
This is an example of which of the following?

  • A. Cloud computing
  • B. Cloud broker
  • C. Cloud eradication
  • D. Cloud auditor

Answer: D


NEW QUESTION # 119
The state of incident response preparedness that enables an organization to maximize its potential to use
digital evidence while minimizing the cost of an investigation is called:

  • A. Computer Forensics
  • B. Digital Forensic Analysis
  • C. Forensic Readiness
  • D. Digital Forensic Policy

Answer: C


NEW QUESTION # 120
James has been appointed as an incident handing and response (IH&R) team lead and was assigned to build an IH&R plan and his own team in the company. Identify the IH&R process step James is currently working on.

  • A. Eradication
  • B. Notification
  • C. Preparation
  • D. Recovery

Answer: C


NEW QUESTION # 121
Alice is an incident handler and she has been informed by her lead that the data on affected systems must be backed up so that it can be retrieved if it is damaged during the incident response process. She was also told that the system backup can also be used for further investigation of the incident.
In which of the following stages of the incident handling and response (IH&R) process does Alice need to do a complete backup of the infected system?

  • A. Eradication
  • B. Containment
  • C. Incident triage
  • D. Incident recording

Answer: D


NEW QUESTION # 122
Which of the following tools helps incident responders effectively contain a potential cloud security incident and gather required forensic evidence?

  • A. Qualys Cloud Platform
  • B. Cloud Passage Halo
  • C. Cloud Passage Quarantine
  • D. Alert Logic

Answer: B


NEW QUESTION # 123
During the vulnerability assessment phase, the incident responders perform various steps as below:
1. Run vulnerability scans using tools
2. Identify and prioritize vulnerabilities
3. Examine and evaluate physical security
4. Perform OSINT information gathering to validate the vulnerabilities
5. Apply business and technology context to scanner results
6. Check for misconfigurations and human errors
7. Create a vulnerability scan report
Identify the correct sequence of vulnerability assessment steps performed by the incident responders.

  • A. 3-->6-->1->2->5->4-->7
  • B. 4-->1-->2->3->6->5-->7
  • C. 1-->3-->2->4->5->6-->7
  • D. 2-->1-->4->7->5->6-->3

Answer: A


NEW QUESTION # 124
A self-replicating malicious code that does not alter files but resides in active memory and duplicates itself,
spreads through the infected network automatically and takes advantage of file or information transport
features on the system to travel independently is called:

  • A. Worm
  • B. Virus
  • C. RootKit
  • D. Trojan

Answer: A


NEW QUESTION # 125
Zaimasoft, a prominent IT organization, was attacked by perpetrators who directly targeted the hardware and caused irreversible damage to the hardware. In result, replacing or reinstalling the hardware was the only solution. Identify the type of denial-of-service attack performed on Zaimasoft.

  • A. PDoS
  • B. DRDoS
  • C. DDoS
  • D. DoS

Answer: A


NEW QUESTION # 126
Which of the following is NOT a network forensic tool?

  • A. Tcpdump
  • B. Caps a Network Analyzer
  • C. Advanced NTFS Journaling Parser
  • D. Wire shark

Answer: C


NEW QUESTION # 127
Sam received an alert through an email monitoring tool indicating that their company was targeted by a phishing attack. After analyzing the incident, Sam identified that most of the targets of the attack are high-prof le executives of the company.
What type of phishing attack is this?

  • A. Pharming
  • B. Puddle phishing
  • C. Whaling
  • D. Spear phishing

Answer: C


NEW QUESTION # 128
Multiple component incidents consist of a combination of two or more attacks in a system. Which of the
following is not a multiple component incident?

  • A. An attacker using email with malicious code to infect internal workstation
  • B. An attacker redirecting user to a malicious website and infects his system with Trojan
  • C. An insider intentionally deleting files from a workstation
  • D. An attacker infecting a machine to launch a DDoS attack

Answer: C


NEW QUESTION # 129
An organization implemented an encoding technique to eradicate SQL injection attacks. In this technique, if a user submits a request using single-quote and some values, the encoding technique will convert it into numeric digits and letters ranging from "a" to "f". This prevents the user request from performing a SQL injection attempt on the web application.
Identify the encoding technique used by the organization.

  • A. Base 64 encoding
  • B. Unicode encoding
  • C. URL encoding
  • D. Hex encoding

Answer: D


NEW QUESTION # 130
Which of the following confidentiality attacks do attackers try to lure users by posing themselves as authorized AP by beaconing the WLAN's SSID?

  • A. Session hijacking
  • B. Evil twin AP
  • C. Masquerading
  • D. Honeypot AP

Answer: B


NEW QUESTION # 131
Clark, a professional hacker, successfully exploited the web application of a target organization by tampering the form and parameter values. In result, Clark gained access to the information assets of the organization. Identify the vulnerability in the web application exploited by the attacker.

  • A. Security misconfiguration
  • B. Broken access control
  • C. SQL injection
  • D. Sensitive data exposure

Answer: C


NEW QUESTION # 132
Which of the following options describes common characteristics of phishing emails?

  • A. No BCC fields
  • B. Written in French
  • C. Sent from friends or colleagues
  • D. Urgency, threatening, or promising subject lines

Answer: D


NEW QUESTION # 133
The goal of incident response is to handle the incident in a way that minimizes damage and reduces recovery time and cost. Which of the following does NOT constitute a goal of incident response?

  • A. Helping personal to recover quickly and efficiently from security incidents, minimizing loss or theft and disruption of services.
  • B. Using information gathered during incident handling to prepare for handling future incidents in a better way and to provide stronger protection for systems and data.
  • C. Dealing properly with legal issues that may arise during incidents.
  • D. Dealing with human resources department and various employee conflict behaviors.

Answer: D


NEW QUESTION # 134
Otis is an incident handler working in an organization called Delmont. Recently, the organization faced several setbacks in business, whereby its revenues are decreasing. Otis was asked to take charge and look into the matter. While auditing the enterprise security, he found traces of an attack through which proprietary information was stolen from the enterprise network and passed on to their competitors.
Which of the following information se cunty incidents did Delmont face?

  • A. Network and resource abuses
  • B. Espionage
  • C. Email-based abuse
  • D. Unauthorized access

Answer: B


NEW QUESTION # 135
An incident handler is analyzing email headers to uncover suspicious emails.
Which of the following tools would he/she use in order to accomplish this task?

  • A. SPAMfighter
  • B. Barracuda Email Security Gateway
  • C. Mx Toolbox
  • D. Go phish

Answer: C


NEW QUESTION # 136
The free, open source, TCP/IP protocol analyzer, sniffer and packet capturing utility standard across many
industries and educational institutions is known as:

  • A. Snort
  • B. nmap
  • C. Wireshark
  • D. Cain & Able

Answer: C


NEW QUESTION # 137
......

EC-COUNCIL Dumps - Learn How To Deal With The Exam Anxiety: https://www.vcedumps.com/212-89-examcollection.html

Ultimate Guide to 212-89 Dumps - Enhance Your Future Career Now: https://drive.google.com/open?id=1ZHkEuB4DuZdA1UhFKSJrcT__nVCUSLme