
Updated Jun-2024 212-89 Free Exam Files Downloaded Instantly
Practice Exams and Training Solutions for Certifications
The EC-Council Certified Incident Handler (ECIH v2) certification is a popular certification in the cybersecurity industry that is focused on preparing candidates to deal with cybersecurity incidents effectively. EC Council Certified Incident Handler (ECIH v3) certification is designed to equip candidates with the necessary skills to identify, respond to, and recover from cybersecurity incidents. EC Council Certified Incident Handler (ECIH v3) certification is vendor-neutral, which means that candidates are not tied to one particular technology or product, making it an invaluable certification for any cybersecurity professional.
NEW QUESTION # 90
Which of the following details are included in the evidence bags?
- A. Date and time of seizure, exhibit number, and name of incident responder
- B. Software version information and web application source code
- C. Sensitive directories, personal, and organizational email address
- D. Error messages that contain sensitive information and files containing passwords
Answer: A
NEW QUESTION # 91
Which of the following tools helps incident handlers to view the file system, retrieve deleted data, perform timeline analysis, web artifacts, etc., during an incident response process?
- A. nblslal
- B. Process Explorer
- C. Autopsy
- D. netstat
Answer: C
Explanation:
Autopsy is a digital forensics platform and graphical interface to The Sleuth Kit and other digital forensics tools. It is used by law enforcement, military, and corporate examiners to investigate what happened on a computer. Autopsy enables incident handlers to view the file system, retrieve deleted data, perform timeline analysis, and analyze web artifacts, among other functionalities. This tool is particularly useful during the incident response process for conducting in-depth investigations into the nature of a security incident, identifying the methods used by attackers, and recovering lost or compromised data.
References:The EC-Council's Certified Incident Handler (ECIH v3) program covers digital forensic tools and techniques, highlighting the capabilities of Autopsy for supporting comprehensive incident investigations and response activities.
Top of Form
NEW QUESTION # 92
Michael is an incident handler at CyberTech Solutions. He is performing detection and analysis of a cloud security incident. He is analyzing the file systems, slack spaces, and metadata of the storage units to find hidden malware and evidence of malice.
Identify the cloud security incident handled by Michael.
- A. Network-related incident
- B. Storage-related incident
- C. Server-related incident
- D. Application-related incident
Answer: B
NEW QUESTION # 93
Stanley works as an incident responder at a top MNC based in Singapore. He was asked to investigate a cybersecurity incident that recently occurred in the company. While investigating the incident, he collected evidence from the victim systems. He must present this evidence in a clear and comprehensible manner to the members of a jury so that the evidence clarifies the facts and further helps in obtaining an expert opinion on the incident to conf rm the investigation process.
In the above scenario, which of the following characteristics of the digital evidence did Stanley attempt to preserve?
- A. Completeness
- B. Believability
- C. Admissibility
- D. Authenticity
Answer: B
NEW QUESTION # 94
Which of the following is a risk assessment tool:
- A. Nmap
- B. Nessus
- C. CRAMM
- D. Wireshark
Answer: C
NEW QUESTION # 95
Stanley works as an incident responder at a top MNC based in Singapore. He was asked to investigate a cybersecurity incident that recently occurred in the company. While investigating the incident, he collected evidence from the victim systems. He must present this evidence in a clear and comprehensible manner to the members of a jury so that the evidence clarifies the facts and further helps in obtaining an expert opinion on the incident to confirm the investigation process. In the above scenario, which of the following characteristics of the digital evidence did Stanley attempt to preserve?
- A. Authenticity
- B. Completeness
- C. Believability
- D. Admissibility
Answer: A
NEW QUESTION # 96
Malicious downloads that result from malicious office documents being manipulated are caused by which of the following?
- A. Impersonation
- B. Macro abuse
- C. Clickjacking
- D. Registry key manipulation
Answer: B
Explanation:
Malicious downloads initiated through manipulated office documents typically involve macro abuse. Macros are scripts that can automate tasks within documents and are embedded within Office documents like Word, Excel, and PowerPoint files. While macros can be used for legitimate purposes, they can also be abused by attackers to execute maliciouscode. When an office document with a malicious macro is opened, and macros are enabled, the macro can run arbitrary code that leads to malicious downloads, installing malware or performing other unauthorized actions on the victim's system.
Macro abuse has become a common vector for cyber attacks, as it exploits the functionality of widely used office applications. Attackers often craft phishing emails with attachments or links to documents that contain malicious macros, tricking users into enabling macros to execute the malicious code. This method is effective for bypassing some security measures since it relies on user interaction and exploitation of legitimate features.
References:In the ECIH v3 course by EC-Council, there is a focus on various methods used by attackers to compromise systems, including macro abuse in office documents. The curriculum stresses the importance of understanding these attack vectors for effective incident handling and response strategies.
NEW QUESTION # 97
Which of the following tools helps incident responders effectively contain a potential cloud security incident and gather required forensic evidence?
- A. Cloud Passage Halo
- B. Qualys Cloud Platform
- C. CloudPassage Quarantine
- D. Alert Logic
Answer: D
NEW QUESTION # 98
In which of the following phases of the incident handling and response (IH&R) process is the identified security incidents analyzed, validated, categorized, and prioritized?
- A. Incident triage
- B. Incident recording and assignment
- C. Notification
- D. Containment
Answer: A
Explanation:
Incident triage is the phase in the Incident Handling and Response (IH&R) process where identified security incidents are analyzed, validated, categorized, and prioritized. This step is crucial for determining the severity of incidents and deciding on the order in which they should be addressed. During triage, incident handlers assess the impact, urgency, and potential harm of an incident to prioritize their response efforts effectively.
This ensuresthat resources are allocated efficiently, and the most critical incidents are handled first. Incident recording and assignment involve logging incidents and assigning them to handlers, containment focuses on limiting the extent of damage, and notification involves informing stakeholders about the incident.References:The Incident Handler (ECIH v3) courses and study guides detail the IH&R process, emphasizing the importance of triage in managing and responding to security incidents effectively.
NEW QUESTION # 99
SWA Cloud Services added PKI as one of their cloud security controls. What does PKI stand for?
- A. Public key information
- B. Private key infrastructure
- C. Public key infrastructure
- D. Private key in for ma lion
Answer: C
NEW QUESTION # 100
Jason is setting up a computer forensics lab and must perform the following steps: 1. physical location and structural design considerations; 2. planning and budgeting; 3. work area considerations; 4. physical security recommendations; 5. forensic lab licensing; 6. human resource considerations. Arrange these steps in the order of execution.
- A. 2 -> 1 -> 3 -> 6 -> 4 -> 5
- B. 5-> 2-> l-> 3-> 4-> 6
- C. 2->3->l ->4->6->5
- D. 3 .> 2 -> 1 -> 4-> 6-> 5
Answer: A
NEW QUESTION # 101
Which of the following is a type of malicious code or software that appears legitimate but can take control of your computer?
- A. Trojan attack
- B. DDoS
- C. Phishing attack
- D. Password attack
Answer: A
Explanation:
A Trojan attack involves a type of malicious code or software that appears legitimate but can take control of your computer. Trojans often disguise themselves as legitimate software or are hidden within legitimate software that has been tampered with. They differ from viruses and worms because they do not replicate.
However, once activated, Trojans can enable cyber-criminals to spy on you, steal your sensitive data, and gain backdoor access to your system. This can include unauthorized actions such as deleting files, monitoring user activities, or installing additional malicious software.
References:The ECIH v3 course details various forms of malware, including Trojans, their modes of operation, and their impact on information security. Understanding the nature of these threats is crucial for effective incident handling and response.
NEW QUESTION # 102
Which of the following tools helps incident handlers to view the file system, retrieve deleted data, perform timeline analysis, web artifacts, etc., during an incident response process?
- A. nblslal
- B. Process Explorer
- C. Autopsy
- D. netstat
Answer: C
NEW QUESTION # 103
James has been appointed as an incident handing and response (IH&R) team lead and was assigned to build an IH&R plan and his own team in the company. Identify the IH&R process step James is currently working on.
- A. Recovery
- B. Eradication
- C. Notification
- D. Preparation
Answer: D
NEW QUESTION # 104
Which of the following types of digital evidence is temporarily stored in a digital device that requires constant power supply and is deleted if the power supply is interrupted?
- A. Event logs
- B. Process memory
- C. Swap file
- D. Slack space
Answer: B
Explanation:
Process memory (RAM) is a type of digital evidence that is temporarily stored and requires a constant power supply to retain information. If the power supply is interrupted, the information stored in process memory is lost. This type of evidence can include data about running programs, user actions, system events, and more, making it crucial for forensic analysis, especially in identifying actions taken by both users and malware.
Collecting data from process memory helps incident responders understand the state of the system at the time of an incident and can reveal valuable information that is not persisted elsewhere on the device.
References:Incident handling and response training, such as the ECIH v3 program, emphasize the importance of collecting and analyzing volatile data, including process memory, to effectively investigate and respond to cybersecurity incidents.
NEW QUESTION # 105
Farheen is an incident responder at reputed IT Firm based in Florida. Farheen was asked to investigate a recent cybercrime faced by the organization. As part of this process, she collected static data from a victim system. She used dd, a command line tool, to perform forensic duplication to obtain an NTFS image of the original disk. She created a sector-by-sector mirror imaging of the disk and saved the output image file as image.dd. Identify the static data collection process step performed by Farheen while collecting static data.
- A. System preservation
- B. Physical presentation
- C. Administrative consideration
- D. Comparison
Answer: A
NEW QUESTION # 106
identify the network security incident where intended or authorized users are prevented from using system, network, or applications by flooding the network with a high volume of traffic that consumes all existing network resources.
- A. Denial-of-service
- B. URL manipulation
- C. SQL injection
- D. XSS attack
Answer: A
NEW QUESTION # 107
......
Q&As with Explanations Verified & Correct Answers: https://www.vcedumps.com/212-89-examcollection.html
Dumps Free Test Engine Player Verified Answers: https://drive.google.com/open?id=1aa4DOD6gewA_Cbru0o9PPQRhTdI1nZhp
