2024 Latest 212-89 dumps Exam Material with 205 Questions [Q36-Q56]

Share

2024 Latest 212-89 dumps Exam Material with 205 Questions

EC-COUNCIL 212-89 Questions and Answers Guarantee you Oass the Test Easily


EC-COUNCIL is a leading provider of cybersecurity certifications, and the ECIH certification is one of the many certifications offered by the organization. The organization is known for its rigorous certification process and high-quality training programs. EC-COUNCIL also provides various resources such as study materials, practice exams, and webinars to help candidates prepare for the ECIH certification exam.

 

NEW QUESTION # 36
A malware code that infects computer files, corrupts or deletes the data in them and requires a host file to propagate is called:

  • A. Virus
  • B. Trojan
  • C. Worm
  • D. RootKit

Answer: A


NEW QUESTION # 37
Identify a standard national process which establishes a set of activities, general tasks and a management structure to certify and accredit systems that will maintain the information assurance (IA) and security posture of a system or site.

  • A. NIAAAP
  • B. NIPACP
  • C. NIASAP
  • D. NIACAP

Answer: D


NEW QUESTION # 38
Which one of the following is the correct flow of the stages in an incident handling and response (IH&R) process?

  • A. Incident recording Preparation Containment Incident triage Recovery Eradication Post-incident activities
  • B. Preparation Incident recording Incident triage Containment Eradication Recovery Post-incident activities
  • C. Incident t rage Eradication Containment Incident recording Preparation Recovery Post-incident activities
  • D. Containment Incident recording Incident triage Preparation Recovery Eradication Post-incident activities

Answer: B


NEW QUESTION # 39
Drake is an incident handler at Dark Cloud Inc. Heist asked with performing log analysis in order to detect traces of malicious activities within the network infrastructure.
Which of the following tools should Drake employ in order to view logs in real time and identify malware propagation within the network?

  • A. LOIC
  • B. Splunk
  • C. HULK
  • D. Hydra

Answer: B


NEW QUESTION # 40
Mr.Smith is a lead incident responder of a small financial enterprise, which has a few branches in Australia. Recently, the company suffered a massive attack, losing$5M through an inter-banking system After an in-depth investigation, it was found that the incident occurred because the attackers penetrated the network through a minor vulnerability 6 months ago and maintained access without being detected by any user. They then tried to delete user fingerprints and performed a lateral movement to the computer of a person with privileges in the inter-banking system. The attackers finally gained access and performed fraudulent transactions.
In the above scenario, which of the following most accurately describes the type of attack?

  • A. Phishing
  • B. APT attack
  • C. Ransom ware attack
  • D. Denial-of-service attack

Answer: B


NEW QUESTION # 41
Incident Response Plan requires

  • A. All the above
  • B. Expert team composition
  • C. Financial and Management support
  • D. Resources

Answer: A


NEW QUESTION # 42
Which of the following is defined as the identification of the boundaries of an IT system along with the resources and information that constitute the system?

  • A. Control analysis
  • B. Threat identification
  • C. Vulnerability identification
  • D. System characterization

Answer: D


NEW QUESTION # 43
Finnis working in the eradication phase, wherein he is eliminating the root cause of an incident that occurred in the Windows operating system installed in a system. He ran a tool that can detect missing security patches and install the latest patches on the system and networks.
Which of the following tools did he use to detect the missing se cunty patches?

  • A. Microsoft Cloud App Security
  • B. Microsoft Baseline Security Analyzer
  • C. Office360 Advanced Threat Protection
  • D. Microsoft Advanced Threat Analytics

Answer: B


NEW QUESTION # 44
Alice is an incident handler and she has been informed by her lead that the data on affected systems must be backed up so that it can be retrieved if it is damaged during the incident response process. She was also told that the system backup can also be used for further investigation of the incident.
In which of the following stages of the incident handling and response (IH&R) process does Alice need to do a complete backup of the infected system?

  • A. Incident recording
  • B. Incident triage
  • C. Containment
  • D. Eradication

Answer: A


NEW QUESTION # 45
Shiela is working at night as an incident handler. During a shit, servers were affected by a massive cyber-attack. After she classified and prioritized the incident, she must report the incident, obtain necessary permissions, and perform other incident response functions.
What list should she check to notify other responsible personnel?

  • A. Point of contact
  • B. Email list
  • C. HR logbook
  • D. Phone number list

Answer: A


NEW QUESTION # 46
Total cost of disruption of an incident is the sum of

  • A. Intangible cost only
  • B. Tangible cost only
  • C. Tangible and Intangible costs
  • D. Level Two and Level Three incidents cost

Answer: C


NEW QUESTION # 47
The left over risk after implementing a control is called:

  • A. Residual risk
  • B. Critical risk
  • C. Low risk
  • D. Unaccepted risk

Answer: A


NEW QUESTION # 48
XYZ Inc. was affected by a malware attack and James, being the incident handling and response (IH&R) team personnel handling the incident, found out that the root cause of the incident is a backdoor that has bypassed the security perimeter due to an existing vulnerability in the deployed firewall. James had contained the spread of the infection and removed the malware completely. Now the organization asked him to perform an incident impact assessment to identify the impact of the incident over the organization and he was also asked to prepare a detailed report of the incident.
Which of the following stages in IH&R process is James working on?

  • A. Evidence gathering and forensics analysis
  • B. Notification
  • C. Eradication
  • D. Post-incident activities

Answer: D


NEW QUESTION # 49
A computer Risk Policy is a set of ideas to be implemented to overcome the risk associated with computer security incidents. Identify the procedure that is NOT part of the computer risk policy?

  • A. Procedure to identify security funds to hedge risk
  • B. Procedure to monitor the efficiency of security controls
  • C. Provisions for continuing support if there is an interruption in the system or if the system crashes
  • D. Procedure for the ongoing training of employees authorized to access the system

Answer: D


NEW QUESTION # 50
An attacker uncovered websites a target individual was frequently Suring. The attacker then tested those particular websites to identify possible vulnerabilities. After detecting vulnerabilities within a website, the attacker started injecting malicious script/code into the web application that would redirect the webpage and download the malware on to the victim's machine. After infecting the vulnerable web application, the attacker waited for the victim to access the infected web application. Identify the type of attack performed by the attacker.

  • A. Directory traversal
  • B. Cookie/Session poisoning
  • C. Obfuscation application
  • D. Watering hole

Answer: B


NEW QUESTION # 51
Chandler is a professional hacker who is targeting an organization called Technote. He wants to obtain important organizational information that is being transmitted between different hierarchies. In the process, he sniffs the data packets transmitted through the network and then analyzes them to gather packet details such as network, ports, protocols, devices, issues in network transmission, and other network specifications.
Which of the following tools can Chandler employ to perform packet analysis?

  • A. Omni peek
  • B. shARP
  • C. IDA Pro
  • D. BeEf

Answer: B


NEW QUESTION # 52
Which of the following service(s) is provided by the CSIRT:

  • A. Vulnerability handling
  • B. Technology watch
  • C. All the above
  • D. Development of security tools

Answer: C


NEW QUESTION # 53
The main feature offered by PGP Desktop Email is:

  • A. End-to-end email communications
  • B. None of the above
  • C. End-to-end secure email service
  • D. Email service during incidents

Answer: C


NEW QUESTION # 54
One of the main objectives of incident management is to prevent incidents and attacks by tightening the
physical security of the system or infrastructure. According to CERT's incident management process, which
stage focuses on implementing infrastructure improvements resulting from postmortem reviews or other
process improvement mechanisms?

  • A. Preparation
  • B. Detection
  • C. Protection
  • D. Triage

Answer: C


NEW QUESTION # 55
Rossi san incident manager (IM) at an organization, and his team provides support to all users in the
organization who are affected by threats or attacks. David, who is the organization's intemal auditor, is also part of Ross's incident response team.
Which of the following is David's responsibility?

  • A. Preform the necessary action to block the network traffic from the suspected intruder.
  • B. Configure information security controls.
  • C. Coordinate incident containment activities with the information security officer (ISO).
  • D. Identify and report security loopholes to the management for necessary action.

Answer: D


NEW QUESTION # 56
......

Share Latest 212-89 DUMP Questions and Answers: https://www.preppdf.com/EC-COUNCIL/212-89-prepaway-exam-dumps.html

PDF Dumps 2024 Exam Questions with Practice Test: https://drive.google.com/open?id=1Vjg4M4LEX7rHGKC0WbkZN79dPKL9DmVU