EC-COUNCIL 212-89 Real Exam Questions Test Engine Dumps Training With 165 Questions
212-89 Actual Questions Answers PDF 100% Cover Real Exam Questions
NEW QUESTION 68
Preventing the incident from spreading and limiting the scope of the incident is known as:
- A. Incident Classification
- B. Incident Containment
- C. Incident Eradication
- D. Incident Protection
Answer: B
NEW QUESTION 69
Computer viruses are malicious software programs that infect computers and corrupt or delete the data on them. Identify the virus type that specifically infects Microsoft Word files?
- A. File Infector
- B. Macro Virus
- C. Micro Virus
- D. Boot Sector virus
Answer: B
NEW QUESTION 70
Incident handling and response steps help you to detect, identify, respond and manage an incident. Which of
the following steps focus on limiting the scope and extent of an incident?
- A. Identification
- B. Data collection
- C. Eradication
- D. Containment
Answer: D
NEW QUESTION 71
Which of the following terms may be defined as "a measure of possible inability to achieve a goal, objective, or target within a defined security, cost plan and technical limitations that adversely affects the organization's operation and revenues?
- A. Vulnerability
- B. Incident Response
- C. Risk
- D. Threat
Answer: C
NEW QUESTION 72
Which of the following is an appropriate flow of the incident recovery steps?
- A. System Operation-System Restoration-System Validation-System Monitoring
- B. System Restoration-System Monitoring-System Validation-System Operations
- C. System Restoration-System Validation-System Operations-System Monitoring
- D. System Validation-System Operation-System Restoration-System Monitoring
Answer: C
NEW QUESTION 73
CERT members can provide critical support services to first responders such as:
- A. Organizing spontaneous volunteers at a disaster site
- B. Consolidated automated service process management platform
- C. A + C
- D. Immediate assistance to victims
Answer: C
NEW QUESTION 74
To recover, analyze, and preserve computer and related materials in such a way that it can be presented as evidence in a court of law and identify the evidence in short time, estimate the potential impact of the malicious activity on the victim, and assess the intent and identity of the perpetrator is known as:
- A. Digital Forensic Analysis
- B. Computer Forensics
- C. Forensic Readiness
- D. Digital Forensic Examiner
Answer: A
NEW QUESTION 75
Digital evidence must:
- A. Not prove the attackers actions
- B. Cast doubt on the authenticity and veracity of the evidence
- C. Be Authentic, complete and reliable
- D. Be Volatile
Answer: C
NEW QUESTION 76
Bit stream image copy of the digital evidence must be performed in order to:
- A. Prevent alteration to the original disk
- B. Copy the FAT table
- C. All the above
- D. Copy all disk sectors including slack space
Answer: D
NEW QUESTION 77
The state of incident response preparedness that enables an organization to maximize its potential to use digital evidence while minimizing the cost of an investigation is called:
- A. Digital Forensic Policy
- B. Computer Forensics
- C. Digital Forensic Analysis
- D. Forensic Readiness
Answer: D
NEW QUESTION 78
A malware code that infects computer files, corrupts or deletes the data in them and requires a host file to propagate is called:
- A. Worm
- B. RootKit
- C. Trojan
- D. Virus
Answer: D
NEW QUESTION 79
Which policy recommends controls for securing and tracking organizational resources:
- A. Administrative security policy
- B. Acceptable use policy
- C. Access control policy
- D. Asset control policy
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION 80
Business continuity is defined as the ability of an organization to continue to function even after a disastrous event, accomplished through the deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy. Identify the plan which is mandatory part of a business continuity plan?
- A. New business strategy plan
- B. Forensics Procedure Plan
- C. Business Recovery Plan
- D. Sales and Marketing plan
Answer: C
NEW QUESTION 81
The flow chart gives a view of different roles played by the different personnel of CSIRT. Identify the incident
response personnel denoted by A, B, C, D, E, F and G.
- A. A- Incident Coordinator, B- Constituency, C-Administrator, D-Incident Manager, E- Human Resource, F-
Incident Analyst, G-Public relations - B. A- Incident Coordinator, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-
Constituency, G-Incident Manager - C. A- Incident Manager, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-
Constituency, G-Incident Coordinator - D. A-Incident Analyst, B- Incident Coordinator, C- Public Relations, D-Administrator, E- Human Resource, F-
Constituency, G-Incident Manager
Answer: A
NEW QUESTION 82
The Linux command used to make binary copies of computer media and as a disk imaging tool if given a raw disk device as its input is:
- A. "netstat" command
- B. "nslookup" command
- C. "find" command
- D. "dd" command
Answer: D
NEW QUESTION 83
Computer forensics is methodical series of techniques and procedures for gathering evidence from computing equipment, various storage devices and or digital media that can be presented in a course of law in a coherent and meaningful format. Which one of the following is an appropriate flow of steps in the computer forensics process:
- A. Examination> Analysis > Preparation > Collection > Reporting
- B. Preparation > Collection > Examination > Analysis > Reporting
- C. Preparation > Analysis > Collection > Examination > Reporting
- D. Analysis > Preparation > Collection > Reporting > Examination
Answer: B
NEW QUESTION 84
Multiple component incidents consist of a combination of two or more attacks in a system. Which of the following is not a multiple component incident?
- A. An attacker redirecting user to a malicious website and infects his system with Trojan
- B. An attacker using email with malicious code to infect internal workstation
- C. An attacker infecting a machine to launch a DDoS attack
- D. An insider intentionally deleting files from a workstation
Answer: D
NEW QUESTION 85
The open source TCP/IP network intrusion prevention and detection system (IDS/IPS), uses a rule-driven
language, performs real-time traffic analysis and packet logging is known as:
- A. Wireshark
- B. Snort
- C. Nessus
- D. SAINT
Answer: B
Explanation:
Explanation
NEW QUESTION 86
The very well-known free open source port, OS and service scanner and network discovery utility is called:
- A. Snort
- B. Wireshark
- C. Nmap (Network Mapper)
- D. SAINT
Answer: C
NEW QUESTION 87
Incident may be reported using/ by:
- A. Phone call
- B. Facsimile (Fax)
- C. Email or on-line Web form
- D. All the above
Answer: D
NEW QUESTION 88
Spyware tool used to record malicious user's computer activities and keyboard stokes is called:
- A. adware
- B. Rootkit
- C. Firewall
- D. Keylogger
Answer: D
NEW QUESTION 89
An incident is analyzed for its nature, intensity and its effects on the network and systems. Which stage of the
incident response and handling process involves auditing the system and network log files?
- A. Containment
- B. Reporting
- C. Identification
- D. Incident recording
Answer: C
NEW QUESTION 90
Computer Forensics is the branch of forensic science in which legal evidence is found in any computer or any digital media device. Of the following, who is responsible for examining the evidence acquired and separating the useful evidence?
- A. Evidence Examiner/ Investigator
- B. Evidence Manager
- C. Evidence Supervisor
- D. Evidence Documenter
Answer: A
NEW QUESTION 91
When an employee is terminated from his or her job, what should be the next immediate step taken by an organization?
- A. The access requests granted to an employee should be documented and vetted by the supervisor
- B. The organization should monitor the activities of the system administrators and privileged users who have permissions to access the sensitive information
- C. The organization should enforce separation of duties
- D. All access rights of the employee to physical locations, networks, systems, applications and data should be disabled
Answer: D
NEW QUESTION 92
The USB tool (depicted below) that is connected to male USB Keyboard cable and not detected by anti-spyware tools is most likely called:
- A. Software Key Grabber
- B. USB adapter
- C. Anti-Keylogger
- D. Hardware Keylogger
Answer: D
NEW QUESTION 93
......
The EC-Council 212-89 is an entrance exam to the field of incident handling. It recognizes the skills needed to not only identify hazards but also correct and prevent future incidents. Thus, this test will qualify you for the Certified Incident Handler certification from the EC-Council, denoted the ECIH certificate. In general, most of the candidates who register for this exam possess one of the following titles:
- Risk assessment administrators;
- Cyber forensic investigators;
- Penetration testers;
- Vulnerability assessment auditors;
- System engineers;
- Incident handlers;
- Firewall administrators.
Exam Overview
EC-Council 212-89 is a 3-hour test consisting of 100 questions. The potential candidates must understand the details of different topics covered in the exam before attempting it. The highlights of the scope of the domains that should be studied during your preparation are enumerated below:
- Email Security Incidents: The next domain covers one’s skills in different areas, including phishing email, email incidents, deceptive & suspicious email, and email security. It comes with 10% of the exam questions;
- Application Level Incidents: This part covers 8% of the whole content and measures the skills of the individuals in web application vulnerabilities & threats, eradication of web apps, and web attack;
- Incident Occurred within the Cloud Environment: This objective also covers 8% of the whole content and focuses on the students’ skills in Cloud computing threats, recovery in Cloud, eradication, and security within Cloud computing.
- Network & Mobile Incidents: This module focuses on 16% of the exam content and covers the skill areas related to network attacks, eradication of mobile incidents and recovery, denial-of-service, mobile platform risks & vulnerabilities, wireless network, inappropriate usage, and unauthorized access;
- Malware Incidents: This subject area makes up 8% of the exam questions and focuses on malicious code, malware incident triage, and malware;
- First Response & Forensic Readiness: This section focuses on 13% of the exam content and covers the areas, such as computer forensic, volatile evidence, anti-forensics, static evidence, digital evidence, preservation of electronic evidence, and forensic readiness;
- Insider Threats: Here, you need to have the skills in insider threats, employee monitoring tools, detecting & preventing insider threats, and eradication. It covers 7% of the entire content;
- Incident Handling & Response: This topic focuses on information security, threat intelligence, computer security, security policies, incident handling, and risk management. It makes up 16% of the exam content;
- Process Handling: This area covers 14% of the exam questions and focuses on incident handling & response, security auditing, incident readiness, eradication & recovery, forensic investigation, and security incidents;
PrepPDF 212-89 Exam Practice Test Questions : https://www.preppdf.com/EC-COUNCIL/212-89-prepaway-exam-dumps.html
212-89 Exam questions and answers: https://drive.google.com/open?id=1KpRHnqRqUvaNHRXrRCiUo5eAsISWgE2b