
[Nov-2024] Use Real 212-89 Dumps - 100% Free 212-89 Exam Dumps
212-89 PDF Dumps Exam Questions – Valid 212-89 Dumps
The EC-Council Certified Incident Handler (ECIH v2) certification exam is a globally recognized certification that validates the skills and knowledge of an individual in incident handling and response. EC Council Certified Incident Handler (ECIH v3) certification exam is ideal for security professionals who want to advance their career in incident handling and response and IT professionals who are responsible for protecting their organization's critical assets. EC Council Certified Incident Handler (ECIH v3) certification exam is comprehensive, covers all aspects of incident handling and response, and is available online in multiple languages.
Becoming Certified Incident Handler
If you opt to become a Certified Incident Handler, your job scope will fall under one of Incident Management Team (IMT) or Incident Response Team (IRT). The ECIH certificate is meant to equip you with the skills you need to deal with and manage computer security issues within a certain information system. In the modern IT environments, a Certified Incident Handler is expected to become a knowledgeable professional who can manage different kinds of incidents and understand the methodologies of risk assessment, including the common policies associated with incident handling. In many organizations, an incident handler will be responsible for creating incident handling policies & dealing with different forms of incidents for security comprising insider attack threats and incidents for malicious code. Therefore, getting certified will earn you recognition as the designated and highly respected incident handler in your company.
NEW QUESTION # 22
Which of the following is not called volatile data?
- A. State of the network interface
- B. The date and time of the system
- C. Open sockets or open ports
- D. Creation dates off les
Answer: D
NEW QUESTION # 23
Which of the following is an attack that attempts to prevent the use of systems, networks, or applications by the intended users?
- A. Malicious code or insider threat attack
- B. Unauthorized access
- C. Fraud and theft
- D. Denial of service (DoS) attack
Answer: D
NEW QUESTION # 24
Identify Sarbanes-Oxley Act (SOX) Title, which consists of only one section, that includes measures designed to help restore investor confidence in the reporting of securities analysts.
- A. Title V: Analyst Conflicts of Interest
- B. Title VII: Studies and Reports
- C. Title IX: White-Collar-Crime Penalty Enhancement
- D. Title VIII: Corporate and Criminal Fraud Accountability
Answer: A
NEW QUESTION # 25
Rica works as an incident handler for an international company. As part of her role, she must review the present security policy implemented. Upon inspection, Rica finds that the policy is wide open, and only known dangerous services/attacks or behaviors are blocked. Which of the following is the current policy that Rica identified?
- A. Paranoic policy
- B. Promiscuous policy
- C. Permissive policy
- D. Prudent policy
Answer: C
Explanation:
A permissive security policy is characterized by allowing all activities except those that are explicitly blocked.
This approach starts with a default state of allowing access and functionality, with restrictions applied only to known dangerous services, attacks, or behaviors. Such a policy can lead to a wider attack surface because it assumes services and behaviors are safe unless proven otherwise.
* A prudent policy would typically involve more conservative security measures, applying necessary restrictions to protect against identified and potential threats.
* A paranoic policy would be at the extreme end of security measures, possibly blocking more than necessary to ensure the highest level of security, often at the expense of usability or functionality.
* A promiscuous policy, in contrast, would be even more open than a permissive policy, essentially allowing nearly all traffic or actions with minimal restrictions, which is not what Rica observed.
References:In the context of the ECIH v3 course by EC-Council, reviewing and understanding the implications of security policies, like the permissive policy identified by Rica, is crucial for incident handlers to assess and improve organizational security postures.
NEW QUESTION # 26
John is performing memory dump analysis in order to find out the traces of malware.
He has employed volatility tool in order to achieve his objective.
Which of the following volatility framework commands he will use in order to analyze running process from the memory dump?
- A. python vol.py svcscan --profile=Win2008SP1x86 -f /root/Desktop/memdump.mem | more
- B. python vol.py imageinfo -f /root/Desktop/memdump.mem
- C. python vol.py hivelist --profile=Win2008SP1x86 -f /root/Desktop/memdump.mem
- D. python vol.py pslist --profile=Win2008SP1x86 -f /root/Desktop/memdump.mem
Answer: D
NEW QUESTION # 27
While analyzing a file, Ryan discovered that an attacker used an anti-forensics method, wherein the attacker embedded a hidden message inside an image file.
What type of method is this?
- A. Password protection
- B. Steganography
- C. Program packers
- D. Golden ticket
Answer: B
NEW QUESTION # 28
Jacob is an employee at a firm called Dolphin Investment. While he was on duty, he identified that his computer was facing some problems, and he wanted to convey the issue to the concerned authority in his organization. However, this organization currently does not have a ticketing system to address such types of issues. In the above scenario, which of the following ticketing systems can be employed by Dolphin Investment to allow Jacob to inform the concerned team about the incident?
- A. ThreatConnect
- B. ManageEngine ServiceDesk Plus
- C. IBM XForco Exchange
- D. MISP
Answer: B
Explanation:
In the scenario where Dolphin Investment needs to implement a ticketing system for employees like Jacob to report IT-related issues, ManageEngine ServiceDesk Plus is the most suitable option among the choices provided. ManageEngine ServiceDesk Plus is a comprehensive IT help desk software that facilitates issue tracking, incident management, and efficient resolution of IT-related problems and requests. It enables users to submit tickets through various channels, including email, web portal, phone, or chat, and allows IT support teams to manage these tickets through a centralized platform. This system is designed to streamline the process of reporting, tracking, and resolving IT issues and incidents, making it an ideal solution for organizations looking to establish a formalized incident reporting and resolution process. Other options like IBM X-Force Exchange, ThreatConnect, and MISP focus more on threat intelligence sharing and security incident analysis rather than functioning as an IT help desk or ticketing system.References:Incident Handler (ECIH v3) courses and study guides often discuss the importance of having an effective incident reporting and management system in place, and ManageEngine ServiceDesk Plus is frequently cited as a practical solution for organizations seeking to implement such a system.
NEW QUESTION # 29
Insiders may be:
- A. All the above
- B. Ignorant employees
- C. Disgruntled staff members
- D. Carless administrators
Answer: A
NEW QUESTION # 30
Bit stream image copy of the digital evidence must be performed in order to:
- A. Copy all disk sectors including slack space
- B. Copy the FAT table
- C. All the above
- D. Prevent alteration to the original disk
Answer: A
NEW QUESTION # 31
Patrick is performing a cyber forensic investigation. He is in the process of collect ng physical evidence at the crime scene.
Which of the following elements must he consider while collecting physical evidence?
- A. Open ports, services, and operating system (OS) vulnerabilities
- B. DNS information including domains and subdomains
- C. Published nameservers and web-application source code
- D. Removable media, cables, and publications
Answer: D
NEW QUESTION # 32
Your manager hands you several items of digital evidence and asks you to investigate them in the order of volatility.
Which of the following is the MOST volatile?
- A. Disk
- B. Temp files
- C. Cache
- D. Emails
Answer: C
NEW QUESTION # 33
In which of the following confidentiality attacks attackers try to lure users by posing themselves as authorized AP by beaconing the WLAN's SSID?
- A. Evil twin AP
- B. Honeypot AP
- C. Masqueradin
- D. Session hijacking
Answer: A
NEW QUESTION # 34
Francis received a spoof email asking for his bank information. He decided to use a tool to analyze the email headers. Which of the following should he use?
- A. PoliteMail
- B. MxTooIbox
- C. Email Checker
- D. EventLog Analyzer
Answer: B
NEW QUESTION # 35
Which of the following confidentiality attacks do attackers try to lure users by posing themselves as authorized AP by beaconing the WLAN's SSID?
- A. Evil twin AP
- B. Honeypot AP
- C. Masquerading
- D. Session hijacking
Answer: A
NEW QUESTION # 36
According to NITS, what are the 5 main actors in cloud computing?
- A. Provider, carrier, auditor, broker, and seller
- B. Consumer, provider, carrier, auditor, ano broker
- C. None of these
- D. Buyer, consumer, carrier, auditor, and broker
Answer: D
NEW QUESTION # 37
Which of the following is an appropriate flow of the incident recovery steps?
- A. System Validation-System Operation-System Restoration-System Monitoring
- B. System Restoration-System Validation-System Operations-System Monitoring
- C. System Operation-System Restoration-System Validation-System Monitoring
- D. System Restoration-System Monitoring-System Validation-System Operations
Answer: B
NEW QUESTION # 38
Which of the following techniques prevent or mislead incident-handling processes and may also affect the collection, preservation, and identification phases of the forensic investigation process?
- A. Enumeration
- B. Anti-forensics
- C. Scanning
- D. Foot printing
Answer: B
NEW QUESTION # 39
Khai was tasked with examining the logs from a Linux email server. The server uses Sendmail to execute the command to send emailsand Syslog to maintain logs. To validate the data within email headers, which of the following directories should Khai check for information such as source and destination IP addresses, dates, and timestamps?
- A. /va r/log/mai11og
- B. /Var/log/mailog
- C. /va r/log/sendmail/mailog
- D. /ar/log/sendmail
Answer: B
Explanation:
In a Linux environment, email servers such as Sendmail log events, including details about sent and received emails, in a specific log file. The correct directory and file for examining email logs, particularly for Sendmail and using Syslog for logging, is /Var/log/maillog. Thisfile contains vital information for forensic and incident response purposes, including source and destination IP addresses, email addresses, timestamps, and other data relevant to the email traffic handled by the server. By analyzing this log, incident responders can gather evidence related to email-based incidents, trace the source of malicious emails, and understand the scope of an incident. It's crucial for individuals like Khai, who are tasked with examining logs, to know the correct log file locations and their contents to effectively validate and analyze email header information and other relevant data.
References:Incident Handler (ECIH v3) study materials often cover the logging mechanisms of common services and applications on Linux systems, including email servers like Sendmail, and the importance of log files like /var/log/maillog in incident investigation and response activities.
NEW QUESTION # 40
The ability of an agency to continue to function even after a disastrous event, accomplished through the
deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup
and recovery strategy is known as:
- A. Disaster Planning
- B. Business Continuity
- C. Contingency Planning
- D. Business Continuity Plan
Answer: B
NEW QUESTION # 41
Which of the following options describes common characteristics of phishing emails?
- A. Sent from friends or colleagues
- B. Written in French
- C. No BCC fields
- D. Urgency, threatening, or promising subject lines
Answer: D
Explanation:
Phishing emails often share common characteristics designed to manipulate the recipient into taking immediate action. One of the hallmark features is the use of urgency, threatening language, or promising subject lines in the emails. These tactics are intended to create a sense of urgency or fear, compelling the recipient to respond quickly without giving due consideration to the legitimacy of the email. Phishing emails may claim that the recipient's account has been compromised, that they need to confirm personal information immediately, or that they have won a prize. The goal is to trick the recipient into clicking on malicious links, opening attachments, or providing sensitive information.
References:The Certified Incident Handler (ECIH v3) program by EC-Council covers the identification and handling of phishing incidents, including the analysis of phishing emails and the importance of educating users on recognizing and responding to phishing attempts.
NEW QUESTION # 42
Removing or eliminating the root cause of the incident is called:
- A. Incident Classification
- B. Incident Protection
- C. Incident Containment
- D. Incident Eradication
Answer: D
NEW QUESTION # 43
Marley was asked by his incident handling and response (IH&R) team lead to collect volatile data such as system information and network information present in the registries, cache, and RAM of victim's system.
Identify the data acquisition method Marley must employ to collect volatile data.
- A. Remote data acquisition
- B. Validate data acquisition
- C. Live data acquisition
- D. Static data acquisition
Answer: C
NEW QUESTION # 44
......
What Are Domains Covered by ECIH Test?
Overall, this certification exam has nine domains that have a specific weightage in the official validation. The candidates who take this exam need to master the following topics:
- Insider threats 7%;
- Process handling 14%;
- Email security incidents 10%;
- Incident handling and response 16%;
- Application-level incidents 8%;
- Cloud environment incidents 8%;
- Mobile & network incidents 16%;
- Malware incidents 8%;
Ultimate 212-89 Guide to Prepare Free Latest EC-COUNCIL Practice Tests Dumps: https://www.actual4dump.com/EC-COUNCIL/212-89-actualtests-dumps.html
Get Top-Rated EC-COUNCIL 212-89 Exam Dumps Now: https://drive.google.com/open?id=1CdbNbDN2rBtIbQeR2mNvEqZNSsISx4lc