2024 Realistic 212-89 Dumps Latest EC-COUNCIL Practice Tests Dumps
212-89 Dumps PDF - 212-89 Real Exam Questions Answers
NEW QUESTION # 104
An organization faced an information security incident where a disgruntled employee passed sensitive access
control information to a competitor. The organization's incident response manager, upon investigation, found
that the incident must be handled within a few hours on the same day to maintain business continuity and
market competitiveness. How would you categorize such information security incident?
- A. Ultra-High level incident
- B. Low level incident
- C. High level incident
- D. Middle level incident
Answer: C
NEW QUESTION # 105
One of the goals of CSIRT is to manage security problems by taking a certain approach towards the customers' security vulnerabilities and by responding effectively to potential information security incidents. Identify the incident response approach that focuses on developing the infrastructure and security processes before the occurrence or detection of an event or any incident:
- A. Interactive approach
- B. Introductive approach
- C. Qualitative approach
- D. Proactive approach
Answer: D
NEW QUESTION # 106
Chandler is a professional hacker who is targeting an organization called Technote. He wants to obtain important organizational information that is being transmitted between different hierarchies. In the process, he sniffs the data packets transmitted through the network and then analyzes them to gather packet details such as network, ports, protocols, devices, issues in network transmission, and other network specifications.
Which of the following tools can Chandler employ to perform packet analysis?
- A. BeEf
- B. Omni peek
- C. IDA Pro
- D. shARP
Answer: D
NEW QUESTION # 107
Alexis an incident handler in QWERTY Company. He identified that an attacker created a backdoor inside the company's network by installing a fake AP inside a firewall.
Which of the following attack types did the attacker use?
- A. Ad hoc associations
- B. AP misconfiguration
- C. Wardriving
- D. Rogue access point
Answer: D
NEW QUESTION # 108
The ability of an agency to continue to function even after a disastrous event, accomplished through the deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy is known as:
- A. Business Continuity
- B. Contingency Planning
- C. Business Continuity Plan
- D. Disaster Planning
Answer: A
NEW QUESTION # 109
Spyware tool used to record malicious user's computer activities and keyboard stokes is called:
- A. Firewall
- B. Rootkit
- C. Keylogger
- D. adware
Answer: C
NEW QUESTION # 110
Qual Tech Solutions is a leading security services enterprise. Dickson works as an incident responder with this firm. He is performing a vulnerability assessment to identify the security problems in the network, using automated tools to identify the hosts, services, and vulnerabilities present in the enterprise network.
Based on the above scenario, identify the type of vulnerability assessment performed by Dickson.
- A. Active assessment
- B. External assessment
- C. Internal assessment
- D. Passive assessment
Answer: C
NEW QUESTION # 111
In which of the steps of NIST's risk assessment methodology are the boundary of the IT system, along with the resources and the information that constitute the system identified?
- A. Control recommendation
- B. System characterization
- C. Control analysis
- D. Likelihood Determination
Answer: B
NEW QUESTION # 112
To recover, analyze, and preserve computer and related materials in such a way that it can be presented as evidence in a court of law and identify the evidence in short time, estimate the potential impact of the malicious activity on the victim, and assess the intent and identity of the perpetrator is known as:
- A. Forensic Readiness
- B. Digital Forensic Analysis
- C. Digital Forensic Examiner
- D. Computer Forensics
Answer: B
NEW QUESTION # 113
The sign(s) of the presence of malicious code on a host infected by a virus which is delivered via e-mail could be:
- A. Antivirus software detects the infected files
- B. All the above
- C. System files become inaccessible
- D. Increase in the number of e-mails sent and received
Answer: B
NEW QUESTION # 114
Performing Vulnerability Assessment is an example of a:
- A. Incident Handling
- B. Incident Response
- C. Post Incident Management
- D. Pre-Incident Preparation
Answer: D
NEW QUESTION # 115
An access control policy authorized a group of users to perform a set of actions on a set of resources. Access to resources is based on necessity and if a particular job role requires the use of those resources. Which of the following is NOT a fundamental element of access control policy
- A. Resource group: resources controlled by the policy
- B. Action group: group of actions performed by the users on resources
- C. Access group: group of users to which the policy applies
- D. Development group: group of persons who develop the policy
Answer: D
NEW QUESTION # 116
A computer virus hoax is a message warning the recipient of an on-existent computer virus threat. The message is usually a chain e-mail that tells the recipient to forward it to everyone they know.
Which of the following is not a symptom of virus hoax message?
- A. The message prompts the user to install Anti-virus
- B. The message warns to delete certain files if the user does not take appropriate action
- C. The message prompts the end user to forward it to his/her email contact list and gain monetary benefits in doing so
- D. The message from a known email id is caught by SPAM filters due to change in filter settings
Answer: D
NEW QUESTION # 117
The flow chart gives a view of different roles played by the different personnel of CSIRT. Identify the incident
response personnel denoted by A, B, C, D, E, F and G.
- A. A-Incident Analyst, B- Incident Coordinator, C- Public Relations, D-Administrator, E- Human Resource, F-
Constituency, G-Incident Manager - B. A- Incident Manager, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-
Constituency, G-Incident Coordinator - C. A- Incident Coordinator, B- Constituency, C-Administrator, D-Incident Manager, E- Human Resource, F-
Incident Analyst, G-Public relations - D. A- Incident Coordinator, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-
Constituency, G-Incident Manager
Answer: C
NEW QUESTION # 118
Incident management team provides support to all users in the organization that are affected by the threat or
attack. The organization's internal auditor is part of the incident response team. Identify one of the
responsibilities of the internal auditor as part of the incident response team:
- A. Identify and report security loopholes to the management for necessary actions
- B. Configure information security controls
- C. Perform necessary action to block the network traffic from suspected intruder
- D. Coordinate incident containment activities with the information security officer
Answer: A
NEW QUESTION # 119
Clark, a professional hacker, successfully exploited the web application of a target organization by tampering with form and parameter values. Consequently, Clark gained access to the information assets of the organization.
Which of the following is the web-application vulnerability exploited by the attacker?
- A. Security misconfiguration
- B. Broken access control
- C. SQL injection
- D. Sensitive data exposure
Answer: C
NEW QUESTION # 120
Ensuring the integrity, confidentiality and availability of electronic protected health information of a patient is known as:
- A. Sarbanes-Oxley Act
- B. Health Insurance Portability and Privacy Act
- C. Social Security Act
- D. Gramm-Leach-Bliley Act
Answer: B
NEW QUESTION # 121
Which of the following is an incident tracking, reporting and handling tool:
- A. RTIR
- B. NETSTAT
- C. EAR/ Pilar
- D. CRAMM
Answer: A
NEW QUESTION # 122
The insider risk matrix consists of technical literacy and business process knowledge vectors. Considering the matrix, one can conclude that:
- A. If the insider's technical literacy is high and process knowledge is low, the risk posed by the threat will be high.
- B. If the insider's technical literacy is low and process knowledge is high, the risk posed by the threat will be insignificant.
- C. If the insider's technical literacy and process knowledge are high, the risk posed by the threat will be insignificant.
- D. If the insider's technical literacy and process knowledge are high, the risk posed by the threat will be high.
Answer: D
NEW QUESTION # 123
......
The ECIH certification program is ideal for security personnel, network administrators, system administrators, security consultants, and IT managers who are responsible for incident handling or responding to security incidents. EC Council Certified Incident Handler (ECIH v2) certification program provides professionals with the knowledge and skills required to effectively detect, respond, and resolve security incidents in an organization. The ECIH certification is recognized globally and is an industry-standard certification for incident handling professionals. It is a valuable certification for professionals who want to enhance their career prospects in the field of cybersecurity.
212-89 Premium Exam Engine pdf Download: https://www.vceengine.com/212-89-vce-test-engine.html
212-89 Exam [2024] Dumps EC-COUNCIL PDF Questions: https://drive.google.com/open?id=1SncSbVvMzv-tVS-OuEX5na8P1Es4fNfO
