
Use EC-COUNCIL 212-89 Dumps To Succeed Instantly in 212-89 Exam
Ultimate Guide to 212-89 Dumps - Enhance Your Future Career Now
NEW QUESTION # 133
Identify Sarbanes-Oxley Act (SOX) Title, which consists of only one section, that includes measures designed to help restore investor confidence in the reporting of securities analysts.
- A. Title V: Analyst Conflicts of Interest
- B. Title VIII: Corporate and Criminal Fraud Accountability
- C. Title IX: White-Collar-Crime Penalty Enhancement
- D. Title VII: Studies and Reports
Answer: A
NEW QUESTION # 134
Francis received a spoof email asking for his bank information. He decided to use a tool to analyze the email headers. Which of the following should he use?
- A. PoliteMail
- B. MxTooIbox
- C. EventLog Analyzer
- D. Email Checker
Answer: B
NEW QUESTION # 135
Sam. an employee of a multinational company, sends emails to third-party organizations with a spoofed email address of his organization. How can you categorize this type of incident?
- A. Unauthorized access incident.
- B. Denial-of-service incicent
- C. Network intrusion incident
- D. Inappropriate usage incident
Answer: D
Explanation:
An inappropriate usage incident involves misuse of the organization's resources or violations of its acceptable use policies. Sam's actions, where he sends emails to third-party organizations with a spoofed email address of his employer, constitute misuse of the organization's email system and misrepresentation of the organization.
This behavior can harm the organization's reputation, violate policy, and potentially lead to legal consequences. Inappropriate usage incidents can range from unauthorized use of systems for personal gain to the dissemination of unapproved content.
References:The Incident Handler (ECIH v3) by EC-Council includes discussions on various types of security incidents, emphasizing the importance of addressing and mitigating not just external threats but also internal misuse and policy violations.
NEW QUESTION # 136
What is the name of the type of malicious software or malware designed to deny access to a computer system or data until money is paid?
- A. Ransomware
- B. Adware
- C. Spyware
- D. Virus
Answer: A
NEW QUESTION # 137
In the course of an incident handling task, you identified an email with suspicious attributes. The email header indicates an SPF result of "SoftFail" and a DKIM result of "Neutral." Given these attributes, what is the most probable interpretation and appropriate course of action?
- A. The email is legitimate as the DKIM result is Neutral, which means the email is signed but the signature could not be processed due to syntax errors. No further action is required.
- B. The email is likely a spoofed email and should be quarantined immediately as the SPF SoftFail and DKIM Neutral results together indicate possible email forgery.
- C. The email could be suspicious, as the DKIM result indicates syntax errors in the signature.
However, no immediate action is required as the SPF SoftFail does not confirm the email as malicious. - D. The email is likely legitimate as the SPF result does not indicate a failure. Continue to analyze the content of the email for any other suspicious signs.
Answer: B
NEW QUESTION # 138
Which of the following digital evidence temporarily stored on a digital device that requires a constant power supply and is deleted if the power supply is interrupted?
- A. Event logs
- B. Swap file
- C. Slack space
- D. Process memory
Answer: D
Explanation:
Process memory, or volatile memory (RAM), is digital evidence that requires a constant power supply to retain data and is deleted or lost when the power supply is interrupted. It contains information about the system's ongoing processes and operations. This type ofevidence can be crucial for forensic investigations as it may hold information about user actions, system events, and the state of applications and services at the time of an incident. Unlike swap files, event logs, and slack space, which can retain information without a constant power supply, process memory is inherently volatile and its contents are lost when a device is powered off or restarts.References:The ECIH v3 certification program includes discussions on digital forensics and the importance of different types of digital evidence, including volatile and non-volatile memory, in the context of incident response and investigation.
NEW QUESTION # 139
Which of the following might be an insider threat?
- A. Business partners
- B. Current employee
- C. All of these
- D. Disgruntled system administrators
Answer: C
NEW QUESTION # 140
In a hypothetical scenario, you are an EC-Council Certified Incident Handler (ECIH). and you have been called to handle an incident at a large multinational corporation where a significant data breach has been detected. The breach involves a cloud-hosted database containing sensitive client information. You need to secure and document the crime scene. Which of the following steps is most appropriate as your first response?
- A. Remotely login and shut down the compromised database to prevent further access.
- B. Begin with a comprehensive network traffic analysis to identify the source of the breach.
- C. Document the state of the cloud environment, including system logs and configurations.
- D. Immediately inform all clients about the breach and the potential loss of data.
Answer: C
NEW QUESTION # 141
The sprawling headquarters of OmegaTech Corp. underwent a significant tech overhaul recently.
With newly installed high-speed data servers, the latest AI-driven security systems, and an ultra- modern IoT-based infrastructure for its thousands of employees, it was a model of tech sophistication. However, one Monday morning, Olivia, a senior IT executive, identified multiple unauthorized remote accesses to their primary server. To her horror, she found a complex maze of data tunnels redirecting confidential business data to numerous shadow servers. While she's battling with that, two divisions reported corrupted firmware in their IoT devices. What should Olivia, as the first respondser, prioritize?
- A. Alert all division heads to immediately initiate a system-wide shut down.
- B. Engage the AI-driven security system to trace unauthorized accesses in real time.
- C. Start a protocol to reinstall firmware in IoT devices.
- D. Begin with isolating the primary server and cutting off remote access.
Answer: D
Explanation:
ECIH prioritizes containment of the most critical threat vector. The primary server actively exfiltrating data represents the highest risk.
Option B is correct because isolating the primary server immediately stops data loss and attacker control. IoT remediation can follow once core assets are secured.
Options A and D delay containment. Option C causes unnecessary disruption.
ECIH stresses that responders must address the most damaging threat first, making Option B correct.
NEW QUESTION # 142
Shall y, an incident handler, is working for a company named Texas Pvt.Ltd.based in Florida. She was asked to work on an incident response plan. As part of the plan, she decided to enhance and improve the security infrastructure of the enterprise. She has incorporated a security strategy that allows security professionals to use several protection layers throughout their information system. Due to multiple layer protection, this security strategy assists in preventing direct attacks against the organization's information system as a break in one layer only leads the attacker to the next layer.
Identify the security strategy Shall y has incorporated in the incident response plan.
- A. Defense-in-depth
- B. Covert channels
- C. Three-way handshake
- D. Exponential back off algorithm
Answer: A
NEW QUESTION # 143
The typical correct sequence of activities used by CSIRT when handling a case is:
- A. Log, maintain contacts, inform, release information, follow up and reporting
- B. Log, maintain contacts, release information, inform, follow up and reporting
- C. Log, inform, maintain contacts, release information, follow up and reporting
- D. Log, inform, release information, maintain contacts, follow up and reporting
Answer: C
NEW QUESTION # 144
The state of incident response preparedness that enables an organization to maximize its potential to use
digital evidence while minimizing the cost of an investigation is called:
- A. Digital Forensic Policy
- B. Computer Forensics
- C. Forensic Readiness
- D. Digital Forensic Analysis
Answer: C
NEW QUESTION # 145
An organization named Sam Morison Inc. decided to use cloud-based services to reduce the cost of maintenance. The organization identified various risks and threats associated with cloud service adoption and migrating business-critical data to thirdparty systems. Hence, the organization decided to deploy cloud-based security tools to prevent upcoming threats.
Which of the following tools help the organization to secure the cloud resources and services?
- A. Alert Logic
- B. Wireshark
- C. Nmap
- D. Burp Suite
Answer: A
NEW QUESTION # 146
A US Federal agency network was the target of a DoS attack that prevented and impaired the normal authorized functionality of the networks. According to agency's reporting timeframe guidelines, this incident should be reported within two (2) HOURS of discovery/detection if the successful attack is still ongoing and the agency is unable to successfully mitigate the activity. Which incident category of the US Federal Agency does this incident belong to?
- A. CAT 1
- B. CAT 5
- C. CAT 2
- D. CAT 6
Answer: C
NEW QUESTION # 147
An incident handler is analyzing email headers to find out suspicious emails.
Which of the following tools he/she must use in order to accomplish the task?
- A. Barracuda Email Security Gateway
- B. SPAMfighter
- C. Gophish
Answer: A
Explanation:
The Barracuda Email Security Gateway is designed to manage and filter inbound and outbound email traffic to protect organizations from email-borne threats and data leaks. As an incident handler analyzing email headers to find out suspicious emails, using a tool like the Barracuda Email Security Gateway would be appropriate. This tool can help identify and block spam, phishing, malware, and other malicious email threats, making it easier to focus on analyzing potentially harmful emails more closely.
NEW QUESTION # 148
Shally, an incident handler, is working for a company named Texas Pvt. Ltd. based in Florida. She was asked to work on an incident response plan. As part of the plan, she decided to enhance and improve the security infrastructure of the enterprise. She has incorporated a security strategy that allows security professionals to use several protection layers throughout their information system. Due to multiple layer protection, this security strategy assists in preventing direct attacks against the organization's information system as a break in one layer only leads the attacker to the next layer.
Identify the security strategy Shally has incorporated in the incident response plan.
- A. Defense-in-depth
- B. Covert channels
- C. Exponential backoff algorithm
- D. Three-way handshake
Answer: A
Explanation:
Shally has incorporated the Defense-in-depth strategy into the incident response plan for Texas Pvt. Ltd.
Defense-in-depth is a layered security approach that involves implementing multiple security measures and controls throughout an information system. This strategy is designed to provide several defensive barriers to protect against threats and attacks, ensuring that if one layer is compromised, others still provide protection.
The goal is to create a multi-faceted defense that addresses potential vulnerabilities in various areas, including physical security, network security, application security, and user education.References:The Incident Handler (ECIH v3) courses and study guides often emphasize the importance of a Defense-in-depth strategy in creating robust security infrastructures to protect against a wide range of cyber threats.
NEW QUESTION # 149
Andrew, an incident responder, is performing risk assessment of the client organization.
As a part of risk assessment process, he identified the boundaries of the IT systems, along with the resources and the information that constitute the systems.
Identify the risk assessment step Andrew is performing.
- A. Likelihood determination
- B. System characterization
- C. Control recommendations
- D. Control analysis
Answer: B
Explanation:
In the risk assessment process, "System characterization" is the initial step where the scope of the assessment is defined. This involves identifying and documenting the boundaries of the IT systems under review, the resources (hardware, software, data, and personnel) that constitute these systems, and any relevant information about their operation and environment. This foundational step is essential for understanding what needs to be protected and forms the basis for subsequent analysis, including identifying vulnerabilities, assessing potential threats, and determining the impact of risks to the organization.
References:The step of system characterization within the risk assessment process is discussed in detail in information security frameworks and incident response guides, including those related to the ECIH v3 certification. These guides stress the importance of accurately characterizing the system to ensure that the risk assessment is comprehensive and tailored to the specific context of the organization.
NEW QUESTION # 150
One of the main objectives of incident management is to prevent incidents and attacks by tightening the
physical security of the system or infrastructure. According to CERT's incident management process, which
stage focuses on implementing infrastructure improvements resulting from postmortem reviews or other
process improvement mechanisms?
- A. Detection
- B. Preparation
- C. Triage
- D. Protection
Answer: D
NEW QUESTION # 151
OmegaTech was compromised by an insider who deliberately introduced vulnerabilities into its flagship product after being recruited by a rival company. OmegaTech wants to minimize such risks in the future.
What should be its primary focus?
- A. Implement a strict vetting process for every software release.
- B. Rotate job roles every six months.
- C. Strengthen background checks and continually monitor employee behavior for anomalies.
- D. Introduce surprise loyalty tests.
Answer: C
Explanation:
Comprehensive and Detailed Explanation (ECIH-aligned):
ECIH insider threat guidance emphasizes continuous monitoring and behavioral analysis combined with background checks as the most effective deterrent against malicious insiders.
Option D is correct because insider threats often evolve after hiring. Continuous monitoring detects abnormal behavior patterns that static vetting cannot.
Options A-C are insufficient or ineffective against sophisticated insider threats.
NEW QUESTION # 152
In a simulated lab environment, an incident handler uses the CurrPorts tool to monitor TCP/IP connections in the wake of a malware incident. The malware, a trojan called "njRAT," has been executed on a Windows Server 2016 virtual machine. After executing the trojan, the handler observes a connection established by the njRAT client on the Windows 10 virtual machine. Using CurrPorts on the infected Windows Server2016, what course of action should the handler take next?
- A. Immediately disconnect Windows Server 2016 from the network.
- B. Run a full antivirus scan on the Windows 10 virtual machine.
- C. Perform port monitoring to identify the process running and the port on which it's running.
- D. Restart Windows Server 2016 to remove the trojan.
Answer: C
NEW QUESTION # 153
Michael is a part of the computer incident response team of a company. One of his responsibilities is to handle email incidents. The company receives an email from an unknown source, and one of the steps that he needs to take is to check the validity of the email.
Which of the following tools should he use?
- A. Zendio
- B. Yes ware
- C. G Suite Toolbox
- D. Email Dossier
Answer: D
NEW QUESTION # 154
A financial institution has recently suffered a major security incident The incident was traced back to a malicious mobile application installed on the personal device of a senior executive, which was used for accessing corporate resources. As a certified incident handler, your immediate task is to mitigate such threats in the future. What step would you prioritize?
- A. Install an advanced mobile device management solution on all personal devices accessing corporate resources.
- B. Encourage all executives to only use corporate-owned devices for work purposes.
- C. Mandate the use of antivirus solutions on all personal devices accessing corporate resources.
- D. Implement strict rules disallowing the use of personal devices to access corporate resources.
Answer: A
NEW QUESTION # 155
Matt is an incident handler working for one of the largest social network companies, which was affected by malware. According to the company's reporting timeframe guidelines, a malware incident should be reported within 1 h of discovery/detection after its spread across the company.
Which category does this incident belong to?
- A. CAT 4
- B. CAT 3
- C. CAT 2
- D. CAT 1
Answer: B
Explanation:
This scenario matches CAT 3 - Malicious Code. Under the US-CERT/NCCIC federal incident notification categorization adopted in ECIH methodology, malicious code (malware) incidents have a special reporting condition: while regular malware incidents are reported on a routine timeframe, if the malicious code has spread widely across the organization, it must be reported within 1 hour of discovery/detection. Since the question specifies that the malware incident must be reported within 1 hour after its spread across the company, this directly aligns with the CAT 3 classification and its special escalation condition.
NEW QUESTION # 156
The region where the CSIRT is bound to serve and what does it and give service to is known as:
- A. None of the above
- B. Consistency
- C. Constituency
- D. Confidentiality
Answer: C
NEW QUESTION # 157
......
EC-COUNCIL Dumps - Learn How To Deal With The Exam Anxiety: https://www.testkingit.com/EC-COUNCIL/latest-212-89-exam-dumps.html
Now, get the Latest 212-89 dumps in Test Engine from : https://drive.google.com/open?id=1VSdfydvctlMITE_JQEWGDEUtxjYfwN02