Pass Your EC-COUNCIL 212-89 Exam with Correct 205 Questions and Answers [Q53-Q76]

Share

Pass Your EC-COUNCIL 212-89 Exam with Correct 205 Questions and Answers

Latest [Jul 14, 2023] 2023 Realistic Verified 212-89 Dumps


Career Prospects

After earning the ECIH certification, the certified professionals can explore various career options. For instance, if you want to grow a career as a Licensed Security Consultant, you can start with this certificate. Those individuals who want to launch a career as Penetration Testers, Risk Assessment Administrators, Firewall Administrators, System Engineers, Network Managers, Vulnerability Assessment Auditors, Incident Handlers, Cyber Forensic Investigators, or IT Managers can also explore this sought-after certification.


The EC Council Certified Incident Handler (ECIH v2) certification is a highly specialized credential that is designed for professionals who are involved in incident handling, response, and analysis. The certification exam covers a wide range of topics related to incident handling and response, including incident management, computer forensics, and network security. The certification is recognized globally and is highly valued by employers and IT security professionals. If you're interested in pursuing a career in IT security, the ECIH v2 certification is an important credential to consider.

 

NEW QUESTION # 53
Which of the following incident recovery testing methods works by creating a mock disaster, like fire to identify
the reaction of the procedures that are implemented to handle such situations?

  • A. Scenario testing
  • B. Facility testing
  • C. Procedure testing
  • D. Live walk-through testing

Answer: C


NEW QUESTION # 54
Allan performed a reconnaissance attack on his corporate network as part of a red-team activity. He scanned the IP range to find live host IP addresses.
What type of technique did he use to exploit the network?

  • A. Port scanning
  • B. Ping sweeping
  • C. Social engineering
  • D. DNS footprinting

Answer: B


NEW QUESTION # 55
The process of rebuilding and restoring the computer systems affected by an incident to normal operational stage including all the processes, policies and tools is known as:

  • A. Incident Management
  • B. Incident Response
  • C. Incident Handling
  • D. Incident Recovery

Answer: D


NEW QUESTION # 56
The state of incident response preparedness that enables an organization to maximize its potential to use digital evidence while minimizing the cost of an investigation is called:

  • A. Digital Forensic Policy
  • B. Computer Forensics
  • C. Forensic Readiness
  • D. Digital Forensic Analysis

Answer: C


NEW QUESTION # 57
The Linux command used to make binary copies of computer media and as a disk imaging tool if given a raw disk device as its input is:

  • A. "nslookup" command
  • B. "netstat" command
  • C. "dd" command
  • D. "find" command

Answer: C


NEW QUESTION # 58
Which of the following is NOT an image integrity tool?

  • A. MD 5 Calculator
  • B. Hash Calc
  • C. Hash My Files
  • D. Netstat

Answer: D


NEW QUESTION # 59
One of your coworkers just sent you an email. She wonders if it is real, a part of your phishing campaign, a real phishing attack, or a mistake. One of the things you want to know is where the email originated from.
Where would you check in the email message to find that information?

  • A. The user's received report
  • B. Email headers
  • C. Inbox digest
  • D. Email's received report

Answer: B


NEW QUESTION # 60
John, a professional hacker, is attacking an organization, and is trying to destroy the connectivity between an AP and client to make the target unavailable to other wireless devices.
Which of the following attacks is John performing in this case?

  • A. EAP failure
  • B. Disassociation attack
  • C. Denial-of-service
  • D. Routing attack

Answer: C


NEW QUESTION # 61
Nervous Nat often sends emails with screenshots of what he thinks are serious incidents, but they always tum out to be false positives. Today, he sends another screenshot, suspecting a nation-state attack. As usual, you go through your list of questions, check your resources for information to determine whether the screenshot shows a real attack, and determine the condition of your network.
Which step of IR did you just perform?

  • A. Detection and analysis (or identification)
  • B. Remediation
  • C. Recovery
  • D. Preparation

Answer: A


NEW QUESTION # 62
Shall y, an incident handler, is working for a company named Texas Pvt.Ltd.based in Florida. She was asked to work on an incident response plan. As part of the plan, she decided to enhance and improve the security infrastructure of the enterprise. She has incorporated a security strategy that allows security professionals to use several protection layers throughout their information system. Due to multiple layer protection, this security strategy assists in preventing direct attacks against the organization's information system as a break in one layer only leads the attacker to the next layer.
Identify the security strategy Shall y has incorporated in the incident response plan.

  • A. Exponential back off algorithm
  • B. Three-way handshake
  • C. Defense-in-depth
  • D. Covert channels

Answer: C


NEW QUESTION # 63
identify the network security incident where intended or authorized users are prevented from using system, network, or applications by flooding the network with a high volume of traffic that consumes all existing network resources.

  • A. SQL injection
  • B. URL manipulation
  • C. XSS attack
  • D. Denial-of-service

Answer: D


NEW QUESTION # 64
Multiple component incidents consist of a combination of two or more attacks in a system.
Which of the following is not a multiple component incident?

  • A. An attacker infecting a machine to launch a DDoS attack
  • B. An attacker redirecting user to a malicious website and infects his system with Trojan
  • C. An insider intentionally deleting files from a workstation
  • D. An attacker using email with malicious code to infect internal workstation

Answer: C


NEW QUESTION # 65
Qual Tech Solutions is a leading security services enterprise. Dickson, who works as an incident responder with this firm, is performing a vulnerability assessment to identify the security problems in the network by using automated tools for identifying the hosts, services, and vulnerabilities in the enterprise network.
In the above scenario, which of the following types of vulnerability assessment is Dickson performing?

  • A. Passive assessment
  • B. Active assessment
  • C. External assessment
  • D. Internal assessment

Answer: B


NEW QUESTION # 66
An attack on a network is BEST blocked using which of the following?

  • A. IPS device inline
  • B. HIPS
  • C. Load balancer
  • D. Web proxy

Answer: A


NEW QUESTION # 67
Risk is defined as the probability of the occurrence of an incident. Risk formulation generally begins with the likeliness of an event's occurrence, the harm it may cause and is usually denoted as Risk = ∑(events)X(Probability of occurrence)X?

  • A. Consequences
  • B. Probability
  • C. Significance
  • D. Magnitude

Answer: D


NEW QUESTION # 68
Contingency planning enables organizations to develop and maintain effective methods to handle
emergencies. Every organization will have its own specific requirements that the planning should address.
There are five major components of the IT contingency plan, namely supporting information, notification
activation, recovery and reconstitution and plan appendices. What is the main purpose of the reconstitution
plan?

  • A. To define the notification procedures, damage assessments and offers the plan activation
  • B. To provide the introduction and detailed concept of the contingency plan
  • C. To restore the original site, tests systems to prevent the incident and terminates operations
  • D. To provide a sequence of recovery activities with the help of recovery procedures

Answer: C


NEW QUESTION # 69
Common name(s) for CSIRT is(are)

  • A. All the above
  • B. Incident Response Team (IRT)
  • C. Incident Handling Team (IHT)
  • D. Security Incident Response Team (SIRT)

Answer: A


NEW QUESTION # 70
Bran is an incident handler who is assessing the network of the organization. He wants to detect ping sweep attempts on the network using Wire shark.
Which of the following W re shark filters would Bran use to accomplish this task?

  • A. icmp.seq
  • B. icmp.ident
  • C. icmp.redir_gw
  • D. icmp.type== 8

Answer: D


NEW QUESTION # 71
Patrick is performing a cyber forensic investigation. He is in the process of collect ng physical evidence at the crime scene.
Which of the following elements must he consider while collecting physical evidence?

  • A. DNS information including domains and subdomains
  • B. Open ports, services, and operating system (OS) vulnerabilities
  • C. Removable media, cables, and publications
  • D. Published nameservers and web-application source code

Answer: C


NEW QUESTION # 72
One of the main objectives of incident management is to prevent incidents and attacks by tightening the
physical security of the system or infrastructure. According to CERT's incident management process, which
stage focuses on implementing infrastructure improvements resulting from postmortem reviews or other
process improvement mechanisms?

  • A. Detection
  • B. Triage
  • C. Protection
  • D. Preparation

Answer: C


NEW QUESTION # 73
Which of the following terms refers to vulnerable account management functions, including account update, recovery of forgotten or lost passwords, and password reset, that might weaken valid authentication schemes?

  • A. SQL injection
  • B. Directory traversal
  • C. Cross-site scripting
  • D. Broken account management

Answer: D


NEW QUESTION # 74
Ensuring the integrity, confidentiality and availability of electronic protected health information of a patient is known as:

  • A. Social Security Act
  • B. Health Insurance Portability and Privacy Act
  • C. Gramm-Leach-Bliley Act
  • D. Sarbanes-Oxley Act

Answer: B


NEW QUESTION # 75
Incidents such as DDoS that should be handled immediately may be considered as:

  • A. Level Three incident
  • B. Level Two incident
  • C. Level Four incident
  • D. Level One incident

Answer: A


NEW QUESTION # 76
......

Get 2023 Updated Free EC-COUNCIL 212-89 Exam Questions and Answer: https://www.testkingpass.com/212-89-testking-dumps.html

Pass 212-89 Exam Updated 205 Questions: https://drive.google.com/open?id=1RL_wa6J8uXU5XwbIpM1LpRjJRWMOOpal