
[Oct 14, 2023] Fully Updated ECIH Certification (212-89) Certification Sample Questions
Latest EC-COUNCIL 212-89 Real Exam Dumps PDF
NEW QUESTION # 98
Identify the malicious program that is masked as a genuine harmless program and gives the attacker unrestricted access to the user's information and system. These programs may unleash dangerous programs that may erase the unsuspecting user's disk and send the victim's credit card numbers and passwords to a stranger.
- A. Trojan
- B. Cookie tracker
- C. Worm
- D. Virus
Answer: A
NEW QUESTION # 99
Stanley works as an incident responder at a top MNC based in Singapore. He was asked to investigate a cybersecurity incident that recently occurred in the company. While investigating the incident, he collected evidence from the victim systems. He must present this evidence in a clear and comprehensible manner to the members of a jury so that the evidence clarifies the facts and further helps in obtaining an expert opinion on the incident to conf rm the investigation process.
In the above scenario, which of the following characteristics of the digital evidence did Stanley attempt to preserve?
- A. Authenticity
- B. Completeness
- C. Believability
- D. Admissibility
Answer: C
NEW QUESTION # 100
Your company sells SaaS, and your company itself is hosted in the cloud (using it as a PaaS).
In case of a malware incident in your customer's database, who is responsible for eradicating the malicious software?
- A. Your company
- B. The PaaS provider
- C. Building management
- D. The customer
Answer: A
NEW QUESTION # 101
Identify the network security incident where intended authorized users are prevented from using system, network, or applications by flooding the network with high volume of traffic that consumes all existing network resources.
- A. SQL Injection
- B. XSS Attack
- C. Denial of Service Attack
- D. URL Manipulation
Answer: C
NEW QUESTION # 102
The message that is received and requires an urgent action and it prompts the recipient to delete certain files or forward it to others is called:
- A. A Virus Hoax
- B. An Adware
- C. Mail bomb
- D. Spear Phishing
Answer: A
NEW QUESTION # 103
Jacobi san employee at a firm called Dolphin Investment. While he was on duty, he identified that his computer was facing some problems, and he wanted to convey the issue to the c once med authority in his organization. However, this organization currently does not have a ticketing system to address such types of issues.
In the above scenario, which of the following ticketing systems can be employed by Dolphin Investment to allow Jacob to inform the c once med team about the incident?
- A. IBM X Force Exchange
- B. Threat Connect
- C. MISP
- D. ManageEngine ServiceDesk Plus
Answer: D
NEW QUESTION # 104
Which of the following methods help incident responders to reduce the false positive alert rates and further provide ben efts of focusing on top priority issues, thereby reducing potential risk and corporate liabilities?
- A. Threat attribution
- B. Threat co relation
- C. Threat profiling
- D. Threat contextualization
Answer: B
NEW QUESTION # 105
Which of the following is NOT a network forensic tool?
- A. Wire shark
- B. Caps a Network Analyzer
- C. Advanced NTFS Journaling Parser
- D. Tcpdump
Answer: C
NEW QUESTION # 106
Sam, an employee of a multinational company, sends emails to third-party organizations with a spoofed email address of his organization.
How can you categorize this type of incident?
- A. Network intrusion incident
- B. Inappropriate usage incident
- C. Denial-of-service incident
- D. Unauthorized access incident
Answer: B
NEW QUESTION # 107
Computer forensics is methodical series of techniques and procedures for gathering evidence from computing
equipment, various storage devices and or digital media that can be presented in a course of law in a coherent
and meaningful format. Which one of the following is an appropriate flow of steps in the computer forensics
process:
- A. Preparation > Analysis > Collection > Examination > Reporting
- B. Preparation > Collection > Examination > Analysis > Reporting
- C. Analysis > Preparation > Collection > Reporting > Examination
- D. Examination> Analysis > Preparation > Collection > Reporting
Answer: B
NEW QUESTION # 108
The free, open source, TCP/IP protocol analyzer, sniffer and packet capturing utility standard across many industries and educational institutions is known as:
- A. Snort
- B. Cain & Able
- C. Wireshark
- D. nmap
Answer: C
NEW QUESTION # 109
Smith employs various malware detection techniques to thoroughly examine the network and its systems for suspicious and malicious malware files.
Among all techniques, which one involves analyzing the memory dumps or binary codes for the traces of malware?
- A. Live system
- B. Dynamic analysis
- C. Intrusion analysis
- D. Static analysis
Answer: D
NEW QUESTION # 110
The steps followed to recover computer systems after an incident are:
- A. System restoration, operation, validation, and monitoring
- B. System monitoring, validation, operation and restoration
- C. System restoration, validation, operation and monitoring
- D. System validation, restoration, operation and monitoring
Answer: C
NEW QUESTION # 111
According to the Evidence Preservation policy, a forensic investigator should make at least ..................... image
copies of the digital evidence.
- A. One image copy
- B. Two image copies
- C. Three image copies
- D. Four image copies
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION # 112
A self-replicating virus does not alter files but resides inactive memory and duplicates itself. It takes advantage of file or information transport features on the system to travel independently.
What is this type of object called?
- A. Trojan
- B. Adware
- C. Spyware
- D. Worm
Answer: D
NEW QUESTION # 113
......
EC-COUNCIL 212-89 Dumps - Secret To Pass in First Attempt: https://actualtests.passsureexam.com/212-89-pass4sure-exam-dumps.html