Free May-2024 212-89 Certification Sample Questions certification Exam [Q33-Q48]

Share

Free May-2024 212-89 Certification Sample Questions certification Exam

Certification Topics of 212-89 Exam PDF Recently Updated Questions

NEW QUESTION # 33
Which of the following techniques helps incident handlers detect man-in-the-middle attacks by finding the new APs and trying to connect an already established channel, even if the spoofed AP consists of similar IP and MAC addresses as the original AP?

  • A. General wireless traffic monitoring
  • B. Network traffic monitoring
  • C. Wireless client monitoring
  • D. Access point monitoring

Answer: D


NEW QUESTION # 34
In the Control Analysis stage of the NIST's risk assessment methodology, technical and none technical control methods are classified into two categories. What are these two control categories?

  • A. Preventive and predictive controls
  • B. Preventive and Detective controls
  • C. Detective and Disguised controls
  • D. Predictive and Detective controls

Answer: B


NEW QUESTION # 35
In which of the following phases of the incident handling and response (IH&R) process is the identified security incidents analyzed, validated, categorized, and prioritized?

  • A. Incident triage
  • B. Notification
  • C. Containment
  • D. Incident recording and assignment

Answer: A


NEW QUESTION # 36
___________________ record(s) user's typing.

  • A. Spyware
  • B. Malware
  • C. Virus
  • D. adware

Answer: A


NEW QUESTION # 37
Michael is a part of the computer incident response team of a company. One of his responsibilities is to handle email incidents. The company receives an email from an unknown source, and one of the steps that he needs to take is to check the validity of the email.
Which of the following tools should he use?

  • A. Email Dossier
  • B. Yes ware
  • C. Zendio
  • D. G Suite Toolbox

Answer: A


NEW QUESTION # 38
An access control policy authorized a group of users to perform a set of actions on a set of resources. Access to resources is based on necessity and if a particular job role requires the use of those resources. Which of the following is NOT a fundamental element of access control policy

  • A. Action group: group of actions performed by the users on resources
  • B. Access group: group of users to which the policy applies
  • C. Resource group: resources controlled by the policy
  • D. Development group: group of persons who develop the policy

Answer: D


NEW QUESTION # 39
An information security policy must be:

  • A. All the above
  • B. Written in simple language
  • C. Distributed and communicated
  • D. Enforceable and Regularly updated

Answer: A


NEW QUESTION # 40
The main difference between viruses and worms is:

  • A. Viruses require a host file to propagate while Worms don't
  • B. Worms require a host file to propagate while viruses don't
  • C. Viruses and worms are common names for the same malware
  • D. Viruses don't require user interaction; they are self-replicating malware

Answer: A


NEW QUESTION # 41
Which of the following is NOT a network forensic tool?

  • A. Wire shark
  • B. Caps a Network Analyzer
  • C. Tcpdump
  • D. Advanced NTFS Journaling Parser

Answer: D


NEW QUESTION # 42
Bonney's system has been compromised by a gruesome malware.
What is the primary step that is advisable to Bonney in order to contain the malware incident from spreading?
What is the cause of this issue?

  • A. Turnoff the infected machine
  • B. Complaint to police in a formal way regarding the incident
  • C. Call the legal department in the organization and info m about the incident
  • D. Leave it to the network administrators to handle

Answer: A


NEW QUESTION # 43
Jacobi san employee at a firm called Dolphin Investment. While he was on duty, he identified that his computer was facing some problems, and he wanted to convey the issue to the c once med authority in his organization. However, this organization currently does not have a ticketing system to address such types of issues.
In the above scenario, which of the following ticketing systems can be employed by Dolphin Investment to allow Jacob to inform the c once med team about the incident?

  • A. Threat Connect
  • B. ManageEngine ServiceDesk Plus
  • C. MISP
  • D. IBM X Force Exchange

Answer: B


NEW QUESTION # 44
One of your coworkers just sent you an email. She wonders if it is real, a part of your phishing campaign, a real phishing attack, or a mistake. One of the things you want to know is where the email originated from.
Where would you check in the email message to find that information?

  • A. Email's received report
  • B. Inbox digest
  • C. The user's received report
  • D. Email headers

Answer: D


NEW QUESTION # 45
Which among the following CERTs is an Internet provider to higher education institutions and various other research institutions in the Netherlands and deals with all cases related to computer security incidents in which a customer is involved either as a victim or as a suspect?

  • A. DFN-CERT
  • B. SURFnet-CERT
  • C. NET-CERT
  • D. Funet CERT

Answer: B


NEW QUESTION # 46
Except for some common roles, the roles in an IRT are distinct for every organization. Which among the following is the role played by the Incident Coordinator of an IRT?

  • A. Focuses on the incident and handles it from management and technical point of view
  • B. Applies the appropriate technology and tries to eradicate and recover from the incident
  • C. Links the groups that are affected by the incidents, such as legal, human resources, different business areas and management
  • D. Links the appropriate technology to the incident to ensure that the foundation's offices are returned to normal operations as quickly as possible

Answer: C


NEW QUESTION # 47
Which of the following processes is referred to as an approach to respond to the security incidents that occur in an organization and enables the response team by ensuring that they know exactly what process to follow in case of security incidents?

  • A. Risk assessment
  • B. Threat assessment
  • C. Incident response orchestration
  • D. Vulnerability management

Answer: C


NEW QUESTION # 48
......


EC-Council Certified Incident Handler (ECIH v2) exam is designed to provide hands-on experience and knowledge to handle various types of incidents, including network security incidents, malicious code incidents, and insider attack threats. 212-89 exam is conducted by the International Council of E-Commerce Consultants (EC-Council), which is a leading provider of information security certifications.


EC-COUNCIL 212-89 (EC Council Certified Incident Handler (ECIH v2)) exam is a valuable certification for professionals in the field of incident handling and response. It covers a wide range of topics and validates the candidate's ability to identify, respond to, and resolve security incidents effectively. EC Council Certified Incident Handler (ECIH v2) certification is recognized worldwide and is vendor-neutral, making it a versatile credential that can be applied in various industries and organizations.

 

2024 New Preparation Guide of EC-COUNCIL 212-89 Exam: https://examtorrent.actualtests4sure.com/212-89-practice-quiz.html