Exam2pass
0 items Sign In or Register
  • Home
  • IT Exams
  • Guarantee
  • FAQs
  • Reviews
  • Contact Us
  • Demo
Exam2pass > EC-COUNCIL > EC-COUNCIL Certifications > 212-89 > 212-89 Online Practice Questions and Answers

212-89 Online Practice Questions and Answers

Questions 4

An organization faced an information security incident where a disgruntled employee passed sensitive access control information to a competitor. The organization's incident response manager, upon investigation, found that the incident must be handled within a few hours on the same day to maintain business continuity and market competitiveness. How would you categorize such information security incident?

A. High level incident

B. Middle level incident

C. Ultra-High level incident

D. Low level incident

Buy Now

Correct Answer: B

Questions 5

When an employee is terminated from his or her job, what should be the next immediate step taken by an organization?

A. All access rights of the employee to physical locations, networks, systems, applications and data should be disabled

B. The organization should enforce separation of duties

C. The access requests granted to an employee should be documented and vetted by the supervisor

D. The organization should monitor the activities of the system administrators and privileged users who have permissions to access the sensitive information

Buy Now

Correct Answer: A

Questions 6

A computer virus hoax is a message warning the recipient of non-existent computer virus. The message is usually a chain e-mail that tells the recipient to forward it to every one they know. Which of the following is NOT a symptom of virus hoax message?

A. The message prompts the end user to forward it to his / her e-mail contact list and gain monetary benefits in doing so

B. The message from a known email id is caught by SPAM filters due to change of filter settings

C. The message warns to delete certain files if the user does not take appropriate action

D. The message prompts the user to install Anti-Virus

Buy Now

Correct Answer: A

Questions 7

An information security incident is

A. Any real or suspected adverse event in relation to the security of computer systems or networks

B. Any event that disrupts normal today's business functions

C. Any event that breaches the availability of information assets

D. All of the above

Buy Now

Correct Answer: D

Questions 8

Removing or eliminating the root cause of the incident is called:

A. Incident Eradication

B. Incident Protection

C. Incident Containment

D. Incident Classification

Buy Now

Correct Answer: A

Questions 9

________________ attach(es) to files

A. adware

B. Spyware

C. Viruses

D. Worms

Buy Now

Correct Answer: C

Questions 10

A self-replicating malicious code that does not alter files but resides in active memory and duplicates itself, spreads through the infected network automatically and takes advantage of file or information transport features on the system to travel independently is called:

A. Trojan

B. Worm

C. Virus

D. RootKit

Buy Now

Correct Answer: B

Questions 11

A malicious security-breaking code that is disguised as any useful program that installs an executable programs when a file is opened and allows others to control the victim's system is called:

A. Trojan

B. Worm

C. Virus

D. RootKit

Buy Now

Correct Answer: A

Questions 12

A Host is infected by worms that propagates through a vulnerable service; the sign(s) of the presence of the worm include:

A. Decrease in network usage

B. Established connection attempts targeted at the vulnerable services

C. System becomes instable or crashes

D. All the above

Buy Now

Correct Answer: C

Questions 13

According to the Fourth Amendment of USA PATRIOT Act of 2001; if a search does NOT violate a person's "reasonable" or "legitimate" expectation of privacy then it is considered:

A. Constitutional/ Legitimate

B. Illegal/ illegitimate

C. Unethical

D. None of the above

Buy Now

Correct Answer: A

Exam Code: 212-89
Exam Name: EC-Council Certified Incident Handler (ECIH)
Last Update: Jun 13, 2025
Questions: 163

PDF (Q&A)

$45.99
ADD TO CART

VCE

$49.99
ADD TO CART

PDF + VCE

$59.99
ADD TO CART

Exam2Pass----The Most Reliable Exam Preparation Assistance

There are tens of thousands of certification exam dumps provided on the internet. And how to choose the most reliable one among them is the first problem one certification candidate should face. Exam2Pass provide a shot cut to pass the exam and get the certification. If you need help on any questions or any Exam2Pass exam PDF and VCE simulators, customer support team is ready to help at any time when required.

Home | Guarantee & Policy |  Privacy & Policy |  Terms & Conditions |  How to buy |  FAQs |  About Us |  Contact Us |  Demo |  Reviews

2025 Copyright @ exam2pass.com All trademarks are the property of their respective vendors. We are not associated with any of them.