• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 123 pages
Exam (elaborations)

Certified Incident Handler – Complete Exam Preparation Q&A Guide with Accurate Answers

Document preview thumbnail
Preview 4 out of 123 pages

This document provides a comprehensive set of practice questions and verified answers tailored for the Certified Incident Handler (EC-Council E|CIH) exam. It covers critical areas such as the incident response lifecycle, risk assessment, containment and eradication strategies, log analysis, malware handling, and organizational policies. Ideal for candidates preparing for certification or enhancing their practical incident handling skills.

Content preview

Certified Incident Handler (CIH) |608 Practice
Questions with accurate answers
A computer Risk Policy is a set of ideas to be implemented to overcome
the risk associated with computer security incidents. Identify the
procedure that is NOT part of the computer risk policy?
Ans✓✓✓Procedure for the ongoing training of employees authorized to
access the system


A distributed Denial of Service (DDoS) attack is a more common type
of DoS Attack, where a single system is targeted by a large number of
infected machines over the Internet. In a DDoS attack, attackers first
infect multiple systems which are known as: Ans✓✓✓Zombies


A threat source does not present a risk if NO vulnerability that can be
exercised for a particular threat source. Identify the step in which
different threat sources are defined: Ans✓✓✓Threat identification


A US Federal agency network was the target of a DoS attack that
prevented and impaired the normal authorized functionality of the
networks. According to agency's reporting timeframe guidelines, this
incident should be reported within two (2) HOURS of
discovery/detection if the successful attack is still ongoing and the
agency is unable to successfully mitigate the activity. Which incident
category of the US Federal Agency does this incident belong to?
Ans✓✓✓CAT 2


Abel, the IH&R team lead at a financial organization, was tasked with
investigating a security incident that occurred on the organization's web

,server. During the investigation, he classified incidents based on their
impact on the organizational assets and prioritized them as critical
incidents.


Which of the following OWASP best practices did Abel adopt in the
above scenario? Ans✓✓✓Triage and mitigation


According to MITRE ATT&CK framework, in which of the following
phases do attackers gather information both actively and passively about
the target system or network? Ans✓✓✓Reconnaissance


According to OWASP best practices, which of the following is a
significant step in restoring services or materials that have been affected
during an incident? Ans✓✓✓Recovery


According to the MITRE ATT&CK framework, identify the phase in
which attackers gain primary control to the target network by exploiting
vulnerabilities. Ans✓✓✓Initial Access


Adam, an incident handler, was tasked with performing live system
analysis on a suspected Windows machine. Through the preliminary
analysis, Adam determined that the malware is accessing a malicious
port. To further monitor and analyze the malware activities, he
employed a port monitoring tool that shows detailed listings of all the
connection endpoints on the system.

,Identify the tool employed by Adam in the above scenario.
Ans✓✓✓TCPView


Alex, an IH&R team member, was attempting to prevent malware
infections from spreading through a malicious file. Therefore, he
completely deleted the malicious file and changed the server
authentication credentials to sanitize the system before restoring it.


Which of the following RE&CT framework phases was Alex performing
in the above scenario? Ans✓✓✓Eradication


Alice, a software professional browsing the official website of an
advertising company, saw a message revealing important information
about the database associated with the website. Using this information,
Alice can perform a code-injection attack on the website and manipulate
the application components.


Identify the vulnerability identified by Alice in the above scenario to
access the database. Ans✓✓✓Errors


An audit trail policy collects all audit trails such as series of records of
computer events, about an operating system, application or user
activities. Which of the following statements is NOT true for an audit
trail policy: Ans✓✓✓It helps calculating intangible losses to the
organization due to incident

, An IH&R team was attempting to handle a security incident that
occurred on the core server of a client organization. Subsequently, the
team immediately launched analysis, recovery, and patch management
tools to quickly mitigate the incident and recover the server to its pre-
incident state.


Identify the OODA loop phase performed by the IH&R team in the
above scenario. Ans✓✓✓Act


An incident is analyzed for its nature, intensity and its effects on the
network and systems. Which stage of the incident response and handling
process involves auditing the system and network log files?
Ans✓✓✓Identification


An incident recovery plan is a statement of actions that should be taken
before, during or after an incident. Identify which of the following is
NOT an objective of the incident recovery plan? Ans✓✓✓Creating new
business processes to maintain profitability after incident


An organization faced an information security incident where a
disgruntled employee passed sensitive access control information to a
competitor. The organization's incident response manager, upon
investigation, found that the incident must be handled within a few hours
on the same day to maintain business continuity and market
competitiveness. How would you categorize such information security
incident? Ans✓✓✓High level incident

Document information

Uploaded on
June 26, 2025
Number of pages
123
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$19.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
cracker
3.8
(401)
Sold
2168
Followers
1346
Items
50099
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions