Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

Latest 212-89 Exam Real Tests Free Updated Today [Q51-Q68]

Share

Latest 212-89 Exam Real Tests Free Updated Today

212-89 Real Exam Question Answers Updated [Nov 28, 2021]

NEW QUESTION 51
What command does a Digital Forensic Examiner use to display the list of all open ports and the associated IP addresses on a victim computer to identify the established connections on it:

  • A. "netstat -an" command
  • B. "dd" command
  • C. "ifconfig" command
  • D. "arp" command

Answer: A

 

NEW QUESTION 52
The correct sequence of incident management process is:

  • A. Prepare, protect, triage, detect and respond
  • B. Prepare, protect, detect, respond and triage
  • C. Prepare, detect, protect, triage and respond
  • D. Prepare, protect, detect, triage and respond

Answer: D

 

NEW QUESTION 53
Incident handling and response steps help you to detect, identify, respond and manage an incident. Which of the following helps in recognizing and separating the infected hosts from the information system?

  • A. Inspecting the process running on the system
  • B. Sending mails to only group of friends
  • C. Browsing particular government websites
  • D. Configuring firewall to default settings

Answer: A

 

NEW QUESTION 54
Electronic evidence may reside in the following:

  • A. Data Files
  • B. Backup tapes
  • C. Other media sources
  • D. All the above

Answer: D

 

NEW QUESTION 55
Incident handling and response steps help you to detect, identify, respond and manage an incident. Which of the following steps focus on limiting the scope and extent of an incident?

  • A. Identification
  • B. Data collection
  • C. Eradication
  • D. Containment

Answer: D

 

NEW QUESTION 56
An incident is analyzed for its nature, intensity and its effects on the network and systems. Which stage of the incident response and handling process involves auditing the system and network log files?

  • A. Containment
  • B. Reporting
  • C. Identification
  • D. Incident recording

Answer: C

 

NEW QUESTION 57
The main difference between viruses and worms is:

  • A. Viruses and worms are common names for the same malware
  • B. Worms require a host file to propagate while viruses don't
  • C. Viruses require a host file to propagate while Worms don't
  • D. Viruses don't require user interaction; they are self-replicating malware

Answer: C

 

NEW QUESTION 58
Multiple component incidents consist of a combination of two or more attacks in a system. Which of the following is not a multiple component incident?

  • A. An attacker redirecting user to a malicious website and infects his system with Trojan
  • B. An attacker using email with malicious code to infect internal workstation
  • C. An attacker infecting a machine to launch a DDoS attack
  • D. An insider intentionally deleting files from a workstation

Answer: D

 

NEW QUESTION 59
A malware code that infects computer files, corrupts or deletes the data in them and requires a host file to propagate is called:

  • A. Worm
  • B. RootKit
  • C. Trojan
  • D. Virus

Answer: D

 

NEW QUESTION 60
Which of the following is a correct statement about incident management, handling and response:

  • A. Incident response is one of the services provided by triage
  • B. Incident response is on the functions provided by incident handling
  • C. Incident handling is on the functions provided by incident response
  • D. Triage is one of the services provided by incident response

Answer: B

 

NEW QUESTION 61
Incident management team provides support to all users in the organization that are affected by the threat or attack. The organization's internal auditor is part of the incident response team. Identify one of the responsibilities of the internal auditor as part of the incident response team:

  • A. Configure information security controls
  • B. Perform necessary action to block the network traffic from suspected intruder
  • C. Identify and report security loopholes to the management for necessary actions
  • D. Coordinate incident containment activities with the information security officer

Answer: C

 

NEW QUESTION 62
Risk management consists of three processes, risk assessment, mitigation and evaluation. Risk assessment determines the extent of the potential threat and the risk associated with an IT system through its SDLC. How many primary steps does NIST's risk assessment methodology involve?

  • A. Four
  • B. Twelve
  • C. Six
  • D. Nine

Answer: D

 

NEW QUESTION 63
________________ attach(es) to files

  • A. adware
  • B. Worms
  • C. Spyware
  • D. Viruses

Answer: D

 

NEW QUESTION 64
The ability of an agency to continue to function even after a disastrous event, accomplished through the deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy is known as:

  • A. Business Continuity Plan
  • B. Disaster Planning
  • C. Business Continuity
  • D. Contingency Planning

Answer: C

 

NEW QUESTION 65
___________________ record(s) user's typing.

  • A. Malware
  • B. adware
  • C. Spyware
  • D. Virus

Answer: C

 

NEW QUESTION 66
Insider threats can be detected by observing concerning behaviors exhibited by insiders, such as conflicts with
supervisors and coworkers, decline in performance, tardiness or unexplained absenteeism. Select the
technique that helps in detecting insider threats:

  • A. Protecting computer systems by implementing proper controls
  • B. Making is compulsory for employees to sign a none disclosure agreement
  • C. Correlating known patterns of suspicious and malicious behavior
  • D. Categorizing information according to its sensitivity and access rights

Answer: C

Explanation:
Explanation

 

NEW QUESTION 67
Digital evidence must:

  • A. Not prove the attackers actions
  • B. Cast doubt on the authenticity and veracity of the evidence
  • C. Be Authentic, complete and reliable
  • D. Be Volatile

Answer: C

 

NEW QUESTION 68
......


What Are Domains Covered by ECIH Test?

Overall, this certification exam has nine domains that have a specific weightage in the official validation. The candidates who take this exam need to master the following topics:

  • Process handling 14%;
  • Email security incidents 10%;
  • Mobile & network incidents 16%;
  • First response and forensic readiness 13%.
  • Cloud environment incidents 8%;
  • Malware incidents 8%;
  • Insider threats 7%;
  • Incident handling and response 16%;
  • Application-level incidents 8%;

 

Latest 212-89 Study Guides 2021 - With Test Engine PDF: https://www.validexam.com/212-89-latest-dumps.html

Easily To Pass New EC-COUNCIL 212-89 Dumps with 165 Questions: https://drive.google.com/open?id=1gnWYyR2RyfxbPeD4tO69a-9VlBvz2pm3