最新的EC-COUNCIL EC Council Certified Incident Handler (ECIH v3) - 212-89免費考試真題
An incident handler is performing security scanning on an Ubuntu Linux system using buck- security to identify potential vulnerabilities. The handler runs the command "./buck-security" and receives a list of warning messages. Among the warnings, the handler finds an issue under the
[3] CHECK firewall: Check firewall policies section. Considering the handler's main objective is to validate and classify the security incident, what should be their next course of action?
[3] CHECK firewall: Check firewall policies section. Considering the handler's main objective is to validate and classify the security incident, what should be their next course of action?
正確答案: C
NovoMed, a pharmaceutical giant, recently launched a drug after 10 years of research. A week later, their systems were compromised. Forensics revealed encrypted data transfers to an unknown location. The encrypted data consisted of the drug's research files, trials, and participant data. Additionally, the company's communication systems received a message in broken English, hinting at releasing the drug's formula. Which is the most prudent course of action?
正確答案: C
說明:(僅 Fast2test 成員可見)
A US Federal Agency network was the target of a DoS attack that prevented and impaired the normal authorized functionality of the networks. According to agency's reporting timeframe guidelines, this incident should be reported within 2 h of discovery/detection if the successful attack is still ongoing and the agency is unable to successfully mitigate the activity.
Which incident category of US Federal Agency does this incident belong to?
Which incident category of US Federal Agency does this incident belong to?
正確答案: A
說明:(僅 Fast2test 成員可見)
Which of the following techniques helps incident handlers to detect man-in-the-middle attack by finding the new APs and trying to connect an already established channel, even if the spoofed AP consists similar IP and MAC addresses as of the original AP?
正確答案: C
說明:(僅 Fast2test 成員可見)
Which of the following best describes the potential failure to meet goals due to constraints related to security, costs, or technology-resulting in negative impacts on an organization's performance or revenue?
正確答案: D
說明:(僅 Fast2test 成員可見)
Which of the following port scanning techniques involves resetting the TCP connection between client and server abruptly before completion of the three-way handshake signals, making the connection half-open?
正確答案: D
說明:(僅 Fast2test 成員可見)
Which of the following is a term that describes the combination of strategies and services intended to restore data, applications, and other resources to the public cloud or dedicated service providers?
正確答案: B
說明:(僅 Fast2test 成員可見)
A global manufacturing company detected unauthorized privilege escalation on one of its OT workstations connected to critical production systems. The IH&R team must respond without alerting the attacker or risking deletion of forensic artifacts. The attacker's persistence mechanisms and data exfiltration activity are not yet fully identified. The CISO instructs the team to implement a strategy that limits the threat's lateral movement without tipping off the adversary.
Which of the following containment actions best aligns with this objective?
Which of the following containment actions best aligns with this objective?
正確答案: A
說明:(僅 Fast2test 成員可見)
Which of the following is not called volatile data?
正確答案: A
說明:(僅 Fast2test 成員可見)
Chandler is a professional hacker who is targeting Technote organization. He wants to obtain important organizational information that is being transmitted between different hierarchies. In the process, he is sniffing the data packets transmitted through the network and then analyzing them to gather packet details such as network, ports, protocols, devices, issues in network transmission, and other network specifications. Which of the following tools Chandler must employ to perform packet analysis?
正確答案: B