
Free 212-89 Exam Braindumps - New 2025 EC-COUNCIL Pratice Exam
Practice Test for 212-89 Certification Real 2025 Mock Exam
NEW QUESTION # 58
Which of the following terms refers to vulnerable account management functions, including account update, recovery of forgotten or lost passwords, and password reset, that might weaken valid authentication schemes?
- A. Broken account management
- B. Directory traversal
- C. SQL injection
- D. Cross-site scripting
Answer: A
NEW QUESTION # 59
The following steps describe the key activities in forensic readiness planning:
1. Train the staff to handle the incident and preserve the evidence
2. Create a special process for documenting the procedure
3. Identify the potential evidence required for an incident
4. Determine the source of the evidence
5. Establish a legal advisory board to guide the investigation process
6. Identify if the incident requires full or formal investigation
7. Establish a policy for securely handling and storing the collected evidence
8. Define a policy that determines the pathway to legally extract electronic evidence with minimal disruption Identify the correct sequence of steps involved in forensic readiness planning.
- A. 2-->3-->1-->4-->6-->5-->7-->8
- B. 3-->1-->4-->5-->8-->2-->6-->7
- C. 3-->4-->8-->7-->6-->1-->2-->5
- D. 1-->2-->3-->4-->5-->6-->7-->8
Answer: C
NEW QUESTION # 60
Which of the following techniques helps incident handlers to detect man-in-the-middle attack by finding the new APs and trying to connect an already established channel, even if the spoofed AP consists similar IP and MAC addresses as of the original AP?
- A. Network traffic monitoring
- B. Wireless client monitoring
- C. General wireless traffic monitoring
- D. Access point monitoring
Answer: D
Explanation:
Access point monitoring is the technique that helps incident handlers to detect man-in-the-middle (MitM) attacks by continuously observing and managing the wireless access points (APs) within a network. This includes identifying unauthorized or new APs attempting to connect to the network or mimic existing APs, even if they present similar IP and MAC addresses to legitimate access points. Through access point monitoring, incident handlers can quickly identify and mitigate spoofed APs, thus preventing MitM attacks that exploit wireless networks by intercepting and manipulating communications.
References:Incident Handler (ECIH v3) courses and study materials discuss network security monitoring strategies, including the importance of monitoring access points to detect and prevent MitM attacks and other threats to wireless networks.
NEW QUESTION # 61
SWA Cloud Services added PKI as one of their cloud security controls. What does PKI stand for?
- A. Public key infrastructure
- B. Private key infrastructure
- C. Public key information
- D. Private key in for ma lion
Answer: A
NEW QUESTION # 62
Your company sells SaaS, and your company itself is hosted in the cloud (using it as a PaaS). In case of a malware incident in your customer's database, who is responsible for eradicating the malicious software?
- A. Your company
- B. The PaaS provider
- C. Building management
- D. The customer
Answer: A
Explanation:
In the scenario where your company sells Software as a Service (SaaS) and is hosted on the cloud using it as a Platform as a Service (PaaS), your company is responsible for eradicating malware in your customer's database. This is because, as the SaaS provider, your company manages the software and is responsible for its security and maintenance, including the databases that store customer data. While the PaaS provider is responsible for the underlying infrastructure, platform, and possibly some middleware security aspects, the application layer security, including data and application management, falls to the SaaS provider. Building management would not be involved in digital security matters, and while customers are responsible for their data, the actual software maintenance and security in a SaaS model are the provider's responsibility.
References:Incident Handler (ECIH v3) certification materials often discuss cloud service models (IaaS, PaaS, SaaS) and their associated security responsibilities, highlighting the importance of understanding who is responsible for what in cloud environments.
NEW QUESTION # 63
An estimation of the expected losses after an incident helps organization in prioritizing and formulating their
incident response. The cost of an incident can be categorized as a tangible and intangible cost. Identify the
tangible cost associated with virus outbreak?
- A. Damage to corporate reputation
- B. Lost productivity damage
- C. Psychological damage
- D. Loss of goodwill
Answer: B
NEW QUESTION # 64
Sam. an employee of a multinational company, sends emails to third-party organizations with a spoofed email address of his organization. How can you categorize this type of incident?
- A. Inappropriate usage incident
- B. Denial-of-service incicent
- C. Network intrusion incident
- D. Unauthorized access incident.
Answer: A
NEW QUESTION # 65
Which of the following is not a countermeasure to eradicate inappropriate usage incidents?
- A. Avoiding VPN and other secure network channels
- B. Registering user activity logs and keep monitoring them regularly
- C. Always storing the sensitive data in far located servers and restricting its access
- D. Installing firewall and IDS/IPS to block services that violate the organization's policy
Answer: A
NEW QUESTION # 66
Which of the following risk mitigation strategies involves execution of controls to reduce the risk factor and brings it to an acceptable level or accepts the potential risk and continues operating the IT system?
- A. Risk planning
- B. Risk avoidance
- C. Risk assumption
- D. Risk transference
Answer: C
Explanation:
Risk assumption involves accepting the potential risk and continuing to operate the IT system while implementing controls to reduce the risk to an acceptable level. This strategy acknowledges that some level of risk is inevitable and focuses on managing it through mitigation measures rather than eliminating it entirely.
Risk avoidance would entail taking actions to avoid the risk entirely, risk planning involves preparing for potential risks, and risk transference shifts the risk to another party, typically through insurance or outsourcing.
Risk assumption is a pragmatic approach that balances the need for operational continuity with the imperative of risk management.References:The ECIH v3 certification program covers various risk mitigation strategies, emphasizing the selection of the appropriate approach based on the organization's risk tolerance and the specific context of the threat.
NEW QUESTION # 67
An incident recovery plan is a statement of actions that should be taken before, during or after an incident.
Identify which of the following is NOT an objective of the incident recovery plan?
- A. Avoiding the legal liabilities arising due to incident
- B. Creating new business processes to maintain profitability after incident
- C. Providing assurance that systems are reliable
- D. Providing a standard for testing the recovery plan
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION # 68
Michael is an incident handler at CyberTech Solutions. He is performing detection and analysis of a cloud security incident. He is also analyzing the file systems, slack spaces, and metadata within the storage units to find hidden malware and evidence of malice.
Identify the cloud security incident handled by Michael:
- A. Application-related incident
- B. Network-related incident
- C. Storage-related incident
- D. Server-related incident
Answer: C
NEW QUESTION # 69
Racheal is an incident handler working at an organization called Inception Tech. Recently, numerous employees have been complaining about receiving emails from unknown senders. In order to prevent employees from spoof ng emails and keeping security in mind, Racheal was asked to take appropriate actions in this matter. As a part of her assignment, she needs to analyze the email headers to check the authenticity of received emails.
Which of the following protocol/authentication standards she must check in email header to analyze the email authenticity?
- A. POP
- B. DKIM
- C. SNMP
- D. ARP
Answer: B
NEW QUESTION # 70
Jacob is an employee at a firm called Dolphin Investment. While he was on duty, he identified that his computer was facing some problems, and he wanted to convey the issue to the concerned authority in his organization. However, this organization currently does not have a ticketing system to address such types of issues. In the above scenario, which of the following ticketing systems can be employed by Dolphin Investment to allow Jacob to inform the concerned team about the incident?
- A. MISP
- B. ManageEngine ServiceDesk Plus
- C. ThreatConnect
- D. IBM XForco Exchange
Answer: B
NEW QUESTION # 71
Your manager hands you several items of digital evidence and asks you to investigate them in the order of volatility. Which of the following is the MOST volatile?
- A. Disk
- B. Temp files
- C. Cache
- D. Emails
Answer: C
NEW QUESTION # 72
Which of the following port scanning techniques involves resetting the TCP connection between client and server abruptly before completion of the three-way handshake signals, making the connection half-open?
- A. Null scan
- B. Stealth scan
- C. Full connects can
- D. Xmas scan
Answer: D
NEW QUESTION # 73
Alexis works as an incident responder at XYZ organization. She was asked to identify and attributethe actors behind an attack that occurred recently. For this purpose, she is performing a type of threat attribution that deals with the identification of a specific person, society, or country sponsoring a well-planned and executed intrusion or attack on its target. Which of the following types of threat attributions is Alexis performing?
- A. Nation-state attribution
- B. Campaign attribution
- C. Intrusion set attribution
- D. True attribution
Answer: A
Explanation:
Nation-state attribution involves identifying a specific country or government as the sponsor behind a cyber-attack or intrusion. This type of threat attribution is focused on determining the involvement of state actors in cyber operations against specific targets, which often involves sophisticated, well-planned, and executed cyber campaigns. Alexis's efforts to identify and attribute the actors behind the attack to a specific nation-state fall under this category, as she seeks to uncover the geopolitical motives and the extent of state sponsorship behind the incident. Nation-state attribution requires analyzing a variety of indicators, including technical evidence, tactics, techniques, and procedures (TTPs), and contextual intelligence. This is distinct from campaign attribution, which focuses on linking attacks to a specific campaign or operation, true attribution, which aims at identifying the actual individuals behind an attack, and intrusion set attribution, which involves attributing a set of malicious activities to a particular threat actor or group.References:The Incident Handler (ECIH v3) certification program includes discussions on various types of threat attributions, highlighting the challenges and methodologies involved in attributing cyber-attacks to specific actors, including nation-states.
NEW QUESTION # 74
Rica works as an incident handler for an international company. As part of her role, she must review the present security policy implemented. Upon inspection, Rica finds that the policy is wide open, and only known dangerous services/attacks or behaviors are blocked.
Which of the following is the current policy that Rica identified?
- A. Promiscuous policy
- B. Paranoid policy
- C. Prudent policy
- D. Permissive policy
Answer: D
NEW QUESTION # 75
An organization implemented an encoding technique to eradicate SQL injection attacks. In this technique, if a user submits a request using single-quote and some values, the encoding technique will convert it into numeric digits and letters ranging from "a" to "f". This prevents the user request from performing a SQL injection attempt on the web application.
Identify the encoding technique used by the organization.
- A. Hex encoding
- B. Base 64 encoding
- C. Unicode encoding
- D. URL encoding
Answer: A
NEW QUESTION # 76
In a qualitative risk analysis, risk is calculated in terms of:
- A. (Countermeasures + Magnitude of Impact) - (Reports from prior risk assessments)
- B. Asset criticality assessment - (Risks and Associated Risk Levels)
- C. Probability of Loss X Loss
- D. (Attack Success + Criticality ) -(Countermeasures)
Answer: C
NEW QUESTION # 77
Multiple component incidents consist of a combination of two or more attacks in a system.
Which of the following is not a multiple component incident?
- A. An insider intentionally deleting files from a workstation
- B. An attacker redirecting user to a malicious website and infects his system with Trojan
- C. An attacker using email with malicious code to infect internal workstation
- D. An attacker infecting a machine to launch a DDoS attack
Answer: A
NEW QUESTION # 78
A user downloaded what appears to be genuine software. Unknown to her, when she installed the application, it executed code that provided an unauthorized remote attacker access to her computer.
What type of malicious threat displays this characteristic?
- A. Backdoor
- B. Trojan
- C. Virus
- D. Spyware
Answer: B
NEW QUESTION # 79
Andrew, an incident responder, is performing risk assessment of the client organization.
As a part of risk assessment process, he identified the boundaries of the IT systems, along with the resources and the information that constitute the systems.
Identify the risk assessment step Andrew is performing.
- A. System characterization
- B. Likelihood determination
- C. Control recommendations
- D. Control analysis
Answer: A
NEW QUESTION # 80
Raven is a part of an IH&R team and was informed by her manager to handle and lead the removal of the root cause for an incident and to close all attack vectors to prevent similar incidents in the future. Raven notifies the service providers and developers of affected resources. Which of the following steps of the incident handling and response process does Raven need to implement to remove the root cause of the incident?
- A. Incident triage
- B. Evidence gathering and forensic analysis
- C. Eracicotion
- D. Containment
Answer: C
NEW QUESTION # 81
Which of the following is NOT one of the Computer Forensic types:
- A. Image Forensics
- B. Email Forensics
- C. Forensic Archaeology
- D. USB Forensics
Answer: C
NEW QUESTION # 82
......
Prepare For Realistic 212-89 Dumps PDF - 100% Passing Guarantee: https://www.prepawaytest.com/EC-COUNCIL/212-89-practice-exam-dumps.html
Check the Available 212-89 Exam Dumps with 174 QA's: https://drive.google.com/open?id=1pq3xQgU7YPOdhGnH77E0flyuHmBn9I2e