
EC-COUNCIL 212-89 Practice Verified Answers - Pass Your Exams For Sure! [2021]
Valid Way To Pass ECIH Certification's 212-89 Exam
Career Prospects
After earning the ECIH certification, the certified professionals can explore various career options. For instance, if you want to grow a career as a Licensed Security Consultant, you can start with this certificate. Those individuals who want to launch a career as Penetration Testers, Risk Assessment Administrators, Firewall Administrators, System Engineers, Network Managers, Vulnerability Assessment Auditors, Incident Handlers, Cyber Forensic Investigators, or IT Managers can also explore this sought-after certification.
NEW QUESTION 93
An assault on system security that is derived from an intelligent threat is called:
- A. Threat Agent
- B. Risk
- C. Attack
- D. Vulnerability
Answer: C
NEW QUESTION 94
Incident may be reported using/ by:
- A. Phone call
- B. All the above
- C. Facsimile (Fax)
- D. Email or on-line Web form
Answer: B
NEW QUESTION 95
Identify the malicious program that is masked as a genuine harmless program and gives the attacker unrestricted access to the user's information and system. These programs may unleash dangerous programs that may erase the unsuspecting user's disk and send the victim's credit card numbers and passwords to a stranger.
- A. Virus
- B. Trojan
- C. Worm
- D. Cookie tracker
Answer: B
NEW QUESTION 96
Quantitative risk is the numerical determination of the probability of an adverse event and the extent of the
losses due to the event. Quantitative risk is calculated as:
- A. (Probability of Loss) X (Loss)
- B. Significant Risks X Probability of Loss X Loss
- C. (Loss) / (Probability of Loss)
- D. (Probability of Loss) / (Loss)
Answer: A
NEW QUESTION 97
Which one of the following is the correct sequence of flow of the stages in an incident response:
- A. Preparation - Identification - Containment - Eradication - Recovery - Follow-upĂ
- B. Eradication - Containment - Identification - Preparation - Recovery - Follow-up
- C. Identification - Preparation - Containment - Recovery - Follow-up - Eradication
- D. Containment - Identification - Preparation - Recovery - Follow-up - Eradication
Answer: A
NEW QUESTION 98
A Malicious code attack using emails is considered as:
- A. Multiple component attack
- B. Email attack
- C. Malware based attack
- D. Inappropriate usage incident
Answer: A
NEW QUESTION 99
A malicious security-breaking code that is disguised as any useful program that installs an executable programs when a file is opened and allows others to control the victim's system is called:
- A. Virus
- B. Trojan
- C. RootKit
- D. Worm
Answer: B
NEW QUESTION 100
The sign(s) of the presence of malicious code on a host infected by a virus which is delivered via e-mail could be:
- A. Antivirus software detects the infected files
- B. System files become inaccessible
- C. All the above
- D. Increase in the number of e-mails sent and received
Answer: C
NEW QUESTION 101
The open source TCP/IP network intrusion prevention and detection system (IDS/IPS), uses a rule-driven
language, performs real-time traffic analysis and packet logging is known as:
- A. Snort
- B. SAINT
- C. Wireshark
- D. Nessus
Answer: A
Explanation:
Explanation
NEW QUESTION 102
A Host is infected by worms that propagates through a vulnerable service; the sign(s) of the presence of the
worm include:
- A. All the above
- B. Decrease in network usage
- C. Established connection attempts targeted at the vulnerable services
- D. System becomes instable or crashes
Answer: D
NEW QUESTION 103
The free utility which quickly scans Systems running Windows OS to find settings that may have been changed by spyware, malware, or other unwanted programs is called:
- A. F-Secure Anti-virus
- B. Stinger
- C. Tripwire
- D. HijackThis
Answer: D
NEW QUESTION 104
A risk mitigation strategy determines the circumstances under which an action has to be taken to minimize and overcome risks. Identify the risk mitigation strategy that focuses on minimizing the probability of risk and losses by searching for vulnerabilities in the system and appropriate controls:
- A. Research and acknowledgment
- B. Risk absorption
- C. Risk limitation
- D. Risk Assumption
Answer: A
NEW QUESTION 105
One of the goals of CSIRT is to manage security problems by taking a certain approach towards the
customers' security vulnerabilities and by responding effectively to potential information security incidents.
Identify the incident response approach that focuses on developing the infrastructure and security processes
before the occurrence or detection of an event or any incident:
- A. Introductive approach
- B. Qualitative approach
- C. Interactive approach
- D. Proactive approach
Answer: D
NEW QUESTION 106
Installing a password cracking tool, downloading pornography material, sending emails to colleagues which
irritates them and hosting unauthorized websites on the company's computer are considered:
- A. Malware attacks
- B. Network based attacks
- C. Unauthorized access attacks
- D. Inappropriate usage incidents
Answer: D
NEW QUESTION 107
The Malicious code that is installed on the computer without user's knowledge to acquire information from the user's machine and send it to the attacker who can access it remotely is called:
- A. Trojan
- B. Logic Bomb
- C. Spyware
- D. Worm
Answer: C
NEW QUESTION 108
......
Career Path
After accomplishing the ECIH certification, you can apply for the CHFI (Computer Hacking Forensic Investigator) and the CASE (Certified Application Security Engineer) to become a multi-domain specialist. In addition, there are many other specialized certifications that you can opt to master in IT security. Thus, if you plan to become a Licensed Security consultant, it's recommended to take the Licensed Penetration Test Master (LPT) qualification. In all, these certificates can attract potential employers and lead you to a successful path.
The EC-Council Certified Incident Handler (ECIH) 212-89 is an exam that prepares you for handling incidents in various information systems. It prepares you for security plans and policies to deal with incidents with efficiency & effectiveness in a time-constrained environment to decrease the effect of those incidents. This test leads you to the ECIH certification that will allow you to work as an Incident Handler and work in incident response frameworks. So, if you want to excel in the information security environment, the EC-Council Certified Incident Handler certification exam is a must for you. It will be the best gateway to a high-paying job and a good working environment, where you can work with other EC-Council specialists.
EC-COUNCIL 212-89 Pre-Exam Practice Tests | PrepAwayTest: https://www.prepawaytest.com/EC-COUNCIL/212-89-practice-exam-dumps.html
212-89 practice test questions, answers, explanations: https://drive.google.com/open?id=191SPars-JAoeZ193TcuWuUC5kgi0jySy