Certified Incident Handler (ECIH) Free Sample Questions

40 free sample questions350 in the full practice test

Try simulator

212-89 Sample Questions

  1. Question 1

    The very well-known free open source port, OS and service scanner and network discovery utility is called:

    Answer and explanation

    Correct answer: B

    Nmap (Network Mapper) is the most well-known free and open-source network scanning tool for port scanning, OS detection, and service enumeration. It provides comprehensive network discovery and security auditing capabilities that are essential for incident handlers. Wireshark is a packet analyzer, Snort is an intrusion detection system, and SAINT is a commercial vulnerability scanner, none of which provide the broad network mapping functionality that Nmap offers.

  2. Question 2

    A malware code that infects computer files, corrupts or deletes the data in them and requires a host file to propagate is called:

    Answer and explanation

    Correct answer: C

    A virus is malicious code that infects computer files, corrupts or deletes data, and specifically requires a host file to propagate and spread. This host dependency is the key characteristic that distinguishes viruses from other malware types. Trojans disguise themselves as legitimate software but do not require host files, worms self-replicate across networks without needing host files, and rootkits hide malicious activity rather than requiring hosts for propagation.

  3. Question 3

    Risk is defined as the probability of the occurrence of an incident. Risk formulation generally begins with the likeliness of an event’s occurrence, the harm it may cause and is usually denoted as Risk - Z(events)X (Probability of occurrence)/?

    Answer and explanation

    Correct answer: A

    Risk is commonly formulated as Risk = Events × Probability × Magnitude, where Magnitude represents the potential impact or harm that could result from an incident. The magnitude component quantifies the severity of consequences, making the risk formula complete. Probability is already mentioned in the formula, while consequences and significance are general terms that do not fit the specific mathematical risk formulation structure.

  4. Question 4

    An organization faced an information security incident where a disgruntled employee passed sensitive access control information to a competitor. The organization s incident response manager, upon investigation, found that the incident must be handled within a few hours on the same day to maintain business continuity and market competitiveness.

    How would you categorize such information security incident?

    Answer and explanation

    Correct answer: A

    High level incidents involve sensitive information disclosure to competitors, insider threats, or data breaches that require immediate senior management involvement and significant resources. The scenario describes a disgruntled employee passing sensitive access control information to a competitor, which represents a serious security breach requiring high-level incident response procedures. Middle and low level incidents involve less critical issues, while ultra-high incidents are typically reserved for catastrophic system-wide failures or major data breaches affecting thousands of records.

  5. Question 5

    The process of rebuilding and restoring the computer systems affected by an incident to normal operational stage including all the processes, policies and tools is known as:

    Answer and explanation

    Correct answer: C

    Incident Recovery is the process of rebuilding and restoring computer systems affected by an incident to normal operational status, including all processes, policies, and tools. This phase focuses specifically on system restoration and business continuity. Incident Management is the overall framework, Incident Response refers to the immediate reaction and containment actions, and Incident Handling encompasses the entire lifecycle but does not specifically refer to the restoration phase.

  6. Question 6

    Computer viruses are malicious software programs that infect computers and corrupt or delete the data on them. Identify the virus type that specifically infects Microsoft Word files?

    Answer and explanation

    Correct answer: C

    Macro viruses specifically infect Microsoft Office documents like Word files by embedding malicious code in the document macros. These viruses execute when the document is opened and macros are enabled, making them particularly dangerous for document-based attacks. Micro viruses and file infectors target executable files, while boot sector viruses infect the master boot record of storage devices, none of which specifically target Word document files.

  7. Question 7

    Policies are designed to protect the organizational resources on the network by establishing the set rules and procedures. Which of the following policies authorizes a group of users to perform a set of actions on a set of resources?

    Answer and explanation

    Correct answer: A

    Access control policies specifically authorize groups of users to perform defined sets of actions on designated resources, establishing who can access what and under what conditions. This is the fundamental purpose of access control in organizational security. Audit trail policies track user activities, while other policy types serve different security functions but do not directly authorize user actions on resources.

  8. Question 8

    Which of the following is an incident tracking, reporting and handling tool:

    Answer and explanation

    Correct answer: B

    RTIR (Request Tracker for Incident Response) is a specialized incident tracking, reporting, and handling tool designed specifically for security incident management teams. It provides structured workflows for incident lifecycle management, reporting capabilities, and collaboration features essential for incident response. CRAMM is a risk assessment methodology, NETSTAT is a network utility command, and EAR/Pilar are not incident tracking tools.

  9. Question 9

    Incident management team provides support to all users in the organization that are affected by the threat or attack. The organization’s internal auditor is part of the incident response team. Identify one of the responsibilities of the internal auditor as part of the incident response team:

    Answer and explanation

    Correct answer: C

    Internal auditors in incident response teams are responsible for identifying and reporting security loopholes to management for necessary actions, ensuring organizational compliance and control effectiveness. Their expertise in evaluating internal controls makes them valuable for identifying systemic weaknesses that led to incidents. Configuring security controls, blocking network traffic, and coordinating containment are operational tasks typically handled by security engineers and incident handlers rather than auditors.

  10. Question 10

    Any information of probative value that is either stored or transmitted in a digital form during a computer crime is called:

    Answer and explanation

    Correct answer: A

    Digital evidence refers to any information of probative value that is stored or transmitted in digital form during a computer crime, making it legally admissible in court proceedings. This encompasses all electronic data that can prove or disprove facts related to cyber incidents. Computer emails are just one type of digital evidence, digital investigation is the process of examining evidence, and digital forensic examiner is the person who analyzes the evidence, not the evidence itself.

  11. Question 11

    An incident is analyzed for its nature, intensity and its effects on the network and systems. Which stage of the incident response and handling process involves auditing the system and network log files?

    Answer and explanation

    Correct answer: D

    The Identification stage of incident response involves analyzing incidents for their nature, intensity, and effects, which includes auditing system and network log files to understand what occurred. This stage focuses on determining whether a security event is actually an incident requiring response. Incident recording documents the incident, reporting communicates findings, and containment focuses on limiting the incident spread rather than initial analysis.

  12. Question 12

    Incident Response Plan requires

    Answer and explanation

    Correct answer: D

    Incident Response Plans require all of the above components: financial and management support for resources and authority, expert team composition with skilled personnel from various disciplines, and adequate resources including technology, tools, and budget. A comprehensive incident response plan cannot be effective without any of these critical elements, as each component is essential for successful incident handling and organizational preparedness.

  13. Question 13

    A software application in which advertising banners are displayed while the program is running that delivers ads to display pop-up windows or bars that appears on a computer screen or browser is called:

    Answer and explanation

    Correct answer: A

    Adware is software that displays advertising banners while running and delivers ads through pop-up windows or bars on computer screens or browsers, often generating revenue for developers through ad display. Unlike malicious malware, adware primarily focuses on advertising rather than system damage. Trojans disguise malicious functionality, rootkits hide system presence, viruses self-replicate and infect files, and worms spread across networks, none of which primarily focus on advertising display.

  14. Question 14

    According to the Evidence Preservation policy, a forensic investigator should make at least................image copies of the digital evidence.

    Answer and explanation

    Correct answer: B

    According to Evidence Preservation policy, a forensic investigator should make at least two image copies of digital evidence to ensure data integrity and provide backup protection against corruption or damage during analysis. One copy serves as a working copy for examination while the other remains pristine for verification and legal presentation. Single copies risk evidence loss, while three or more copies may be excessive for most investigations, but two copies specifically provide the minimum redundancy needed for proper evidence preservation and chain of custody maintenance.

  15. Question 15

    The most common type(s) of intellectual property is(are):

    Answer and explanation

    Correct answer: D

    The most common types of intellectual property include all the mentioned forms: copyrights protecting creative works, trademarks protecting brand identifiers, patents protecting inventions, and trade secrets protecting confidential business information. Each type provides different legal protections for intangible assets. Since intellectual property encompasses multiple categories of legal protection for different types of creative and business assets, all the above represents the complete range of common intellectual property types that organizations must protect.

  16. Question 16

    Business continuity is defined as the ability of an organization to continue to function even after a disastrous event, accomplished through the deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy. Identify the plan which is mandatory part of a business continuity plan?

    Answer and explanation

    Correct answer: B

    Business Recovery Plan is the comprehensive strategy that enables organizations to continue functioning after disastrous events through redundant hardware/software, fault-tolerant systems, and robust backup procedures. This plan specifically focuses on operational continuity and system restoration. While disaster recovery plans address immediate response, business impact analysis evaluates potential losses, and contingency plans provide alternative procedures, the Business Recovery Plan encompasses the full spectrum of organizational continuity measures.

  17. Question 17

    Agencies do NOT report an information security incident is because of:

    Answer and explanation

    Correct answer: A

    Organizations often fail to report information security incidents primarily due to fear of negative publicity, which could damage their reputation, customer trust, and stock value. This concern about public perception frequently outweighs the benefits of incident reporting and information sharing. While costs, legal concerns, and technical challenges may be factors, the fear of reputational damage remains the predominant reason organizations avoid incident disclosure.

  18. Question 18

    Which among the following CERTs is an Internet provider to higher education institutions and various other research institutions in the Netherlands and deals with all cases related to computer security incidents in which a customer is involved either as a victim or as a suspect?

    Answer and explanation

    Correct answer: D

    SURFnet-CERT is the Computer Emergency Response Team that serves as an Internet provider to higher education institutions and research institutions in the Netherlands, handling all computer security incidents involving their customers. This specialized CERT focuses on the academic and research community. Other CERTs serve different constituencies: CERT/CC coordinates global incident response, AusCERT serves Australia, and JPCERT serves Japan, but none specifically focus on Dutch higher education institutions.

  19. Question 19

    Which of the following service(s) is provided by the CSIRT:

    Answer and explanation

    Correct answer: D

    Computer Security Incident Response Teams (CSIRTs) provide all the services mentioned including incident handling, vulnerability management, security awareness training, threat intelligence sharing, forensic analysis, and coordination with other security teams. CSIRTs offer comprehensive security services to support organizational incident response capabilities. Since the question asks about CSIRT services in general and multiple options would be correct, all the above represents the complete range of services these teams typically provide.

  20. Question 20

    Ensuring the integrity, confidentiality and availability of electronic protected health information of a patient is known as:

    Answer and explanation

    Correct answer: B

    The Health Insurance Portability and Accountability Act (HIPAA) ensures the integrity, confidentiality, and availability of electronic protected health information (ePHI) of patients through comprehensive privacy and security requirements. HIPAA establishes national standards for protecting medical records and personal health information in healthcare organizations. Other acts like FISMA, SOX, and GLBA address different regulatory requirements but do not specifically focus on patient health information protection.

Register free to unlock 20 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 350 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon