최신 212-89 무료덤프 - EC-COUNCIL EC Council Certified Incident Handler (ECIH v3)

A network administrator reviews firewall and IDS/IPS configurations to ensure logging is properly set, updates logging to centralize alerts from all network devices, and confirms that all response team members know their responsibilities. Which preparatory activity is he performing?

정답: B
Adam is an incident handler who intends to use DBCC LOG command to analyze a database and retrieve the active transaction log files for the specified database. The syntax of DBCC LOG command is DBCC LOG(, ), where the output parameter specifies the level of information an incident handler wants to retrieve. If Adam wants to retrieve the full information on each operation along with the hex dump of a current transaction row, which of the following output parameters should Adam use?

정답: A
설명: (DumpTOP 회원만 볼 수 있음)
Which of the following risk management processes identifies the risks, estimates the impact, and determines sources to recommend proper mitigation measures?

정답: B
설명: (DumpTOP 회원만 볼 수 있음)
GlobalTech recently faced a series of advanced attacks. Post-incident analysis led them to discover a malicious software disguised as an update module for their ERP system. The malware exhibited intricate behavior, making its detection challenging. The security team needs to determine its functionality and potential damage. What should be their primary approach?

정답: C
Which of the following information security personnel handles incidents from management and technical point of view?

정답: A
설명: (DumpTOP 회원만 볼 수 있음)
Bran is an incident handler who is assessing the network of the organization. He wants to detect ping sweep attempts on the network using Wireshark. Which of the following Wireshark filters would Bran use to accomplish this task?

정답: B
설명: (DumpTOP 회원만 볼 수 있음)
Alice is a disgruntled employee. She decided to acquire critical information from her organization for financial benefit. To acccomplish this, Alice started running a virtual machine on the same physical host as her victim's virtual machine and took advantage of shared physical resources (processor cache) to steal data (cryptographic key/plain text secrets) from the victim machine.
Identify the type of attack Alice is performing in the above scenario.

정답: A
설명: (DumpTOP 회원만 볼 수 있음)
An attacker traced out and found the kind of websites a target company/individual is frequently surfing and tested those particular websites to identify any possible vulnerabilities. When the attacker detected vulnerabilities in the website, the attacker started injecting malicious script/code into the web application that can redirect the webpage and download the malware onto the victim's machine. After infecting the vulnerable web application, the attacker waited for the victim to access the infected web application.
Identify the type of attack performed by the attacker.

정답: D
설명: (DumpTOP 회원만 볼 수 있음)
Sarah, an employee at a company, feels frustrated and resentful due to a hostile work environment and perceived unfair treatment. She decides to attack the organization's systems as a means of retaliation. What is the driving force behind Sarah's insider attack?

정답: A
DigitalSoft, a major software development firm, recently discovered unauthorized access to its codebase. The culprit was a disgruntled employee who had been overlooked for a promotion.
The company wants to prevent such insider threats in the future. What is the most effective measure it can implement?

정답: B
설명: (DumpTOP 회원만 볼 수 있음)
Sophia, a security analyst, notices that a sensitive folder on a file server was accessed during off- hours by an intern using authorized credentials. The access was not flagged because the intern's permissions had not been reviewed in months, even after their project ended. What process should have been enforced to avoid this insider threat?

정답: C
설명: (DumpTOP 회원만 볼 수 있음)
After a successful exploitation attempt, a university web server started exhibiting anomalies such as high server load, random form submission errors, and repeated spam complaints. Hosting providers flagged the domain as suspicious and disabled the web application. The IH&R team discovered new unknown files within the web root directory. Which action would be most appropriate to contain the incident and avoid further damage?

정답: D
설명: (DumpTOP 회원만 볼 수 있음)
Alexis works as an incident responder at XYZ organization. She was asked to identify and attribute the actors behind an attack that occurred recently. For this purpose, she is performing a type of threat attribution that deals with the identification of a specific person, society, or country sponsoring a well-planned and executed intrusion or attack on its target. Which of the following types of threat attributions is Alexis performing?

정답: A
설명: (DumpTOP 회원만 볼 수 있음)
The IT security team of a multinational corporation identifies a breach in its BYOD (Bring Your Own Device) policy, with several employees' mobile devices infected with spyware through a malicious app. These devices had access to the corporate email system, potentially exposing sensitive communications. In this scenario, what is the most immediate action the security team should take to handle the mobile-based security incident?

정답: D
설명: (DumpTOP 회원만 볼 수 있음)

우리와 연락하기

문의할 점이 있으시면 메일을 보내오세요. 12시간이내에 답장드리도록 하고 있습니다.

근무시간: ( UTC+9 ) 9:00-24:00
월요일~토요일

서포트: 바로 연락하기