Which stage of the incident response and handling process involves auditing the system and network log files?
A. ContainmentMatt is an incident handler working for one of the largest social network companies, which was affected by malware. According to the company's reporting timeframe guidelines, a malware incident should be reported within 1 h of discovery/detection after its spread across the company. Which category does this incident belong to?
A. CAT 1An organization's customers are experiencing either slower network communication or unavailability of services. In addition, network administrators are receiving alerts from security tools such as IDS/IPS and firewalls about a possible DoS/DDoS attack. In result, the organization requests the incident handling and response (IHandR) team further investigates the incident. The IHandR team decides to use manual techniques to detect DoS/DDoS attack. Which of the following commands helps the IHandR team to manually detect DoS/DDoS attack?
A. netstat -rFarheen is an incident responder at reputed IT Firm based in Florida. Farheen was asked to investigate a recent cybercrime faced by the organization. As part of this process, she collected static data from a victim system. She used DD tool command to perform forensic duplication to obtain an NTFS image of the original disk. She created a sector-by-sector mirror imaging of the disk and saved the output image file as image.dd. Identify the static data collection process step performed by Farheen while collecting static data.
A. ComparisonEric works as a system administrator in ABC organization. He granted privileged users with unlimited permissions to access the systems. These privileged users can misuse their rights unintentionally or maliciously or attackers can trick them to perform malicious activities. Which of the following guidelines helps incident handlers to eradicate insider attacks by privileged users?
A. Do not use encryption methods to prevent administrators and privileged users from accessing backup tapes and sensitive informationA colleague wants to minimize their security responsibility because they are in a small organization. They are evaluating a new application that is offered in different forms. Which form would result in the least amount of responsibility for the colleague?
A. On-prom installationXYZ Inc. was affected by a malware attack and James, being the incident handling and response (IHandR) team personnel handling the incident, found out that the root cause of the incident is a backdoor that has bypassed the security perimeter due to an existing vulnerability in the deployed firewall. James had contained the spread of the infection and removed the malware completely. Now the organization asked him to perform incident impact assessment to identify the impact of the incident over the organization and he was also asked to prepare a detailed report of the incident.
Which of the following stages in IHandR process is James working on?
A. NotificationWhich one of the following is the correct flow of the stages in an incident handling and response (IHandR) process?
A. Preparation -* Incident recording -> Incident triage -* Containment -*# Eradication -?Recovery -* Post-incident activitiesIn which of the following phases of the incident handling and response (IHandR) process is the identified security incidents analyzed, validated, categorized, and prioritized?
A. Incident triageWhich of the following email security tools can be used by an incident handler to prevent the organization against evolving email threats?
A. Email Header AnalyzerNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 212-89 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.