Updated Oct-2021 Test Engine or PDF for the EC-COUNCIL 212-89 test to help you quickly prepare for the EC-COUNCIL exam!
Full 212-89 Practice Test and 165 unique questions with explanations waiting just for you, get it now!
NEW QUESTION 85
Except for some common roles, the roles in an IRT are distinct for every organization. Which among the
following is the role played by the Incident Coordinator of an IRT?
- A. Links the appropriate technology to the incident to ensure that the foundation's offices are returned to
normal operations as quickly as possible - B. Applies the appropriate technology and tries to eradicate and recover from the incident
- C. Links the groups that are affected by the incidents, such as legal, human resources, different business
areas and management - D. Focuses on the incident and handles it from management and technical point of view
Answer: C
NEW QUESTION 86
A distributed Denial of Service (DDoS) attack is a more common type of DoS Attack, where a single system is targeted by a large number of infected machines over the Internet. In a DDoS attack, attackers first infect multiple systems which are known as:
- A. Spyware
- B. Worms
- C. Trojans
- D. Zombies
Answer: D
NEW QUESTION 87
___________________ record(s) user's typing.
- A. Malware
- B. adware
- C. Spyware
- D. Virus
Answer: C
NEW QUESTION 88
The correct order or sequence of the Computer Forensic processes is:
- A. Preparation, collection, examination, analysis, and reporting
- B. Preparation, examination, collection, analysis, and reporting
- C. Preparation, analysis, collection, examination, and reporting
- D. Preparation, analysis, examination, collection, and reporting
Answer: A
NEW QUESTION 89
The network perimeter should be configured in such a way that it denies all incoming and outgoing traffic/
services that are not required. Which service listed below, if blocked, can help in preventing Denial of Service
attack?
- A. SAM service
- B. Echo service
- C. SMTP service
- D. POP3 service
Answer: B
NEW QUESTION 90
Insiders may be:
- A. All the above
- B. Ignorant employees
- C. Carless administrators
- D. Disgruntled staff members
Answer: A
NEW QUESTION 91
The process of rebuilding and restoring the computer systems affected by an incident to normal operational stage including all the processes, policies and tools is known as:
- A. Incident Response
- B. Incident Management
- C. Incident Recovery
- D. Incident Handling
Answer: C
NEW QUESTION 92
The role that applies appropriate technology and tries to eradicate and recover from the incident is known as:
- A. Incident Manager
- B. Incident Analyst
- C. Incident coordinator
- D. Incident Handler
Answer: B
NEW QUESTION 93
Which of the following is NOT one of the Computer Forensic types:
- A. USB Forensics
- B. Forensic Archaeology
- C. Email Forensics
- D. Image Forensics
Answer: B
NEW QUESTION 94
The insider risk matrix consists of technical literacy and business process knowledge vectors. Considering the
matrix, one can conclude that:
- A. If the insider's technical literacy and process knowledge are high, the risk posed by the threat will be
insignificant. - B. If the insider's technical literacy and process knowledge are high, the risk posed by the threat will be high.
- C. If the insider's technical literacy is high and process knowledge is low, the risk posed by the threat will be
high. - D. If the insider's technical literacy is low and process knowledge is high, the risk posed by the threat will be
insignificant.
Answer: B
NEW QUESTION 95
A malicious security-breaking code that is disguised as any useful program that installs an executable programs when a file is opened and allows others to control the victim's system is called:
- A. Trojan
- B. Worm
- C. Virus
- D. RootKit
Answer: A
NEW QUESTION 96
The USB tool (depicted below) that is connected to male USB Keyboard cable and not detected by anti-
spyware tools is most likely called:
- A. Hardware Keylogger
- B. USB adapter
- C. Anti-Keylogger
- D. Software Key Grabber
Answer: A
Explanation:
Explanation
NEW QUESTION 97
One of the goals of CSIRT is to manage security problems by taking a certain approach towards the
customers' security vulnerabilities and by responding effectively to potential information security incidents.
Identify the incident response approach that focuses on developing the infrastructure and security processes
before the occurrence or detection of an event or any incident:
- A. Interactive approach
- B. Introductive approach
- C. Qualitative approach
- D. Proactive approach
Answer: D
NEW QUESTION 98
Incident handling and response steps help you to detect, identify, respond and manage an incident. Which of
the following steps focus on limiting the scope and extent of an incident?
- A. Containment
- B. Eradication
- C. Identification
- D. Data collection
Answer: A
NEW QUESTION 99
The service organization that provides 24x7 computer security incident response services to any user, company, government agency, or organization is known as:
- A. Vulnerability Assessor
- B. Digital Forensics Examiner
- C. Computer Security Incident Response Team CSIRT
- D. Security Operations Center SOC
Answer: C
NEW QUESTION 100
Insider threats can be detected by observing concerning behaviors exhibited by insiders, such as conflicts with
supervisors and coworkers, decline in performance, tardiness or unexplained absenteeism. Select the
technique that helps in detecting insider threats:
- A. Protecting computer systems by implementing proper controls
- B. Correlating known patterns of suspicious and malicious behavior
- C. Making is compulsory for employees to sign a none disclosure agreement
- D. Categorizing information according to its sensitivity and access rights
Answer: B
Explanation:
Explanation
NEW QUESTION 101
Identify a standard national process which establishes a set of activities, general tasks and a management structure to certify and accredit systems that will maintain the information assurance (IA) and security posture of a system or site.
- A. NIPACP
- B. NIASAP
- C. NIAAAP
- D. NIACAP
Answer: D
NEW QUESTION 102
......
Get Latest 212-89 Dumps Exam Questions: https://drive.google.com/open?id=1dcESf1cRNLXztmMFhNhTz-30eo5qHCYF
Full 212-89 Practice Test and 165 unique questions with explanations waiting just for you, get it now: https://www.ipassleader.com/EC-COUNCIL/212-89-practice-exam-dumps.html