試験高合格率保証2023年12月25日 212-89試験問題と正確な回答! [Q42-Q63]

Share

試験高合格率保証2023年12月25日 212-89試験問題と正確な回答!

テストエンジン練習問題212-89有効最新の問題集


EC-COUNCIL 212-89(EC Council Certified Incident Handler(ECIH v2))認定試験は、インシデントハンドリングとレスポンスの分野で個人の知識とスキルをテストする世界的に認知された認定プログラムです。インシデント管理、リスク評価、脆弱性評価、およびインシデント報告など、さまざまなトピックをカバーしています。認定は、セキュリティ専門家、インシデントハンドラー、ITマネージャー、ネットワーク管理者、およびインシデントハンドリングとレスポンスの分野で知識とスキルを向上させたい人に最適です。


EC-Council 212-89は、サイバーセキュリティの専門家がサイバーセキュリティ事件を成功裏に認識、返信、回復する能力をテストする認定試験です。インシデント処理プロセス、コンピューターフォレンジック、インシデント管理システムは、この試験で評価されている主要な知識領域です。この試験に合格した専門家は、現代の攻撃ベクトルと脆弱性について深い知識を持ち、組織のインシデント対応チームの貴重なメンバーにします。

 

質問 # 42
The sign(s) of the presence of malicious code on a host infected by a virus which is delivered via e-mail could be:

  • A. Increase in the number of e-mails sent and received
  • B. System files become inaccessible
  • C. Antivirus software detects the infected files
  • D. All the above

正解:D


質問 # 43
One of the goals of CSIRT is to manage security problems by taking a certain approach towards the customers' security vulnerabilities and by responding effectively to potential information security incidents. Identify the incident response approach that focuses on developing the infrastructure and security processes before the occurrence or detection of an event or any incident:

  • A. Proactive approach
  • B. Qualitative approach
  • C. Interactive approach
  • D. Introductive approach

正解:A


質問 # 44
Incident may be reported using/ by:

  • A. Phone call
  • B. Email or on-line Web form
  • C. Facsimile (Fax)
  • D. All the above

正解:D


質問 # 45
Which of the following is a term that describes the combination of strategies and services intended to restore data, applications, and other resources to the public cloud or dedicated service providers?

  • A. Eradication
  • B. Analysis
  • C. Mitigation
  • D. Cloud recovery

正解:D


質問 # 46
Which of the following can be considered synonymous:

  • A. Precaution and countermeasure
  • B. Hazard and Threat
  • C. Vulnerability and Danger
  • D. Threat and Threat Agent

正解:B


質問 # 47
Electronic evidence may reside in the following:

  • A. Backup tapes
  • B. Data Files
  • C. Other media sources
  • D. All the above

正解:D


質問 # 48
Risk management consists of three processes, risk assessment, mitigation and evaluation. Risk assessment determines the extent of the potential threat and the risk associated with an IT system through its SDLC. How many primary steps does NIST's risk assessment methodology involve?

  • A. Four
  • B. Nine
  • C. Six
  • D. Twelve

正解:B


質問 # 49
According to US-CERT; if an agency is unable to successfully mitigate a DOS attack it must be reported within:

  • A. Three (3) hours of discovery/detection if the successful attack is still ongoing
  • B. Two (2) hours of discovery/detection if the successful attack is still ongoing
  • C. Four (4) hours of discovery/detection if the successful attack is still ongoing
  • D. One (1) hour of discovery/detection if the successful attack is still ongoing

正解:B


質問 # 50
Total cost of disruption of an incident is the sum of

  • A. Level Two and Level Three incidents cost
  • B. Tangible and Intangible costs
  • C. Tangible cost only
  • D. Intangible cost only

正解:B


質問 # 51
Which of the following email security tools can be used by an incident handler to prevent the organization against evolving email threats?

  • A. Mx Toolbox
  • B. G Suite Toolbox
  • C. Gpg4win
  • D. Email Header Analyzer

正解:C


質問 # 52
Which of the following encoding techniques replaces unusual ASCII characters with "%" followed by the character's two-digit ASCII code expressed in hexadecimal?

  • A. Unicode encoding
  • B. HTML encoding
  • C. URL encoding
  • D. Base 64 encoding

正解:C


質問 # 53
Which of the following is NOT a digital forensic analysis tool:

  • A. EAR/ Pilar
  • B. Guidance Software EnCase Forensic
  • C. Access Data FTK
  • D. Helix

正解:A


質問 # 54
Digital evidence must:

  • A. Be Volatile
  • B. Be Authentic, complete and reliable
  • C. Cast doubt on the authenticity and veracity of the evidence
  • D. Not prove the attackers actions

正解:B


質問 # 55
A computer virus hoax is a message warning the recipient of an on-existent computer virus threat. The message is usually a chain e-mail that tells the recipient to forward it to everyone they know.
Which of the following is not a symptom of virus hoax message?

  • A. The message prompts the user to install Anti-virus
  • B. The message prompts the end user to forward it to his/her email contact list and gain monetary benefits in doing so
  • C. The message warns to delete certain files if the user does not take appropriate action
  • D. The message from a known email id is caught by SPAM filters due to change in filter settings

正解:D


質問 # 56
Installing a password cracking tool, downloading pornography material, sending emails to colleagues which
irritates them and hosting unauthorized websites on the company's computer are considered:

  • A. Unauthorized access attacks
  • B. Inappropriate usage incidents
  • C. Network based attacks
  • D. Malware attacks

正解:B


質問 # 57
A software application in which advertising banners are displayed while the program is running that delivers ads to display pop-up windows or bars that appears on a computer screen or browser is called:

  • A. Worm
  • B. Trojan
  • C. Virus
  • D. adware (spelled all lower case)
  • E. RootKit

正解:D


質問 # 58
In which of the following phases of the incident handling and response (IH&R) process is the identified security incidents analyzed, validated, categorized, and prioritized?

  • A. Notification
  • B. Incident triage
  • C. Incident recording and assignment
  • D. Containment

正解:B


質問 # 59
Which test is conducted to determine the incident recovery procedures effectiveness?

  • A. Scenario testing
  • B. Facility-level test
  • C. Live walk-throughs of procedures
  • D. Department-level test

正解:C


質問 # 60
Tibs on works as an incident responder for MNC based in Singapore. He is investigating a web application security incident recently faced by the company. The attack is performed on a MSSQL Server hosted by the company. In the detection and analysis phase, he used regular expressions to analyze and detect SQL meta-characters that led to SQL injection attack. Identify the regular expression used by Tibs on to detect SQL injection attack on MSSQL Server.

  • A. ((\%3C) <) (\%2F) /) *(script) (\%3E) >)
  • B. ((\A.W)(\.A.V))
  • C. ((\.1%2E)\.1%2E)(V%2FN|%5C))
  • D. /exec(\s|\+) +(s|x) p\w+/ix

正解:D


質問 # 61
Which of the following is not the responsibility of first responders?

  • A. Packaging and transporting the electronic evidence
  • B. Preserving temporary and fragile evidence and then shutdown or reboot the victim's computer
  • C. Protecting the crime scene
  • D. Identifying the crime scene

正解:B


質問 # 62
An attacker uncovered websites a target individual was frequently Suring. The attacker then tested those particular websites to identify possible vulnerabilities. After detecting vulnerabilities within a website, the attacker started injecting malicious script/code into the web application that would redirect the webpage and download the malware on to the victim's machine. After infecting the vulnerable web application, the attacker waited for the victim to access the infected web application. Identify the type of attack performed by the attacker.

  • A. Directory traversal
  • B. Cookie/Session poisoning
  • C. Obfuscation application
  • D. Watering hole

正解:B


質問 # 63
......

試験解答212-89最新版とテストエンジン:https://www.passtest.jp/EC-COUNCIL/212-89-shiken.html

合格させる212-89試験最新の212-89試験問題集PDF:https://drive.google.com/open?id=1TDxgCB-Uwu33Nkxnfd_44n3Ji6syPfmC