[2022年12月27日]212-89テスト準備できるトレーニング練習テスト試験問題
試験問題解答ブレーン問題集で212-89試験問題集PDFを使おう
質問 97
Tibs on works as an incident responder for MNC based in Singapore. He is investigating a web application security incident recently faced by the company. The attack is performed on a MSSQL Server hosted by the company. In the detection and analysis phase, he used regular expressions to analyze and detect SQL meta-characters that led to SQL injection attack. Identify the regular expression used by Tibs on to detect SQL injection attack on MSSQL Server.
- A. /exec(\s|\+) +(s|x) p\w+/ix
- B. ((\%3C) <) (\%2F) /) *(script) (\%3E) >)
- C. ((\A.W)(\.A.V))
- D. ((\.1%2E)\.1%2E)(V%2FN|%5C))
正解: A
質問 98
Contingency planning enables organizations to develop and maintain effective methods to handle
emergencies. Every organization will have its own specific requirements that the planning should address.
There are five major components of the IT contingency plan, namely supporting information, notification
activation, recovery and reconstitution and plan appendices. What is the main purpose of the reconstitution
plan?
- A. To restore the original site, tests systems to prevent the incident and terminates operations
- B. To provide the introduction and detailed concept of the contingency plan
- C. To provide a sequence of recovery activities with the help of recovery procedures
- D. To define the notification procedures, damage assessments and offers the plan activation
正解: A
質問 99
What command does a Digital Forensic Examiner use to display the list of all open ports and the associated IP addresses on a victim computer to identify the established connections on it:
- A. "arp" command
- B. "dd" command
- C. "ifconfig" command
- D. "netstat -an" command
正解: D
質問 100
In which of the following stages of the incident handling and response (IH&R) process do the incident handlers try to find the root cause of the incident along with the threat actors behind the incidents, threat vectors, etc.?
- A. Post-incident activities
- B. Incident triage
- C. Incident recording and assignment
- D. Evidence gathering and forensics analysis
正解: D
質問 101
Mr.Smith is a lead incident responder of a small financial enterprise, which has a few branches in Australia. Recently, the company suffered a massive attack losing$5MM through an inter-banking system.
After an in-depth investigation, it was found that the incident occurred because 6 months ago the attackers penetrated the network through a minor vulnerability and maintained the access without any user being aware of it. They then tried to delete users' fingerprints and performed a lateral movement to the computer of a person with privileges in the inter-banking system. The attackers finally gained access and performed the fraudulent transactions.
Based on the above scenario, identify the most accurate kind of attack.
- A. Denial-of-service attack
- B. Ransom ware attack
- C. APT attack
- D. Phishing
正解: C
質問 102
To effectively describe security incidents, it is necessary to adopt a common set of terminology and to categorize the incidents.
According to ECIH text, in which category would you place an incident that involves illegal file download by a suspected or unknown user?
- A. Ultra High Level
- B. High level
- C. Low Level
- D. Middle level
正解: B
質問 103
The largest number of cyber-attacks are conducted by:
- A. Outsiders
- B. Insiders
- C. Business partners
- D. Suppliers
正解: A
質問 104
In a qualitative risk analysis, risk is calculated in terms of:
- A. (Countermeasures + Magnitude of Impact) - (Reports from prior risk assessments)
- B. Asset criticality assessment - (Risks and Associated Risk Levels)
- C. Probability of Loss X Loss
- D. (Attack Success + Criticality ) -(Countermeasures)
正解: C
質問 105
Introduction of malicious programs on to the device connected to the campus network (Trojan Horse, email bombs, virus, etc.) is called?
- A. Authorize Access
- B. Inappropriate Usage
- C. Network Access
- D. Un authorize Access
正解: C
質問 106
A US Federal agency network was the target of a DoS attack that prevented and impaired the normal authorized functionality of the networks. According to agency's reporting timeframe guidelines, this incident should be reported within two (2) HOURS of discovery/detection if the successful attack is still ongoing and the agency is unable to successfully mitigate the activity. Which incident category of the US Federal Agency does this incident belong to?
- A. CAT 6
- B. CAT 2
- C. CAT 5
- D. CAT 1
正解: B
質問 107
Which of the following is the ECIH phase that involves removing or eliminating the root cause of an incident and closing all attack vectors to prevent similar incidents in the future?
- A. Recovery
- B. Vulnerability management phase
- C. Containment
- D. Eradication
正解: D
質問 108
A threat source does not present a risk if NO vulnerability that can be exercised for a particular threat source. Identify the step in which different threat sources are defined:
- A. Identification Vulnerabilities
- B. System characterization
- C. Threat identification
- D. Control analysis
正解: C
質問 109
Which one of the following is the correct sequence of flow of the stages in an incident response:
- A. Identification - Preparation - Containment - Recovery - Follow-up - Eradication
- B. Preparation - Identification - Containment - Eradication - Recovery - Follow-upà
- C. Containment - Identification - Preparation - Recovery - Follow-up - Eradication
- D. Eradication - Containment - Identification - Preparation - Recovery - Follow-up
正解: B
質問 110
Which of the following is the BEST method to prevent email incidents?
- A. Installing antivirus rule updates
- B. Web proxy filtering
- C. Disabling HTML in email content fields
- D. End-user training
正解: D
質問 111
Computer Forensics is the branch of forensic science in which legal evidence is found in any computer or any
digital media device. Of the following, who is responsible for examining the evidence acquired and separating
the useful evidence?
- A. Evidence Manager
- B. Evidence Supervisor
- C. Evidence Documenter
- D. Evidence Examiner/ Investigator
正解: D
質問 112
Which of the following processes is referred to as an approach to respond to the security incidents that occur in an organization and enables the response team by ensuring that they know exactly what process to follow in case of security incidents?
- A. Incident response orchestration
- B. Vulnerability management
- C. Threat assessment
- D. Risk assessment
正解: A
質問 113
A user downloaded what appears to be genuine software. Unknown to her, when she installed the application, it executed code that provided an unauthorized remote attacker access to her computer.
What type of malicious threat displays this characteristic?
- A. Trojan
- B. Backdoor
- C. Spyware
- D. Virus
正解: A
質問 114
According to US-CERT; if an agency is unable to successfully mitigate a DOS attack it must be reported within:
- A. One (1) hour of discovery/detection if the successful attack is still ongoing
- B. Four (4) hours of discovery/detection if the successful attack is still ongoing
- C. Three (3) hours of discovery/detection if the successful attack is still ongoing
- D. Two (2) hours of discovery/detection if the successful attack is still ongoing
正解: D
質問 115
Multiple component incidents consist of a combination of two or more attacks in a system.
Which of the following is not a multiple component incident?
- A. An attacker using email with malicious code to infect internal workstation
- B. An attacker redirecting user to a malicious website and infects his system with Trojan
- C. An attacker infecting a machine to launch a DDoS attack
- D. An insider intentionally deleting files from a workstation
正解: D
質問 116
identify the Sarbanes-Oxley Act (SOX) Title, which consists of only one section, that includes measures designed to help restore investor confidence in the reporting of securities analysts.
- A. Title VIII: Corporate and Criminal Fraud Accountability
- B. Title V: Analyst Conflicts of Interest
- C. Title VII: Studies and Reports
- D. Title IX: White-Collar-Crime Penalty Enhancement
正解: B
質問 117
The most common type(s) of intellectual property is(are):
- A. All the above
- B. Industrial design rights & Trade secrets
- C. Copyrights and Trademarks
- D. Patents
正解: A
質問 118
A malicious security-breaking code that is disguised as any useful program that installs an executable programs when a file is opened and allows others to control the victim's system is called:
- A. Trojan
- B. Worm
- C. RootKit
- D. Virus
正解: A
質問 119
......
EC-COUNCIL 212-89 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
無料ダウンロードEC-COUNCIL 212-89リアルな試験問題で合格しよう:https://www.passtest.jp/EC-COUNCIL/212-89-shiken.html
212-89試験問題集、212-89練習テスト問題:https://drive.google.com/open?id=1RATXolh8MfFebTQE85t1WqLgKsVqGedU