
EC-COUNCIL 212-89リアル試験問題解答は無料
試験問題集で212-89練習無料最新のEC-COUNCIL練習テスト
ECIH v2試験は、インシデント処理と対応に関連する様々なトピックをカバーしており、インシデント管理、インシデント対応、インシデント調査を含んでいます。受験者は、インシデント対応プロセスに深い理解を持つ必要があり、インシデントの識別と分類、証拠の収集、インシデントの影響を抑制する能力が求められます。この試験では、脆弱性スキャン、ネットワークフォレンジック、脅威インテリジェンスなどのインシデント対応ツールとテクニックについてもカバーしています。
EC-Council Certified Incident Handler(ECIH v2)認定試験は、インシデント処理または対応を担当するプロフェッショナルを対象としています。この認定は、候補者がさまざまなタイプのセキュリティインシデントに効果的に対応するために必要なスキルと知識を持っていることを確認します。この試験は、インシデント処理プロセス、フォレンジック準備、ネットワークトラフィック分析など、幅広いトピックをカバーしています。
質問 # 112
James is a professional hacker and is employed by an organization to exploit their cloud services. In order to achieve this, James created anonymous access to the cloud services to carryout various attacks such as password and key cracking, hosting malicious data, and DDoS attacks.
Which of the following threats is he posing to the cloud platform?
- A. Insufficient due diligence
- B. Insecure interface and APIs
- C. Data breach/loss
- D. Abuse and nefarious use of cloud services
正解:D
質問 # 113
Which of the following terms may be defined as "a measure of possible inability to achieve a goal, objective, or target within a defined security, cost plan and technical limitations that adversely affects the organization's operation and revenues?
- A. Threat
- B. Risk
- C. Incident Response
- D. Vulnerability
正解:B
質問 # 114
Removing or eliminating the root cause of the incident is called:
- A. Incident Eradication
- B. Incident Containment
- C. Incident Protection
- D. Incident Classification
正解:A
質問 # 115
The insider risk matrix consists of technical literacy and business process knowledge vectors. Considering the matrix, one can conclude that:
- A. If the insider's technical literacy and process knowledge are high, the risk posed by the threat will be insignificant.
- B. If the insider's technical literacy and process knowledge are high, the risk posed by the threat will be high.
- C. If the insider's technical literacy is high and process knowledge is low, the risk posed by the threat will be high.
- D. If the insider's technical literacy is low and process knowledge is high, the risk posed by the threat will be insignificant.
正解:B
質問 # 116
In which of the following stages of the incident handling and response (IH&R) process do the incident handlers try to find the root cause of the incident along with the threat actors behind the incidents, threat vectors, etc.?
- A. Incident triage
- B. Post-incident activities
- C. Evidence gathering and forensics analysis
- D. Incident recording and assignment
正解:C
質問 # 117
An organization faced an information security incident where a disgruntled employee passed sensitive access
control information to a competitor. The organization's incident response manager, upon investigation, found
that the incident must be handled within a few hours on the same day to maintain business continuity and
market competitiveness. How would you categorize such information security incident?
- A. Ultra-High level incident
- B. High level incident
- C. Middle level incident
- D. Low level incident
正解:B
質問 # 118
Darwin is an attacker within an organization and is performing network sniffing by running his system in promiscuous mode. He is capturing and viewing all the network packets transmitted within the organization. Edwin is an incident handler in the same organization.
In the above situation, which of the following Nmap commands Edwin must use to detect Darwin's system that is running in promiscuous mode?
- A. nmap --script=sniffer-detect [Target IP Address/Range of IP addresses]
- B. nmap -sU -p 500
- C. nmap -sV -T4 -O -F -version-light
- D. nmap --script host map
正解:A
質問 # 119
In which of the following phases of the incident handling and response (IH&R) process is the identified security incidents analyzed, validated, categorized, and prioritized?
- A. Containment
- B. Notification
- C. Incident triage
- D. Incident recording and assignment
正解:C
質問 # 120
An insider threat response plan help san organization minimize the damage caused by malicious insiders.
One of the approaches to mitigate these threats is setting up controls from the human resources department.
Which of the following guidelines can the human resources department use?
- A. Monitor and secure the organization's physical environment.
- B. Disable the default administrative account to ensure accountability.
- C. Implement a person-to-person rule to secure the backup process and physical media.
- D. Access granted to users should be documented and vetted by a supervisor.
正解:D
質問 # 121
Investigator lan gives you a drive image to investigate.
What type of analysis are you performing?
- A. Static
- B. Dynamic
- C. Live
- D. Real-time
正解:A
質問 # 122
Incident may be reported using/ by:
- A. Facsimile (Fax)
- B. Email or on-line Web form
- C. Phone call
- D. All the above
正解:D
質問 # 123
Which of the following GPG 18 and Forensic readiness planning (SPF) principles states that "organizations should adopt a scenario based Forensic Readiness Planning approach that learns from experience gained within the business"?
- A. Principle 7
- B. Principle 5
- C. Principle 3
- D. Principle 2
正解:B
質問 # 124
When an employee is terminated from his or her job, what should be the next immediate step taken by an organization?
- A. The access requests granted to an employee should be documented and vetted by the supervisor
- B. All access rights of the employee to physical locations, networks, systems, applications and data should be disabled
- C. The organization should enforce separation of duties
- D. The organization should monitor the activities of the system administrators and privileged users who have permissions to access the sensitive information
正解:B
質問 # 125
To effectively describe security incidents, it is necessary to adopt a common set of terminology and to categorize the incidents.
According to ECIH text, in which category would you place an incident that involves illegal file download by a suspected or unknown user?
- A. Middle level
- B. Ultra High Level
- C. High level
- D. Low Level
正解:C
質問 # 126
What command does a Digital Forensic Examiner use to display the list of all open ports and the associated IP addresses on a victim computer to identify the established connections on it:
- A. "netstat -an" command
- B. "ifconfig" command
- C. "dd" command
- D. "arp" command
正解:A
質問 # 127
One of the goals of CSIRT is to manage security problems by taking a certain approach towards the
customers' security vulnerabilities and by responding effectively to potential information security incidents.
Identify the incident response approach that focuses on developing the infrastructure and security processes
before the occurrence or detection of an event or any incident:
- A. Proactive approach
- B. Interactive approach
- C. Qualitative approach
- D. Introductive approach
正解:A
質問 # 128
The most common type(s) of intellectual property is(are):
- A. Copyrights and Trademarks
- B. Industrial design rights & Trade secrets
- C. Patents
- D. All the above
正解:D
質問 # 129
......
確認済み212-89試験問題集と解答で時間限定無料提供!212-89には正解付き:https://www.passtest.jp/EC-COUNCIL/212-89-shiken.html
212-89試験問題、リアル212-89練習問題集:https://drive.google.com/open?id=1RATXolh8MfFebTQE85t1WqLgKsVqGedU