Free 212-89 Sample Questions and 100% Cover Real Exam Questions (Updated 165 Questions) [Q35-Q59]

Share

Free 212-89 Sample Questions and 100% Cover Real Exam Questions (Updated 165 Questions)

Download Real EC-COUNCIL 212-89 Exam Dumps Test Engine Exam Questions


EC-COUNCIL 212-89 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Handling and Responding to Network Security Incidents
  • Handling and Responding to Malware Incidents
Topic 2
  • Handling and Responding to Insider Threats
  • Forensic Readiness and First Response
Topic 3
  • Handling and Responding to Cloud Security Incidents
  • Incident Handling and Response Process
Topic 4
  • Handling and Responding to Web Application Security Incidents
  • Introduction to Incident Handling and Response
Topic 5
  • Handling and Responding to Email Security Incidents

 

NEW QUESTION 35
The main feature offered by PGP Desktop Email is:

  • A. None of the above
  • B. End-to-end email communications
  • C. End-to-end secure email service
  • D. Email service during incidents

Answer: C

 

NEW QUESTION 36
In a qualitative risk analysis, risk is calculated in terms of:

  • A. (Attack Success + Criticality ) -(Countermeasures)
  • B. (Countermeasures + Magnitude of Impact) - (Reports from prior risk assessments)
  • C. Probability of Loss X Loss
  • D. Asset criticality assessment - (Risks and Associated Risk Levels)

Answer: C

 

NEW QUESTION 37
Incident prioritization must be based on:

  • A. Criticality of affected systems
  • B. Potential impact
  • C. All the above
  • D. Current damage

Answer: C

 

NEW QUESTION 38
The free utility which quickly scans Systems running Windows OS to find settings that may have been changed by spyware, malware, or other unwanted programs is called:

  • A. HijackThis
  • B. Stinger
  • C. Tripwire
  • D. F-Secure Anti-virus

Answer: A

 

NEW QUESTION 39
The network perimeter should be configured in such a way that it denies all incoming and outgoing traffic/
services that are not required. Which service listed below, if blocked, can help in preventing Denial of Service
attack?

  • A. POP3 service
  • B. Echo service
  • C. SMTP service
  • D. SAM service

Answer: B

 

NEW QUESTION 40
The typical correct sequence of activities used by CSIRT when handling a case is:

  • A. Log, inform, maintain contacts, release information, follow up and reporting
  • B. Log, inform, release information, maintain contacts, follow up and reporting
  • C. Log, maintain contacts, release information, inform, follow up and reporting
  • D. Log, maintain contacts, inform, release information, follow up and reporting

Answer: A

 

NEW QUESTION 41
Incident handling and response steps help you to detect, identify, respond and manage an incident. Which of
the following steps focus on limiting the scope and extent of an incident?

  • A. Identification
  • B. Data collection
  • C. Eradication
  • D. Containment

Answer: D

 

NEW QUESTION 42
Identify the network security incident where intended authorized users are prevented from using system, network, or applications by flooding the network with high volume of traffic that consumes all existing network resources.

  • A. Denial of Service Attack
  • B. XSS Attack
  • C. URL Manipulation
  • D. SQL Injection

Answer: A

 

NEW QUESTION 43
They type of attack that prevents the authorized users to access networks, systems, or applications by exhausting the network resources and sending illegal requests to an application is known as:

  • A. Denial of Service attack
  • B. SQL injection attack
  • C. Session Hijacking attack
  • D. Man in the Middle attack

Answer: A

 

NEW QUESTION 44
When an employee is terminated from his or her job, what should be the next immediate step taken by an organization?

  • A. The access requests granted to an employee should be documented and vetted by the supervisor
  • B. The organization should monitor the activities of the system administrators and privileged users who have permissions to access the sensitive information
  • C. The organization should enforce separation of duties
  • D. All access rights of the employee to physical locations, networks, systems, applications and data should be disabled

Answer: D

 

NEW QUESTION 45
Identify the network security incident where intended authorized users are prevented from using system,
network, or applications by flooding the network with high volume of traffic that consumes all existing network
resources.

  • A. Denial of Service Attack
  • B. XSS Attack
  • C. URL Manipulation
  • D. SQL Injection

Answer: A

 

NEW QUESTION 46
Which of the following is an incident tracking, reporting and handling tool:

  • A. NETSTAT
  • B. RTIR
  • C. CRAMM
  • D. EAR/ Pilar

Answer: B

 

NEW QUESTION 47
A software application in which advertising banners are displayed while the program is running that delivers ads to display pop-up windows or bars that appears on a computer screen or browser is called:

  • A. Worm
  • B. RootKit
  • C. Trojan
  • D. adware (spelled all lower case)
  • E. Virus

Answer: D

 

NEW QUESTION 48
CSIRT can be implemented at:

  • A. Internal enterprise level
  • B. Vendor level
  • C. National, government and military level
  • D. All the above

Answer: D

 

NEW QUESTION 49
An audit trail policy collects all audit trails such as series of records of computer events, about an operating system, application or user activities. Which of the following statements is NOT true for an audit trail policy:

  • A. It helps in reconstructing the events after a problem has occurred
  • B. It helps in compliance to various regulatory laws, rules,and guidelines
  • C. It helps calculating intangible losses to the organization due to incident
  • D. It helps tracking individual actions and allows users to be personally accountable for their actions

Answer: C

 

NEW QUESTION 50
The flow chart gives a view of different roles played by the different personnel of CSIRT. Identify the incident response personnel denoted by A, B, C, D, E, F and G.

  • A. A- Incident Coordinator, B- Constituency, C-Administrator, D-Incident Manager, E- Human Resource, F-Incident Analyst, G-Public relations
  • B. A-Incident Analyst, B- Incident Coordinator, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Manager
  • C. A- Incident Coordinator, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Manager
  • D. A- Incident Manager, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Coordinator

Answer: A

 

NEW QUESTION 51
Which of the following incidents are reported under CAT -5 federal agency category?

  • A. Scans/ probes/ Attempted Access
  • B. Malicious code
  • C. Exercise/ Network Defense Testing
  • D. Denial of Service DoS

Answer: A

 

NEW QUESTION 52
Policies are designed to protect the organizational resources on the network by establishing the set rules and procedures. Which of the following policies authorizes a group of users to perform a set of actions on a set of resources?

  • A. Logging policy
  • B. Documentation policy
  • C. Access control policy
  • D. Audit trail policy

Answer: C

 

NEW QUESTION 53
The free, open source, TCP/IP protocol analyzer, sniffer and packet capturing utility standard across many
industries and educational institutions is known as:

  • A. Snort
  • B. Wireshark
  • C. nmap
  • D. Cain & Able

Answer: B

 

NEW QUESTION 54
A methodical series of techniques and procedures for gathering evidence, from computing equipment and various storage devices and digital media, that can be presented in a court of law in a coherent and meaningful format is called:

  • A. Forensic Readiness
  • B. Forensic Analysis
  • C. Computer Forensics
  • D. Steganalysis

Answer: C

 

NEW QUESTION 55
What command does a Digital Forensic Examiner use to display the list of all open ports and the associated IP
addresses on a victim computer to identify the established connections on it:

  • A. "netstat -an" command
  • B. "dd" command
  • C. "ifconfig" command
  • D. "arp" command

Answer: A

 

NEW QUESTION 56
Which of the following is NOT one of the Computer Forensic types:

  • A. Image Forensics
  • B. Forensic Archaeology
  • C. USB Forensics
  • D. Email Forensics

Answer: B

 

NEW QUESTION 57
Which policy recommends controls for securing and tracking organizational resources:

  • A. Administrative security policy
  • B. Acceptable use policy
  • C. Access control policy
  • D. Asset control policy

Answer: D

Explanation:
Explanation/Reference:

 

NEW QUESTION 58
To whom should an information security incident be reported?

  • A. Chief Information Security Officer
  • B. It should be reported according to the incident reporting & handling policy
  • C. It should not be reported at all and it is better to resolve it internally
  • D. Human resources and Legal Department

Answer: B

 

NEW QUESTION 59
......

New 212-89 exam dumps Use Updated EC-COUNCIL Exam: https://www.prep4sureguide.com/212-89-prep4sure-exam-guide.html

Verified 212-89 Dumps Q&As - 212-89 Test Engine with Correct Answers: https://drive.google.com/open?id=10BxBM9AdXkACbExIoQHTP72CqdwTHeqY