Here are all the actual test exam dumps for IT exams. Most people prepare for the actual exams with our test dumps to pass their exams. So it's critical to choose and actual test pdf to succeed.

Free 212-89 Exam Files Verified & Correct Answers Downloaded Instantly [Q41-Q56]

Share

Free 212-89 Exam Files Verified & Correct Answers Downloaded Instantly

Instant Download 212-89 Dumps Q&As Provide PDF&Test Engine


EC-COUNCIL 212-89 certification exam is specifically designed for cybersecurity professionals who aspire to become incident handlers, incident response team members, or computer forensics professionals. These IT security practitioners work to protect businesses, government organizations, and other large institutions, and are typically responsible for identifying, investigating, and resolving security incidents. These professionals need specific skills and knowledge to excel in their work, so the exam content is tailored to cover the most relevant and up-to-date topics.

 

NEW QUESTION # 41
A US Federal agency network was the target of a DoS attack that prevented and impaired the normal authorized functionality of the networks. According to agency's reporting timeframe guidelines, this incident should be reported within two (2) HOURS of discovery/detection if the successful attack is still ongoing and the agency is unable to successfully mitigate the activity. Which incident category of the US Federal Agency does this incident belong to?

  • A. CAT 2
  • B. CAT 5
  • C. CAT 6
  • D. CAT 1

Answer: A


NEW QUESTION # 42
Raven is a part of an IH&R team and was info med by her manager to handle and lead the removal of the root cause for an incident and to close all attack vectors to prevent similar incidents in the future. Raven notifies the service providers and developers of affected resources.
Which of the following steps of the incident handling and response process does Raven need to implement to remove the root cause of the incident?

  • A. Eradication
  • B. Incident triage
  • C. Evidence gathering and forensic analysis
  • D. Containment

Answer: A


NEW QUESTION # 43
Computer Forensics is the branch of forensic science in which legal evidence is found in any computer or any
digital media device. Of the following, who is responsible for examining the evidence acquired and separating
the useful evidence?

  • A. Evidence Examiner/ Investigator
  • B. Evidence Manager
  • C. Evidence Supervisor
  • D. Evidence Documenter

Answer: A


NEW QUESTION # 44
Which of the following describes the introduction of malicious programs on to a device connected to a campus network (Trojan horse, email bombs, virus, etc.)?

  • A. Authorized access
  • B. Unauthorized access
  • C. Network access
  • D. Inappropriate usage

Answer: C


NEW QUESTION # 45
To respond to DDoS attacks; one of the following strategies can be used:

  • A. Shut down some services until the attack has subsided
  • B. All the above
  • C. Identifying none critical services and stopping them
  • D. Using additional capacity to absorb attack

Answer: B


NEW QUESTION # 46
___________________ record(s) user's typing.

  • A. Spyware
  • B. adware
  • C. Virus
  • D. Malware

Answer: A


NEW QUESTION # 47
John is a professional hacker who is performing an attack on the target organization where he tries to redirect the connection between the IP address and its target server such that when the users type in the Internet address, it redirects them to a rogue website that resembles the original website. He tries this attack using cache poisoning technique.
Identify the type of attack John is performing on the target organization.

  • A. Pre texting
  • B. Pharming
  • C. War driving
  • D. Skimming

Answer: B


NEW QUESTION # 48
Your manager hands you several items of digital evidence and asks you to investigate them in the order of volatility.
Which of the following is the MOST volatile?

  • A. Temp files
  • B. Disk
  • C. Cache
  • D. Emails

Answer: C


NEW QUESTION # 49
Which of the following port scanning techniques involves resetting the TCP connection between client and server abruptly before completion of the three-way handshake signals, making the connection half-open?

  • A. Stealth scan
  • B. Xmas scan
  • C. Null scan
  • D. Full connects can

Answer: B


NEW QUESTION # 50
Alexis an incident handler in QWERTY Company. He identified that an attacker created a backdoor inside the company's network by installing a fake AP inside a firewall.
Which of the following attack types did the attacker use?

  • A. Wardriving
  • B. Ad hoc associations
  • C. Rogue access point
  • D. AP misconfiguration

Answer: C


NEW QUESTION # 51
Which of the following terms may be defined as "a measure of possible inability to achieve a goal, objective, or target within a defined security, cost plan and technical limitations that adversely affects the organization's operation and revenues?

  • A. Threat
  • B. Incident Response
  • C. Vulnerability
  • D. Risk

Answer: D


NEW QUESTION # 52
To whom should an information security incident be reported?

  • A. Human resources and Legal Department
  • B. It should not be reported at all and it is better to resolve it internally
  • C. It should be reported according to the incident reporting & handling policy
  • D. Chief Information Security Officer

Answer: C


NEW QUESTION # 53
Bob, an incident responder at CyberTech Solutions, is investigating a cybercrime attack that occurred in the client company. He acquired the evidence data, preserved it, and started performing analysis on the acquired evidentiary data to identify the source of the crime and the culprit behind the incident. Identify the forensic investigation phase in which Bob is currently in.

  • A. Post-investigation phase
  • B. Pre-investigation phase
  • C. Investigation phase
  • D. Vulnerability assessment phase

Answer: C


NEW QUESTION # 54
Jacobi san employee in Dolphin Investment firm. While he was on his duty, he identified that his computer is facing some problems and he wanted to convey the issue to the respective authority in his organization.
But currently this organization does not have a ticketing system to address such types of issues.
In the above scenario, which of the following ticketing systems can be employed by the Dolphin Investment firm to allow Jacob to raise the issue in order to tell the respective team about the incident?

  • A. ThreatConnec
  • B. IBM XForce Exchange
  • C. MISP
  • D. ManageEngine ServiceDesk Plus

Answer: C


NEW QUESTION # 55
Matt is an incident handler working for one of the largest social network companies, which was affected by malware. According to the company's reporting timeframe guidelines, a malware incident should be reported within 1 h of discovery/detection after its spread across the company.
Which category does this incident belong to?

  • A. CAT 3
  • B. CAT 4
  • C. CAT 2
  • D. CAT 1

Answer: A


NEW QUESTION # 56
......

Exam Valid Dumps with Instant Download Free Updates: https://examtorrent.actual4test.com/212-89_examcollection.html