[Apr 01, 2024] 100% Latest Most updated 212-89 Questions and Answers [Q115-Q140]

Share

[Apr 01, 2024] 100% Latest Most updated 212-89 Questions and Answers

Try with 100% Real Exam Questions and Answers

NEW QUESTION # 115
To respond to DDoS attacks; one of the following strategies can be used:

  • A. Shut down some services until the attack has subsided
  • B. Using additional capacity to absorb attack
  • C. All the above
  • D. Identifying none critical services and stopping them

Answer: C


NEW QUESTION # 116
To recover, analyze, and preserve computer and related materials in such a way that it can be presented as evidence in a court of law and identify the evidence in short time, estimate the potential impact of the malicious activity on the victim, and assess the intent and identity of the perpetrator is known as:

  • A. Computer Forensics
  • B. Forensic Readiness
  • C. Digital Forensic Analysis
  • D. Digital Forensic Examiner

Answer: C


NEW QUESTION # 117
Organizations or incident response teams need to protect the evidence for any future legal actions that may be taken against perpetrators that intentionally attacked the computer system. EVIDENCE PROTECTION is also required to meet legal compliance issues. Which of the following documents helps in protecting evidence from physical or logical damage:

  • A. Chain-of-Custody
  • B. Forensic analysis report
  • C. Chain-of-Precedence
  • D. Network and host log records

Answer: A


NEW QUESTION # 118
A Host is infected by worms that propagates through a vulnerable service; the sign(s) of the presence of the worm include:

  • A. Decrease in network usage
  • B. Established connection attempts targeted at the vulnerable services
  • C. System becomes instable or crashes
  • D. All the above

Answer: C


NEW QUESTION # 119
Jason is an incident handler dealing with malware incidents. He was asked to perform a memory dump analysis in order to collect the information about the basic functionality of any program. As apart of his assignment, he needs to perform string search analysis to search for the malicious string that could determine the harmful actions that a program can perform.
Which of the following string-searching tools does Jason need to use to perform the intended task?

  • A. Process Explorer
  • B. PE View
  • C. Bin Text
  • D. Dependency Walker Information about the resource is in the response body.

Answer: C


NEW QUESTION # 120
Racheal is an incident handler working at an organization called Inception Tech. Recently, numerous employees have been complaining about receiving emails from unknown senders. In order to prevent employees from spoof ng emails and keeping security in mind, Racheal was asked to take appropriate actions in this matter. As a part of her assignment, she needs to analyze the email headers to check the authenticity of received emails.
Which of the following protocol/authentication standards she must check in email header to analyze the email authenticity?

  • A. ARP
  • B. SNMP
  • C. DKIM
  • D. POP

Answer: C


NEW QUESTION # 121
Insider threats can be detected by observing concerning behaviors exhibited by insiders, such as conflicts with
supervisors and coworkers, decline in performance, tardiness or unexplained absenteeism. Select the
technique that helps in detecting insider threats:

  • A. Correlating known patterns of suspicious and malicious behavior
  • B. Making is compulsory for employees to sign a none disclosure agreement
  • C. Protecting computer systems by implementing proper controls
  • D. Categorizing information according to its sensitivity and access rights

Answer: A

Explanation:
Explanation


NEW QUESTION # 122
Insiders understand corporate business functions. What is the correct sequence of activities performed by Insiders to damage company assets:

  • A. Install malware, gain privileged access, then activate
  • B. Activate malware, gain privileged access then install malware
  • C. Gain privileged access, install malware then activate
  • D. Gain privileged access, activate and install malware

Answer: C


NEW QUESTION # 123
In the cloud environment, an authorized security professional executes approved sanitation procedures using approved utilities to permanently remove data spilled from contaminated information systems and applications in the cloud.
This is an example of which of the following?

  • A. Cloud auditor
  • B. Cloud computing
  • C. Cloud broker
  • D. Cloud eradication

Answer: A


NEW QUESTION # 124
Francis received a spoof email asking for his bank information. He decided to use a tool to analyze the email headers.
Which of the following should he use?

  • A. Email Checker
  • B. EventLog Analyzer
  • C. Polite Mail
  • D. Mx Toolbox

Answer: D


NEW QUESTION # 125
In which of the following phases of incident handling and response (IH&R) process are the identified security incidents analyzed, validated, categorized, and prioritized?

  • A. Incident triage
  • B. Containment
  • C. Notification
  • D. Incident recording and assignment

Answer: A


NEW QUESTION # 126
Elizabeth, who works for OBC organization as an incident responder, is assessing the risks to the organizational security. As part of the assessment process, she is calculating the probability of a threat source exploiting an existing system vulnerability.
Which of the following risk assessment steps is Elizabeth currently in?

  • A. System characterization
  • B. Vulnerability identification
  • C. Likelihood analysis
  • D. Impact analysis

Answer: B


NEW QUESTION # 127
What command does a Digital Forensic Examiner use to display the list of all IP addresses and their associated MAC addresses on a victim computer to identify the machines that were communicating with it:

  • A. "dd" command
  • B. "arp" command
  • C. "ifconfig" command
  • D. "netstat -an" command

Answer: B


NEW QUESTION # 128
Michael is a part of the computer incident response team of a company. One of his responsibilities is to handle email incidents. The company receives an email from an unknown source, and one of the steps that he needs to take is to check the validity of the email.
Which of the following tools should he use?

  • A. Email Dossier
  • B. G Suite Toolbox
  • C. Yes ware
  • D. Zendio

Answer: A


NEW QUESTION # 129
In which of the following phases of the incident handling and response (IH&R) process is the identified security incidents analyzed, validated, categorized, and prioritized?

  • A. Incident triage
  • B. Containment
  • C. Notification
  • D. Incident recording and assignment

Answer: A


NEW QUESTION # 130
Frederick is in the eradication process in one of the incidents he is handing.
Which of the following is NOT an eradication process?

  • A. Monitor the client's traffic for any malicious activities.
  • B. Analyze the security model of the cloud provider interface.
  • C. CCs must train a few of their employees to use the cloud securely.
  • D. Conduct vulnerability scanning and configuration audits.

Answer: C


NEW QUESTION # 131
Which one of the following is Inappropriate Usage Incidents?

  • A. Access Control Attack
  • B. Denial of Service Attack
  • C. Reconnaissance Attack
  • D. Insider Threat

Answer: D


NEW QUESTION # 132
Clark, a professional hacker, successfully exploited the web application of a target organization by tampering the form and parameter values. In result, Clark gained access to the information assets of the organization. Identify the vulnerability in the web application exploited by the attacker.

  • A. Sensitive data exposure
  • B. SQL injection
  • C. Security misconfiguration
  • D. Broken access control

Answer: B


NEW QUESTION # 133
Alice is a disgruntled employee. She decided to acquire critical information from her organization for financial benefit.
To accomplish this, Alice started running a virtual machine on the same physical host as her victim's virtual machine and took advantage of shared physical resources (processor cache) to steal data (cryptographic key/plaintext secrets) from the victim machine. Identify the type of attack Alice is performing in the above scenario.

  • A. Side channel attack
  • B. SQL injection attack
  • C. Man-in-the-cloud attack
  • D. Service hijacking

Answer: A


NEW QUESTION # 134
The Linux command used to make binary copies of computer media and as a disk imaging tool if given a raw disk device as its input is:

  • A. "netstat" command
  • B. "find" command
  • C. "nslookup" command
  • D. "dd" command

Answer: D


NEW QUESTION # 135
Policies are designed to protect the organizational resources on the network by establishing the set rules and procedures. Which of the following policies authorizes a group of users to perform a set of actions on a set of resources?

  • A. Access control policy
  • B. Logging policy
  • C. Audit trail policy
  • D. Documentation policy

Answer: A


NEW QUESTION # 136
Patrick is performing a cyber forensic investigation. He is in the process of collect ng physical evidence at the crime scene.
Which of the following elements must he consider while collecting physical evidence?

  • A. DNS information including domains and subdomains
  • B. Published nameservers and web-application source code
  • C. Open ports, services, and operating system (OS) vulnerabilities
  • D. Removable media, cables, and publications

Answer: D


NEW QUESTION # 137
The region where the CSIRT is bound to serve and what does it and give service to is known as:

  • A. Constituency
  • B. Confidentiality
  • C. Consistency
  • D. None of the above

Answer: A


NEW QUESTION # 138
The ability of an agency to continue to function even after a disastrous event, accomplished through the
deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup
and recovery strategy is known as:

  • A. Business Continuity Plan
  • B. Contingency Planning
  • C. Disaster Planning
  • D. Business Continuity

Answer: D


NEW QUESTION # 139
What is the name of the type of malicious software or malware designed to deny access to a computer system or data until money is paid?

  • A. Spyware
  • B. Adware
  • C. Virus
  • D. Ransomware

Answer: D


NEW QUESTION # 140
......

New EC-COUNCIL 212-89 Dumps & Questions: https://www.examcost.com/212-89-practice-exam.html

Dumps to Pass your 212-89 Exam with 100% Real Questions and Answers: https://drive.google.com/open?id=1GFNK9QEe2PjhhpVnEWmyAoux4P6v89ve