
Quality 212-89 PDF Dumps - 212-89 Exam Questions
Most UptoDate EC-COUNCIL 212-89 Exam Dumps PDF 2021
ECCouncil 212-89 Exam
The Incident Manager Certification certified by the EC Council is designed to provide the fundamental skills to manage and respond to cybersecurity incidents in an information system. A certified accident controller is a qualified professional who can handle various types of accidents, risk assessment methodologies, and various accident management laws and policies. A certified incident controller will be capable to generate an incident response and management policies and control various types of computer security incidents, such as network security incidents, malicious code incidents, and threats of internal attacks.
NEW QUESTION 76
In the Control Analysis stage of the NIST's risk assessment methodology, technical and none technical control
methods are classified into two categories. What are these two control categories?
- A. Preventive and Detective controls
- B. Detective and Disguised controls
- C. Preventive and predictive controls
- D. Predictive and Detective controls
Answer: A
NEW QUESTION 77
Ensuring the integrity, confidentiality and availability of electronic protected health information of a patient is known as:
- A. Social Security Act
- B. Health Insurance Portability and Privacy Act
- C. Gramm-Leach-Bliley Act
- D. Sarbanes-Oxley Act
Answer: B
NEW QUESTION 78
An audit trail policy collects all audit trails such as series of records of computer events, about an operating
system, application or user activities. Which of the following statements is NOT true for an audit trail policy:
- A. It helps in compliance to various regulatory laws, rules,and guidelines
- B. It helps in reconstructing the events after a problem has occurred
- C. It helps calculating intangible losses to the organization due to incident
- D. It helps tracking individual actions and allows users to be personally accountable for their actions
Answer: C
NEW QUESTION 79
The largest number of cyber-attacks are conducted by:
- A. Suppliers
- B. Business partners
- C. Outsiders
- D. Insiders
Answer: C
NEW QUESTION 80
Overall Likelihood rating of a Threat to Exploit a Vulnerability is driven by :
- A. All the above
- B. Threat-source motivation and capability
- C. Existence and effectiveness of the current controls
- D. Nature of the vulnerability
Answer: A
NEW QUESTION 81
___________________ record(s) user's typing.
- A. Virus
- B. Malware
- C. Spyware
- D. adware
Answer: C
NEW QUESTION 82
An adversary attacks the information resources to gain undue advantage is called:
- A. Electronic Warfare
- B. Offensive Information Warfare
- C. Defensive Information Warfare
- D. Conventional Warfare
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 83
Common name(s) for CSIRT is(are)
- A. Incident Response Team (IRT)
- B. All the above
- C. Incident Handling Team (IHT)
- D. Security Incident Response Team (SIRT)
Answer: B
NEW QUESTION 84
To respond to DDoS attacks; one of the following strategies can be used:
- A. Identifying none critical services and stopping them
- B. All the above
- C. Shut down some services until the attack has subsided
- D. Using additional capacity to absorb attack
Answer: B
NEW QUESTION 85
An estimation of the expected losses after an incident helps organization in prioritizing and formulating their incident response. The cost of an incident can be categorized as a tangible and intangible cost. Identify the tangible cost associated with virus outbreak?
- A. Psychological damage
- B. Lost productivity damage
- C. Loss of goodwill
- D. Damage to corporate reputation
Answer: B
NEW QUESTION 86
An incident recovery plan is a statement of actions that should be taken before, during or after an incident.
Identify which of the following is NOT an objective of the incident recovery plan?
- A. Avoiding the legal liabilities arising due to incident
- B. Creating new business processes to maintain profitability after incident
- C. Providing assurance that systems are reliable
- D. Providing a standard for testing the recovery plan
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 87
Any information of probative value that is either stored or transmitted in a digital form during a computer crime is called:
- A. Digital Forensic Examiner
- B. Digital evidence
- C. Computer Emails
- D. Digital investigation
Answer: B
NEW QUESTION 88
Incident Response Plan requires
- A. All the above
- B. Resources
- C. Expert team composition
- D. Financial and Management support
Answer: A
NEW QUESTION 89
The IDS and IPS system logs indicating an unusual deviation from typical network traffic flows; this is called:
- A. An Indication
- B. A Precursor
- C. A Proactive
- D. A Reactive
Answer: A
NEW QUESTION 90
Incidents such as DDoS that should be handled immediately may be considered as:
- A. Level One incident
- B. Level Two incident
- C. Level Three incident
- D. Level Four incident
Answer: C
NEW QUESTION 91
The free, open source, TCP/IP protocol analyzer, sniffer and packet capturing utility standard across many industries and educational institutions is known as:
- A. Snort
- B. Wireshark
- C. Cain & Able
- D. nmap
Answer: B
NEW QUESTION 92
The network perimeter should be configured in such a way that it denies all incoming and outgoing traffic/ services that are not required. Which service listed below, if blocked, can help in preventing Denial of Service attack?
- A. POP3 service
- B. SAM service
- C. Echo service
- D. SMTP service
Answer: C
NEW QUESTION 93
An estimation of the expected losses after an incident helps organization in prioritizing and formulating their
incident response. The cost of an incident can be categorized as a tangible and intangible cost. Identify the
tangible cost associated with virus outbreak?
- A. Psychological damage
- B. Lost productivity damage
- C. Loss of goodwill
- D. Damage to corporate reputation
Answer: B
NEW QUESTION 94
An active vulnerability scanner featuring high speed discovery, configuration auditing, asset profiling, sensitive data discovery, and vulnerability analysis is called:
- A. EtherApe
- B. CyberCop
- C. Nessus
- D. nmap
Answer: C
NEW QUESTION 95
Incidents are reported in order to:
- A. Deal properly with legal issues
- B. All the above
- C. Provide stronger protection for systems and data
- D. Be prepared for handling future incidents
Answer: B
NEW QUESTION 96
......
100% Free ECIH Certification 212-89 Dumps PDF Demo Cert Guide Cover: https://www.freepdfdump.top/212-89-valid-torrent.html
PDF Exam Material 2021 Realistic 212-89 Dumps Questions: https://drive.google.com/open?id=1sMvLYhhUQWkAjMJ8RorS812DxnBy2Ut0

