212-89 Exam Questions
175 real 212-89 exam questions with expert-verified answers and explanations. Page 1 of 4.
- Question #1
Malicious Micky has moved from the delivery stage to the exploitation stage of the kill chain. This malware wants to find and report to the command center any useful services on th...
- Question #2
Raven is a part of an IH&R team and was informed by her manager to handle and lead the removal of the root cause for an incident and to close all attack vectors to prevent similar...
- Question #3
According to NITS, what are the 5 main actors in cloud computing?
- Question #4
Which of the following is an Inappropriate usage incident?
- Question #5
Which of the following is the ECIH phase that involves removing or eliminating the root cause of an incident and closing all attack vectors to prevent similar incidents in the futu...
- Question #6
An insider threat response plan helps an organization minimize the damage caused by malicious insiders. One of the approaches to mitigate these threats is setting up controls from...
- Question #7
Alice is an incident handler and she has been informed by her lead that the data on affected systems must be backed up so that it can be retrieved if it is damaged during the incid...
- Question #8
A user downloaded what appears to be genuine software. Unknown to her, when she installed the application, it executed code that provided an unauthorized remote attacker access to...
- Question #9
Finn is working in the eradication phase, wherein he is eliminating the root cause of an incident that occurred in the Windows operating system installed in a system. He ran a tool...
- Question #10
Your manager hands you several items of digital evidence and asks you to investigate them in the order of volatility. Which of the following is the MOST volatile?
- Question #11
Ikeo Corp, hired an incident response team to assess the enterprise security. As part of the incident handling and response process, the IR team is reviewing the current security p...
- Question #12
You are a systems administrator for a company. You are accessing your file server remotely for maintenance. Suddenly, you are unable to access the server. After contacting others i...
- Question #13
Nervous Nat often sends emails with screenshots of what he thinks are serious incidents, but they always turn out to be false positives. Today, he sends another screenshot, suspect...
- Question #14
Which of the following does NOT reduce the success rate of SQL injection?
- Question #15
Rica works as an incident handler for an international company. As part of her role, she must review the present security policy implemented. Upon inspection, Rica finds that the p...
- Question #16
An organization's customers are experiencing either slower network communication or unavailability of services. In addition, network administrators are receiving alerts from securi...
- Question #17
Which of the following is a volatile evidence collecting tool?
- Question #18
Your company holds a large amount of customer PH. and you want to protect those data from theft or unauthorized modification. Among other actions, you classify and encrypt the data...
- Question #19
Which of the following are malicious software programs that infect computers and corrupt or delete the data on them?
- Question #20
Alex is an incident handler in QWERTY Company. He identified that an attacker created a backdoor inside the company's network by installing a fake AP inside a firewall. Which of th...
- Question #21
Which of the following terms refers to an organization's ability to make optimal use of digital evidence in a limited period of time and with minimal investigation costs?
- Question #22
Bran is an incident handler who is assessing the network of the organization. He wants to detect ping sweep attempts on the network using Wireshark. Which of the following Wireshar...
- Question #23
Which of the following is the BEST method to prevent email incidents?
- Question #24
Which of the following is a type of malicious code or software that appears legitimate but can take control of your computer?
- Question #25
Which of the following terms refers to vulnerable account management functions, including account update, recovery of forgotten or lost passwords, and password reset, that might we...
- Question #26
Otis is an incident handler working in an organization called Delmont. Recently, the organization faced several setbacks in business, whereby its revenues are decreasing. Otis was...
- Question #27
Which of the following is NOT part of the static data collection process?
- Question #28
Attackers or insiders create a backdoor into a trusted network by installing an unsecured access point inside a firewall. They then use any software or hardware access point to per...
- Question #29
Which of the following is a standard framework that provides recommendations for implementing information security controls for organizations that initiate, implement, or maintain...
- Question #30
Alice is a disgruntled employee. She decided to acquire critical information from her organization for financial benefit. To acccomplish this, Alice started running a virtual machi...
- Question #31
Sam. an employee of a multinational company, sends emails to third-party organizations with a spoofed email address of his organization. How can you categorize this type of inciden...
- Question #32
Jason is setting up a computer forensics lab and must perform the following steps: 1. physical location and structural design considerations; 2. planning and budgeting; 3. work are...
- Question #33
Which of the following options describes common characteristics of phishing emails?
- Question #34
In which of the following phases of the incident handling and response (IH&R) process is the identified security incidents analyzed, validated, categorized, and prioritized?
- Question #35
Your company sells SaaS, and your company itself is hosted in the cloud (using it as a PaaS). In case of a malware incident in your customer's database, who is responsible for erad...
- Question #36
Employee monitoring tools are mostly used by employers to find which of the following?
- Question #37
BadGuy Bob hid files in the slack space, changed the file headers, hid suspicious files in executables, and changed the metadata for all types of files on his hacker laptop. What h...
- Question #38
Which of the following is an attack that occurs when a malicious program causes a user's browser to perform an unwanted action on a trusted site for which the user is currently aut...
- Question #39
Which one of the following is the correct flow of the stages in an incident handling and response (IH&R) process?
- Question #40
Eric works as an incident handler at Erinol software systems. He was assigned a task to protect the organization from any kind of DoS/DDoS attacks. Which of the following tools can...
- Question #41
Richard is analyzing a corporate network. After an alert in the network's IPS. he identified that all the servers are sending huge amounts of traffic to the website abc.xyz. What t...
- Question #42
Which of the following is not called volatile data?
- Question #43
Alex is an incident handler for Tech-o-Tech Inc. and is tasked to identify any possible insider threats within his organization. Which of the following insider threat detection tec...
- Question #44
Francis is an incident handler and security expert. He works at MorisonTech Solutions based in Sydney, Australia. He was assigned a task to detect phishing/spam mails for the clien...
- Question #45
Allan performed a reconnaissance attack on his corporate network as part of a red-team activity. He scanned the IP range to find live host IP addresses. What type of technique did...
- Question #46
Sam received an alert through an email monitoring tool indicating that their company was targeted by a phishing attack. After analyzing the incident, Sam identified that most of th...
- Question #47
A colleague wants to minimize their security responsibility because they are in a small organization. They are evaluating a new application that is offered in different forms. Whic...
- Question #48
Eric works as a system administrator at ABC organization and previously granted several users with access privileges to the organizations systems with unlimited permissions. These...
- Question #49
Shiela is working at night as an incident handler. During a shift, servers were affected by a massive cyberattack. After she classified and prioritized the incident, she must repor...
- Question #50
An attack on a network is BEST blocked using which of the following?