212-89 Exam Questions
175 real 212-89 exam questions with expert-verified answers and explanations. Page 2 of 4.
- Question #51Incident Handling and Response Planning
Which of the following risk management processes identifies the risks, estimates the impact, and determines sources to recommend proper mitigation measures?
risk assessmentrisk managementrisk identificationmitigation measures - Question #52Incident Handling and Response Technologies
Eric is an incident responder and is working on developing incident-handling plans and procedures. As part of this process, he is performing an analysis on the organizational netwo...
Wiresharknetwork traffic analysisincident response toolspolicy development - Question #53Incident Handling and Response Technologies
Miko was hired as an incident handler in XYZ company. His first task was to identify the PING sweep attempts inside the network. For this purpose, he used Wireshark to analyze the...
Wireshark filtersICMPping sweep detectionnetwork forensics - Question #54Incident Handling and Response Process
QualTech Solutions is a leading security services enterprise. Dickson, who works as an incident responder with this firm, is performing a vulnerability assessment to identify the s...
active assessmentvulnerability assessmentautomated scanningnetwork enumeration - Question #55Computer Forensics in Incident Handling
James is working as an incident responder at CyberSol Inc. The management instructed James to investigate a cybersecurity incident that recently happened in the company. As a part...
volatile data collectionnetstatWindows forensicsrunning processes - Question #56Computer Forensics in Incident Handling
Which of the following types of digital evidence is temporarily stored in a digital device that requires constant power supply and is deleted if the power supply is interrupted?
volatile evidenceprocess memoryRAM forensicsdigital evidence types - Question #57Incident Handling and Response Management
You are talking to a colleague who Is deciding what information they should include in their organization's logs to help with security auditing. Which of the following items should...
security loggingaudit logslog managementprivacy in logging - Question #58Incident Handling and Response Technologies
Which of the following tools helps incident responders effectively contain a potential cloud security incident and gather required forensic evidence?
cloud forensicsincident containmentCloudPassage Halocloud security tools - Question #59Computer Forensics in Incident Handling
Investigator Ian gives you a drive image to investigate. What type of analysis are you performing?
static analysisdisk imageforensic investigationdead analysis - Question #60Incident Handling and Response Process
Oscar receives an email from an unknown source containing his domain name oscar.com. Upon checking the link, he found that it contains a malicious URL that redirects to the website...
unvalidated redirectsweb vulnerabilitiesURL manipulationphishing - Question #61Incident Handling and Response Process
Alexis works as an incident responder at XYZ organization. She was asked to identify and attribute the actors behind an attack that occurred recently. For this purpose, she is perf...
threat attributionnation-state attributionincident responsethreat intelligence - Question #62Computer Forensics in Incident Handling
Ren is assigned to handle a security incident of an organization. He is tasked with forensics investigation to find the evidence needed by the management. Which of the following st...
computer forensicsinvestigation phaseevidence assessmentforensics process - Question #63Incident Handling and Response Technologies
Which of the following is a technique used by attackers to make a message difficult to understand through the use of ambiguous language?
obfuscationevasion techniquesattacker techniquesmalware - Question #64Incident Handling and Response Technologies
Which of the following has been used to evade IDS and IPS?
IDS evasionIPS evasionfragmentationnetwork attacks - Question #65Incident Handling and Response Planning
What is the most recent NIST standard for incident response?
NIST standardsincident response framework800-61compliance - Question #66Incident Handling and Response Technologies
SWA Cloud Services added PKI as one of their cloud security controls. What does PKI stand for?
PKIpublic key infrastructurecloud securitycryptography - Question #67Incident Handling and Response Technologies
Racheal is an incident handler working in InceptionTech organization. Recently, numerous employees are complaining about receiving emails from unknown senders. In order to prevent...
DKIMemail authenticationemail spoofingemail headers - Question #68Incident Handling and Response Process
Which of the following is a term that describes the combination of strategies and services intended to restore data, applications, and other resources to the public cloud or dedica...
cloud recoverydisaster recoverycloud servicesbusiness continuity - Question #69Incident Handling and Response Process
If a hacker cannot find any other way to attack an organization, they can influence an employee or a disgruntled staff member. What type of threat is this?
insider threatsocial engineeringdisgruntled employeethreat types - Question #70Incident Handling and Response Process
During the vulnerability assessment phase, the incident responders perform various steps as below: 1. Run vulnerability scans using tools 2. Identify and prioritize vulnerabilities...
vulnerability assessmentvulnerability scanningOSINTincident response steps - Question #71Incident Handling and Response Process
Which of the following is not a countermeasure to eradicate cloud security incidents?
cloud securityincident eradicationcountermeasurestwo-factor authentication - Question #72Incident Handling and Response Technologies
An organization named Sam Morison Inc. decided to use cloud-based services to reduce the cost of maintenance. The organization identified various risks and threats associated with...
cloud security toolsAlert Logiccloud threat preventionsecurity controls - Question #73Incident Handling and Response Process
Which of the following is not a countermeasure to eradicate inappropriate usage incidents?
inappropriate usageincident eradicationcountermeasuresVPN - Question #74Incident Handling and Response Technologies
An incident handler is analyzing email headers to find out suspicious emails. Which of the following tools he/she must use in order to accomplish the task?
email header analysisemail securityBarracudaphishing investigation - Question #75Computer Forensics in Incident Handling
Rinni is an incident handler and she is performing memory dump analysis. Which of following tools she can use in order to perform memory dump analysis?
memory dump analysisforensic toolsScyllaOllyDumpEx - Question #76Incident Handling and Response Process
In which of the following types of insider threats an insider who is uneducated on potential security threats or simply bypasses general security procedures to meet workplace effic...
insider threat typesnegligent insidersecurity awarenesshuman error - Question #77Incident Handling and Response Process
Johnson an incident handler is working on a recent web application attack faced by the organization. As part of this process, he performed data preprocessing in order to analyzing...
watering hole attackdata preprocessingsessionizationweb application attack - Question #78Incident Handling and Response Process
Which stage of the incident response and handling process involves auditing the system and network log files?
incident triagelog analysisincident response phasesnetwork logs - Question #79Incident Handling and Response Management
Identify Sarbanes-Oxley Act (SOX) Title, which consists of only one section, that includes measures designed to help restore investor confidence in the reporting of securities anal...
SOX complianceSarbanes-Oxleyregulatory compliancesecurities analysts - Question #80Incident Handling and Response Planning
Which of the following GPG18 and Forensic readiness planning (SPF) principles states that "organizations should adopt a scenario based Forensic Readiness Planning approach that lea...
forensic readinessGPG18SPF principlesscenario-based planning - Question #81Incident Handling and Response Technologies
Darwin is an attacker residing within the organization and is performing network sniffing by running his system in promiscuous mode. He is capturing and viewing all the network pac...
network sniffingpromiscuous modeNmapsniffer detection - Question #82Computer Forensics in Incident Handling
Jason is an incident handler dealing with malware incidents. He was asked to perform memory dump analysis in order to collect the information about the basic functionality of any p...
memory dump analysismalware analysisstring searchBinText - Question #83Incident Handling and Response Technologies
Which of the following encoding techniques replaces unusual ASCII characters with "%" followed by the character's two-digit ASCII code expressed in hexadecimal?
URL encodingASCII encodingencoding techniquesweb attacks - Question #84Computer Forensics in Incident Handling
For analyzing the system, the browser data can be used to access various credentials. Which of the following tools is used to analyze the history data files in Microsoft Edge brows...
browser forensicsMicrosoft Edgehistory analysisBrowsingHistoryView - Question #85Computer Forensics in Incident Handling
Stanley works as an incident responder at a top MNC based out of Singapore. He was asked to investigate a cybersecurity incident that recently occurred in the company. While invest...
digital evidenceevidence admissibilityforensic evidencecourt presentation - Question #86Incident Handling and Response Management
A US Federal Agency network was the target of a DoS attack that prevented and impaired the normal authorized functionality of the networks. According to agency's reporting timefram...
incident categorizationDoS attackUS federal reportingincident reporting timeframe - Question #87Incident Handling and Response Process
Eric works as a system administrator in ABC organization. He granted privileged users with unlimited permissions to access the systems. These privileged users can misuse their righ...
insider threatsprivileged usersaccount managementeradication - Question #88Incident Handling and Response Technologies
During the process of detecting and containing malicious emails, incident responders should examine the originating IP address of the emails. The steps to examine the originating I...
email forensicsIP tracingemail header analysisWHOIS lookup - Question #89Incident Handling and Response Technologies
Bran is an incident handler who is assessing the network of the organization. In the process, he wants to detect ping sweep attempts on the network using Wireshark tool. Which of t...
Wiresharkping sweep detectionICMP filteringnetwork monitoring - Question #90Incident Handling and Response Process
In which of the following phases of incident handling and response (IH&R) process the identified security incidents are analyzed, validated, categorized, and prioritized?
incident triageIH&R process phasesincident prioritizationincident categorization - Question #91Incident Handling and Response Process
Alexis is working as an incident responder in XYZ organization. She was asked to identify and attribute the actors behind an attack that took place recently. In order to do so, she...
threat attributiontrue attributionthreat intelligenceintrusion attribution - Question #92Incident Handling and Response Process
XYZ Inc. was affected by a malware attack and James, being the incident handling and response (IH&R) team personnel handling the incident, found out that the root cause of the inci...
post-incident activitiesincident impact assessmentIH&R phasesincident reporting - Question #93Incident Handling and Response Process
Mr. Smith is a lead incident responder of a small financial enterprise having few branches in Australia. Recently, the company suffered a massive attack losing USD 5 million throug...
APT attacklateral movementattack classificationthreat analysis - Question #94Incident Handling and Response Management
Which of the following risk mitigation strategies involves execution of controls to reduce the risk factor and brings it to an acceptable level or accepts the potential risk and co...
risk assumptionrisk mitigation strategiesrisk managementIT risk - Question #95Computer Forensics in Incident Handling
The following steps describe the key activities in forensic readiness planning: 1. Train the staff to handle the incident and preserve the evidence 2. Create a special process for...
forensic readiness planningevidence collection policydigital forensics planningforensic policy - Question #96Incident Handling and Response Technologies
Tibson works as an incident responder for MNC based in Singapore. He is investigating a web application security incident recently faced by the company. The attack is performed on...
SQL injectionregular expressionsMS SQL Serverweb application security - Question #97Incident Handling and Response Process
Robert is an incident handler working for Xsecurity Inc. One day, his organization faced a massive cyberattack and all the websites related to the organization went offline. Robert...
recovery phasebusiness continuityIH&R processservice restoration - Question #98Incident Handling and Response Technologies
Clark, a professional hacker, exploited the web application of a target organization by tampering the form and parameter values. He successfully exploited the web application and g...
broken access controlparameter tamperingweb application securityOWASP - Question #99Incident Handling and Response Planning
Eric who is an incident responder is working on developing incident-handling plans and procedures. As part of this process, he is performing analysis on the organizational network...
network traffic analysisWiresharkincident planning toolsnetwork monitoring - Question #100Incident Handling and Response Technologies
Drake is an incident handler in Dark CLoud Inc. He is intended to perform log analysis in order to detect traces of malicious activities within the network infrastructure. Which of...
log analysisSIEMSplunkmalware detection