212-89 Exam Questions
175 real 212-89 exam questions with expert-verified answers and explanations. Page 3 of 4.
- Question #101Computer Forensics in Incident Handling
Which of the following is not the responsibility of first responders?
first responder dutiescrime scene managementelectronic evidenceevidence preservation - Question #102Computer Forensics in Incident Handling
Bob, an incident responder at CyberTech Solutions, is investigating a cybercrime attack occurred in the client company. He acquired the evidence data, preserved it, and started per...
forensic investigation phasesevidence analysiscybercrime investigationinvestigation phase - Question #103Incident Handling and Response Technologies
Which of the following port scanning techniques involves resetting the TCP connection between client and server abruptly before completion of the three-way handshake signals, makin...
port scanningstealth scanTCP handshakenetwork reconnaissance - Question #104Computer Forensics in Incident Handling
Smith employs various malware detection techniques to thoroughly examine the network and its systems for suspicious and malicious malware files. Among all techniques, which one inv...
malware analysisstatic analysismemory forensicsbinary analysis - Question #105Computer Forensics in Incident Handling
Which of the following techniques prevent or mislead incident-handling process and may also affect the collection, preservation, and identification phases of the forensic investiga...
anti-forensicsevidence tamperingforensic investigationincident handling - Question #106Computer Forensics in Incident Handling
Marley was asked by his incident handling and response (IH&R) team lead to collect volatile data such as system information and network information present in the registries, cache...
live data acquisitionvolatile dataRAM forensicsdata collection methods - Question #107Incident Handling and Response Process
Bonney's system has been compromised by a gruesome malware. What is the primary step that is advisable to Bonney in order to contain the malware incident from spreading?
malware containmentincident containmentmalware responsefirst response - Question #108Incident Handling and Response Technologies
QualTech Solutions is a leading security services enterprise. Dickson works as an incident responder with this firm. He is performing vulnerability assessment to identify the secur...
vulnerability assessmentactive assessmentnetwork scanningautomated tools - Question #109Computer Forensics in Incident Handling
After a recent email attack, Harry is analyzing the incident to obtain important information related to the incident. While investigating the incident, he is trying to extract info...
email forensicsemail header analysissender trackingemail investigation tools - Question #110Incident Handling and Response Process
Otis is an incident handler working in Delmont organization. Recently, the organization is facing several setbacks in the business and thereby its revenues are going down. Otis was...
espionageincident classificationdata theftinformation security incidents - Question #111Incident Handling and Response Technologies
In which of the following types of fuzz testing strategies the new data will be generated from scratch and the amount of data to be generated are predefined based on the testing mo...
fuzz testinggeneration-based fuzzingsecurity testingvulnerability testing - Question #112Computer Forensics in Incident Handling
Patrick is doing a cyber forensic investigation. He is in the process of collecting physical evidence at the crime scene. Which of the following elements he must consider while col...
physical evidence collectioncrime sceneforensic investigationevidence handling - Question #113Incident Handling and Response Technologies
An attacker traced out and found the kind of websites a target company/individual is frequently surfing and tested those particular websites to identify any possible vulnerabilitie...
watering hole attackmalware injectionweb-based attackattack identification - Question #114Incident Handling and Response Management
Who is mainly responsible for providing proper network services and handling network-related incidents in all the cloud service models?
cloud securitycloud service modelscloud service providernetwork incident handling - Question #115Incident Handling and Response Process
Adam is an attacker who along with his team launched multiple attacks on target organization for financial benefits. Worried about getting caught, he decided to forge his identity....
identity theftsynthetic identity theftcybercrime classificationsocial engineering - Question #116Incident Handling and Response Technologies
An organization implemented an encoding technique to eradicate SQL injection attacks. In this technique, if a user submits a request using single-quote and some values, then the en...
SQL injection preventionhex encodinginput validationweb application security - Question #117Incident Handling and Response Process
In which of the following stages of incident handling and response (IH&R) process do the incident handlers try to find out the root cause of the incident along with the threat acto...
IH&R process stagesroot cause analysisforensics analysisthreat actor identification - Question #118Incident Handling and Response Planning
Andrew, an incident responder, is performing risk assessment of the client organization. As a part of risk assessment process, he identified the boundaries of the IT systems, along...
risk assessmentsystem characterizationIT boundary identificationNIST risk framework - Question #119Computer Forensics in Incident Handling
Farheen is an incident responder at reputed IT Firm based in Florida. Farheen was asked to investigate a recent cybercrime faced by the organization. As part of this process, she c...
forensic duplicationdisk imagingDD toolstatic data collection - Question #120Computer Forensics in Incident Handling
Chandler is a professional hacker who is targeting Technote organization. He wants to obtain important organizational information that is being transmitted between different hierar...
packet analysisnetwork sniffingOmnipeeknetwork forensics - Question #121Incident Handling and Response Process
Michael is an incident handler at CyberTech Solutions. He is performing detection and analysis of a cloud security incident. He is analyzing the file systems, slack spaces, and met...
cloud security incidentsstorage forensicsfile system analysisincident classification - Question #122Computer Forensics in Incident Handling
An attacker after performing an attack decided to wipe evidences using artifact wiping techniques to evade forensic investigation. He applied magnetic field to the digital media de...
artifact wipingdisk degaussinganti-forensicsevidence destruction - Question #123Incident Handling and Response Technologies
Rose is an incident-handling person and she is responsible for detecting and eliminating any kind of scanning attempts over the network by any malicious threat actors. Rose uses Wi...
Wireshark filtersTCP Xmas scannetwork scanning detectionpacket analysis - Question #124Incident Handling and Response Planning
James has been appointed as an incident handling and response (IH&R) team lead and he was assigned to build an IH&R plan along with his own team in the company. Identify the IH&R p...
IH&R processpreparation phaseincident response planteam roles - Question #125Incident Handling and Response Process
Which of the following processes is referred to as an approach to respond to the security incidents that occurred in an organization and enables the response team by ensuring that...
incident response orchestrationsecurity incident responseresponse process definition - Question #126Incident Handling and Response Technologies
Which of the following methods help incident responders to reduce the false-positive alert rates and further provide benefits of focusing on topmost priority issues reducing potent...
threat correlationfalse positive reductionalert triagerisk prioritization - Question #127Incident Handling and Response Planning
Shally, an incident handler, is working for a company named Texas Pvt. Ltd. based in Florida. She was asked to work on an incident response plan. As part of the plan, she decided t...
defense-in-depthlayered securitysecurity strategyincident response planning - Question #128Incident Handling and Response Technologies
In which of the following confidentiality attacks attackers try to lure users by posing themselves as authorized AP by beaconing the WLAN's SSID?
evil twin APwireless attacksSSID spoofingconfidentiality attacks - Question #129Incident Handling and Response Process
Joseph is an incident handling and response (IH&R) team lead in Toro Network Solutions Company. As a part of IH&R process, Joseph alerted the service providers, developers, and man...
containment phaseIH&R processstakeholder notificationincident stages - Question #130Incident Handling and Response Process
Identify the network security incident where intended or authorized users are prevented from using system, network, or applications by flooding the network with a high volume of tr...
denial-of-servicenetwork floodingavailability attacksincident classification - Question #131Computer Forensics in Incident Handling
Clark is investigating a cybercrime at TechSoft Solutions. While investigating the case, he needs to collect volatile information such as running services, their process IDs, start...
volatile data collectionwmic commandlive forensicsrunning services - Question #132Incident Handling and Response Technologies
Stenley is an incident handler working for Texa Corp. located in the United States. With the growing concern of increasing emails from outside the organization, Stenley was asked t...
email forensicsemail validationEmail Dossiermalicious email detection - Question #133Incident Handling and Response Planning
Which of the following is not a best practice to eliminate the possibility of insider attacks?
insider threatssecurity best practicesaccess control policythreat prevention - Question #134Incident Handling and Response Process
When an employee is terminated from his or her job, what should be the next immediate step taken by an organization?
employee terminationaccess revocationoffboardingaccess control - Question #135Incident Handling and Response Process
Unusual logins, accessing sensitive information not used for the job role, and the use of personal external storage drives on company assets are all signs of which of the following...
Insider Threat DetectionAnomalous User BehaviorUnauthorized Data AccessData Exfiltration - Question #136Incident Handling and Response Management
What is the best staffing model for an incident response team if current employees' expertise is very low?
incident response staffingoutsourcing strategycapability assessmentresource planning - Question #137Incident Handling and Response Process
ZYX company experienced a DoS/DDoS attack on their network. Upon investigating the incident, they concluded that the attack is an application-layer attack. Which of the following a...
Slowloris attackapplication-layer DoSDDoS attack typesHTTP flooding - Question #138Incident Handling and Response Management
Ross is an incident manager (IM) at an organization, and his team provides support to all users in the organization who are affected by threats or attacks. David, who is the organi...
incident response team rolesinternal auditor responsibilitiesIH&R team structureaccountability - Question #139Incident Handling and Response Technologies
Dash wants to perform a DoS attack over 256 target URLs simultaneously. Which of the following tools can Dash employ to achieve his objective?
HOICDoS attack toolshigh-orbit ion cannonnetwork attack tools - Question #140Incident Handling and Response Management
Which of the following information security personnel handles incidents from management and technical point of view?
incident manager roleIH&R team rolesmanagement responsibilitiestechnical coordination - Question #141Incident Handling and Response Technologies
Francis received a spoof email asking for his bank information. He decided to use a tool to analyze the email headers. Which of the following should he use?
email header analysisMxToolboxphishing investigationemail spoofing - Question #142Incident Handling and Response Process
Zaimasoft, a prominent IT organization, was attacked by perpetrators who directly targeted the hardware and caused irreversible damage to the hardware. In result, replacing or rein...
permanent DoSPDoShardware destructionbricking attacks - Question #143Incident Handling and Response Management
Which of the following terms refers to the personnel that the incident handling and response (IH&R) team must contact to report the incident and obtain the necessary permissions?
point of contactIH&R team communicationincident reportingteam roles - Question #144Computer Forensics in Incident Handling
Khai was tasked with examining the logs from a Linux email server. The server uses Sendmail to execute the command to send emailsand Syslog to maintain logs. To validate the data w...
email server logsSendmailSyslogLinux log directories - Question #145Incident Handling and Response Technologies
A malicious, security-breaking program is disguised as a useful program. Such executable programs, which are installed when a file is opened, allow others to control a user's syste...
Trojanmalware typesmalware definitionunauthorized access - Question #146Computer Forensics in Incident Handling
A computer forensic investigator must perform a proper investigation to protect digital evidence. During the investigation, an investigator needs to process large amounts of data u...
Forensic ExaminationEvidence ProcessingInvestigation PhasesData Analysis - Question #147Computer Forensics in Incident Handling
What command does a Digital Forensic Examiner use to display the list of all open ports and the associated IP addresses on a victim computer to identify the established connections...
netstat commandnetwork connectionsopen portslive forensics - Question #148Computer Forensics in Incident Handling
Organizations or incident response teams need to protect the evidence for any future legal actions that may be taken against perpetrators that intentionally attacked the computer s...
Chain-of-CustodyEvidence ProtectionEvidence IntegrityLegal Compliance - Question #149Incident Handling and Response Process
Which among the following CERTs is an Internet provider to higher education institutions and various other research institutions in the Netherlands and deals with all cases related...
CERT organizationsIncident responseRegional security teamsComputer security incidents - Question #150Incident Handling and Response Technologies
James is a professional hacker and is employed by an organization to exploit their cloud services. In order to achieve this, James created anonymous access to the cloud services to...
cloud abusecloud threatsDDoSanonymous cloud access