212-89 Exam Questions
175 real 212-89 exam questions with expert-verified answers and explanations. Page 4 of 4.
- Question #151Incident Handling and Response Process
Mike is an incident handler for PNP Infosystems Inc. One day, there was a ticket submitted regarding a critical incident and Mike was assigned to handle the incident. During the pr...
incident triageincident validationfalse positiveincident analysis - Question #152Incident Handling and Response Management
Elizabeth, who works for OBC organization as an incident responder, is assessing the risks to the organizational security. As part of the assessment process, she is calculating the...
risk assessmentlikelihood analysisthreat probabilityvulnerability - Question #153Incident Handling and Response Technologies
Michael is a part of the computer incident response team of a company. One of his responsibilities is to handle email incidents. The company receives an email from an unknown sourc...
email incident responseemail validationEmail Dossieremail forensics tools - Question #154Computer Forensics in Incident Handling
Which of the following tools helps incident handlers to view the file system, retrieve deleted data, perform timeline analysis, web artifacts, etc., during an incident response pro...
digital forensics toolsAutopsyfile system analysisdeleted data recovery - Question #155Incident Handling and Response Process
Dan is a newly appointed information security professional in a renowned organization. He is supposed to follow multiple security strategies to eradicate malware incidents. Which o...
malware eradicationsecurity best practicestrusted sourcesmalware prevention - Question #156Incident Handling and Response Technologies
Which of the following is an attack that attempts to prevent the use of systems, networks, or applications by the intended users?
DoS attackdenial of serviceattack typesavailability attack - Question #157Incident Handling and Response Technologies
Which of the following best describes an email issued as an attack medium, in which several messages are sent to a mailbox to cause overflow?
email bombingemail attacksmailbox overflowattack definition - Question #158Incident Handling and Response Technologies
John is a professional hacker who is performing an attack on the target organization where he tries to redirect the connection between the IP address and its target server such tha...
pharmingDNS cache poisoningrogue websiteweb redirection attack - Question #159Incident Handling and Response Technologies
Identify the malicious program that is masked as a genuine harmless program and gives the attacker unrestricted access to the user's information and system. These programs may unle...
Trojanmalware definitionunauthorized accessdata theft - Question #160Incident Handling and Response Technologies
Which of the following email security tools can be used by an incident handler to prevent the organization against evolving email threats?
email security toolsMxToolboxemail threat preventionemail protection - Question #161Incident Handling and Response Process
Eve's is an incident handler in ABC organization. One day, she got a complaint about email hacking incident from one of the employees of the organization. As a part of incident han...
email incident recoveryaccount securitypassword resetbusiness continuity - Question #162Incident Handling and Response Technologies
Which of the following techniques helps incident handlers to detect man-in-the-middle attack by finding the new APs and trying to connect an already established channel, even if th...
MITM detectionwireless securityaccess point monitoringrogue AP - Question #163Computer Forensics in Incident Handling
Which of the following digital evidence temporarily stored on a digital device that requires a constant power supply and is deleted if the power supply is interrupted?
volatile evidencedigital evidence typesprocess memoryRAM forensics - Question #164Computer Forensics in Incident Handling
John is performing memory dump analysis in order to find out the traces of malware. He has employed volatility tool in order to achieve his objective. Which of the following volati...
Volatility frameworkmemory forensicspslist commandmalware analysis - Question #165Incident Handling and Response Technologies
John, a professional hacker, is attacking an organization, where he is trying to destroy the connectivity between an AP and client to make the target unavailable to other wireless...
disassociation attackwireless attacksAP disconnection802.11 attacks - Question #166Computer Forensics in Incident Handling
Which of the following details are included in the evidence bags?
evidence bagschain of custodyevidence taggingdigital evidence handling - Question #167Computer Forensics in Incident Handling
Stanley works as an incident responder at a top MNC based in Singapore. He was asked to investigate a cybersecurity incident that recently occurred in the company. While investigat...
digital evidence admissibilityevidence characteristicsevidence presentationexpert testimony - Question #168Incident Handling and Response Technologies
Which of the following is a common tool used to help detect malicious internal or compromised actors?
user behavior analyticsinsider threat detectionthreat monitoringSOC tools - Question #169Computer Forensics in Incident Handling
Adam is an incident handler who intends to use DBCC LOG command to analyze a database and retrieve the active transaction log files for the specified database. The syntax of DBCC L...
database forensicsDBCC LOGtransaction log analysisSQL Server forensics - Question #170Computer Forensics in Incident Handling
Which of the following is NOT a network forensic tool?
network forensics toolspacket captureWiresharkNTFS forensics - Question #171Incident Handling and Response Technologies
Malicious downloads that result from malicious office documents being manipulated are caused by which of the following?
macro abusemalicious office documentsmalware deliverydocument-based attacks - Question #172Incident Handling and Response Management
Jacob is an employee at a firm called Dolphin Investment. While he was on duty, he identified that his computer was facing some problems, and he wanted to convey the issue to the c...
incident ticketingITSMManageEngine ServiceDeskincident reporting tools - Question #173Incident Handling and Response Technologies
If the browser does not expire the session when the user fails to logout properly, which of the following OWASP Top 10 web vulnerabilities is caused?
OWASP Top 10broken authenticationsession managementweb vulnerabilities - Question #174Incident Handling and Response Process
Matt is an incident handler working for one of the largest social network companies, which was affected by malware. According to the company's reporting timeframe guidelines, a mal...
incident categorizationreporting timeframesmalware incidentsCAT classification - Question #175Incident Handling and Response Planning
Which of the following is defined as the identification of the boundaries of an IT system along with the resources and information that constitute the system?
system characterizationIT system boundariesrisk assessmentasset identification