nerdexam
EC-Council

312-50V12 · Question #80

Attacker Lauren has gained the credentials of an organization's internal server system, and she was often logging in during irregular times to monitor the network activities. The organization was…

The correct answer is A. Incident triage. In this phase, the identified security incidents are analyzed, validated, categorized, and prioritized. The IH&R team further analyzes the compromised device to find incident details such as the type of attack, its severity, target, impact, and method of propagation, and any…

Submitted by salim_om· Mar 4, 2026Information Security and Ethical Hacking Overview

Question

Attacker Lauren has gained the credentials of an organization's internal server system, and she was often logging in during irregular times to monitor the network activities. The organization was skeptical about the login times and appointed security professional Robert to determine the issue. Robert analyzed the compromised device to find incident details such as the type of attack, its severity, target, impact, method of propagation, and vulnerabilities exploited. What is the incident handling and response (IH&R) phase, in which Robert has determined these issues?

Options

  • AIncident triage
  • BPreparation
  • CIncident recording and assignment
  • DEradication

How the community answered

(41 responses)
  • A
    93% (38)
  • C
    2% (1)
  • D
    5% (2)

Explanation

In this phase, the identified security incidents are analyzed, validated, categorized, and prioritized. The IH&R team further analyzes the compromised device to find incident details such as the type of attack, its severity, target, impact, and method of propagation, and any vulnerabilities it exploited.

Topics

#Incident response#Incident triage#Incident handling phases#Security incident analysis

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice