Pre-Winter Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free ECCouncil 212-89 Practice Exam with Questions & Answers | Set: 11

Questions 101

Which of the following options describes common characteristics of phishing emails?

Options:
A.

Written in French

B.

Sent from friends or colleagues

C.

Urgency, threatening, or promising subject lines

D.

No BCC fields

ECCouncil 212-89 Premium Access
Questions 102

Ross is an incident manager (IM) at an organization, and his team provides support to all users in the organization who are affected by threats or attacks. David, who is the organization ' s internal auditor, is also part of Ross ' s incident response team. Which of the following is David ' s responsibility?

Options:
A.

Configure information security controls.

B.

Identify and report security loopholes to the management for necessary action.

C.

Coordinate incident containment activities with the information security officer (ISO).

D.

Perform the- necessary action to block the network traffic from the suspectoc intruder.

Questions 103

A regional healthcare provider leveraging a platform-as-a-service (PaaS) cloud model detects suspicious activity involving unauthorized access to patient records. During the investigation, the incident response team attempts to retrieve system logs from virtual machines used during the breach. However, they realize that crucial log files are unavailable, as the short-lived instances were automatically terminated shortly after the event. This hampers their ability to reconstruct a complete activity trail and trace the attacker ' s movements. Which core cloud forensic challenge does this situation most likely reflect?

Options:
A.

Limited log access from containerized workloads.

B.

Metadata misalignment resulting from inconsistent log normalization.

C.

Evaporation of logs due to volatile storage.

D.

Log encryption hindered by poor key management practices.

Questions 104

After experiencing a large-scale distributed denial-of-service (DDoS) attack that caused service outages and degraded performance to its online subscriber portal, a national telecom provider was able to recover and restore its web platform. With customer trust on the line and concerns about similar future incidents, the organization ' s IH & R team has been tasked with implementing robust post-recovery measures that enhance the resilience of web services against traffic-based disruptions. The team is evaluating several options to maintain service availability while mitigating the potential impact of recurring DDoS attempts. Which of the following actions would be most effective in strengthening the provider ' s defenses as part of the recovery process?

Options:
A.

Remove antivirus to speed up application response.

B.

Configure a CDN and implement blackhole routing.

C.

Add guest user accounts for remote diagnostics.

D.

Increase FTP access for easier maintenance.

Questions 105

James has been appointed as an incident handling and response (IH & R) team lead and

he was assigned to build an IH & R plan along with his own team in the company.

Identify the IH & R process step James is currently working on.

Options:
A.

Eradication

B.

Recovery

C.

Preparation

D.

Notification

Questions 106

Lara, a SOC analyst, investigates multiple alerts generated by an IDS showing repeated login failures from a specific workstation to an internal application. When reviewing Windows Event Viewer logs, she discovers a user repeatedly attempting logins outside of working hours. Further checks reveal the user had installed an unauthorized remote desktop tool. Which of the following best describes this situation?

Options:
A.

Policy-enforced remote work attempt

B.

Unauthorized access incident from a third party

C.

Inappropriate usage due to policy violation and software installation

D.

DoS attack against an internal application