Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free ECCouncil 212-89 Practice Exam with Questions & Answers | Set: 7

Questions 61

James, a network administrator at a manufacturing company, is part of the organization ' s incident response team. A recent advisory indicates a surge in denial-of-service (DoS) attacks targeting similar industries. To stay prepared, James reviews firewall and IDS/IPS configurations to ensure logging and alerting are properly set. He also updates logging mechanisms to centralize alerts from all network devices and verifies that all response team members are aware of their responsibilities. Which preparatory activity is James performing?

Options:
A.

Coordinating external law enforcement

B.

Conducting vulnerability scanning

C.

Ensuring network monitoring readiness

D.

Hardening backup systems

ECCouncil 212-89 Premium Access
Questions 62

An organization notices unusual API activity in its AWS account, suggesting unauthorized access and potential data exfiltration. What is the most critical immediate action to take to mitigate this security incident?

Options:
A.

Increase the security group ' s restrictions to limit access to the affected resources.

B.

Enable AWS CloudTrail logs for all regions to track future API activities.

C.

Deploy AWS Shield to protect against potential DDoS attacks as a precaution.

D.

Rotate all AWS IAM access keys and review IAM policies for excessive permissions.

Questions 63

Your company holds a large amount of customer PH. and you want to protect those data from theft or unauthorized modification. Among other actions, you classify and encrypt the data. In this process, which of the following OWASP security risks are you guarding against?

Options:
A.

Insecure deserialization

B.

Security misconfiguration

C.

Broken authentication

D.

Sensitive data exposure

Questions 64

SafePay, an online payment portal, recently introduced an advanced search feature allowing users to search for their transaction history. A week later, an alarming number of users reported unauthorized transactions. Investigation showed that attackers were using advanced search strings, exploiting a previously unidentified vulnerability. What is SafePay ' s best immediate action?

Options:
A.

Implement multi-factor authentication for all user accounts.

B.

Disable the advanced search feature and revert to the older version.

C.

Increase the encryption level of user data stored in databases.

D.

Require users to re-authenticate before accessing the advanced search feature.

Questions 65

In which of the following confidentiality attacks attackers try to lure users by posing themselves as authorized AP by beaconing the WLAN ' s SSID?

Options:
A.

Evil twin AP

B.

Session hijacking

C.

Honeypot AP

D.

Masqueradin

Questions 66

Stenley is an incident handler working for Texa Corp. located in the United States. With the growing concern of increasing emails from outside the organization, Stenley was

asked to take appropriate actions to keep the security of the organization intact. In the process of detecting and containing malicious emails, Stenley was asked to check the

validity of the emails received by employees.

Identify the tools he can use to accomplish the given task.

Options:
A.

PointofMail

B.

Email Dossier

C.

PoliteMail

D.

EventLog Analyzer

Questions 67

Allan performed a reconnaissance attack on his corporate network as part of a red-team activity. He scanned the IP range to find live host IP addresses. What type of technique did he use to exploit the network?

Options:
A.

DNS foot printing

B.

Social engineering

C.

Port scanning

D.

Ping sweeping

Questions 68

A mid-sized healthcare organization undergoing digital modernization is working toward ISO/IEC 27001 certification. During a readiness review, the CISO identifies gaps: staff lack clear channels to raise concerns about system weaknesses, outcome tracking after adverse events is inconsistent, and there is no formalized way to assess what went right or wrong following disruptions. To comply with ISO/IEC 27001 Annex A.16, which action should be prioritized?

Options:
A.

Conduct tabletop exercises to simulate insider threat scenarios.

B.

Implement a centralized SIEM dashboard for real-time alerting.

C.

Define and implement structured procedures for flaw escalation and integrating post-incident response knowledge.

D.

Deploy EDR agents across endpoints for automatic quarantine.

Questions 69

After a recent cloud migration, AeroFlights, an airline company, spotted unauthorized data access. Preliminary checks hinted at malware that used cloud resources to spread, impacting flight schedules. Equipped with a cloud-specific security tool and a real-time scheduling monitor, what should be the primary action?

Options:
A.

Notify passengers about possible delays and offer compensation.

B.

Monitor flight schedules in real time to avoid potential disruptions.

C.

Temporarily halt all flight operations until the issue is resolved.

D.

Deploy the cloud security tool to identify and counteract the malware.

Questions 70

An IT security analyst at a logistics firm is alerted to unusual outbound traffic originating from an employee ' s mobile device, which is actively connected to the corporate VPN. Initial investigation confirms the presence of malware. Although antivirus scans are run multiple times, the malicious activity continues, suggesting the infection is deeply embedded or resistant to standard removal methods. The organization cannot afford further data leakage or operational disruptions caused by this device. Which action should the incident handler take next to ensure complete removal of the persistent threat and restore device integrity?

Options:
A.

Disable the SIM card.

B.

Switch the device to airplane mode.

C.

Perform a factory reset or reinstall the mobile OS.

D.

Restrict background app refresh for social apps.