
Updated Nov-2024 Test Engine or PDF for the EC-COUNCIL 212-89 test to help you quickly prepare for the EC-COUNCIL exam!
Full 212-89 Practice Test and 170 unique questions with explanations waiting just for you, get it now!
NEW QUESTION # 83
Malicious downloads that result from malicious office documents being manipulated are caused by which of the following?
- A. Impersonation
- B. Registry key manipulation
- C. Macro abuse
- D. Clickjacking
Answer: C
Explanation:
Malicious downloads initiated through manipulated office documents typically involve macro abuse. Macros are scripts that can automate tasks within documents and are embedded within Office documents like Word, Excel, and PowerPoint files. While macros can be used for legitimate purposes, they can also be abused by attackers to execute maliciouscode. When an office document with a malicious macro is opened, and macros are enabled, the macro can run arbitrary code that leads to malicious downloads, installing malware or performing other unauthorized actions on the victim's system.
Macro abuse has become a common vector for cyber attacks, as it exploits the functionality of widely used office applications. Attackers often craft phishing emails with attachments or links to documents that contain malicious macros, tricking users into enabling macros to execute the malicious code. This method is effective for bypassing some security measures since it relies on user interaction and exploitation of legitimate features.
References:In the ECIH v3 course by EC-Council, there is a focus on various methods used by attackers to compromise systems, including macro abuse in office documents. The curriculum stresses the importance of understanding these attack vectors for effective incident handling and response strategies.
NEW QUESTION # 84
Which of the following types of fuzz testing strategies does new data get generated from scratch, and the amount of data generated is predefined based on the testing model?
- A. Mutation-based fuzz testing
- B. Generation-based fuzz testing
- C. Protocol-based fuzz testing
- D. Log-based fuzz testing
Answer: B
NEW QUESTION # 85
The free, open source, TCP/IP protocol analyzer, sniffer and packet capturing utility standard across many industries and educational institutions is known as:
- A. nmap
- B. Cain & Able
- C. Wireshark
- D. Snort
Answer: C
NEW QUESTION # 86
Bran is an incident handler who is assessing the network of the organization. He wants to detect ping sweep attempts on the network using Wireshark. Which of the following Wireshark filters would Bran use to accomplish this task?
- A. icmp.ident
- B. icmp.scq
- C. icmp.lype==8
- D. icmp.redir_gw
Answer: C
NEW QUESTION # 87
Tom received a phishing email and accidentally opened its attachment. This resulted in the redirection of all traffic to a fraudulent website.
What type of phishing attack occurred in this scenario?
- A. Pharming
- B. Whaling
- C. Spimming
- D. Spear phishing
Answer: D
NEW QUESTION # 88
According to the Evidence Preservation policy, a forensic investigator should make at least ..................... image
copies of the digital evidence.
- A. Four image copies
- B. Three image copies
- C. One image copy
- D. Two image copies
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION # 89
Which of the following is not a best practice to eliminate the possibility of insider attacks?
- A. Monitoring employee behaviors and computer systems used by employees
- B. Disabling users from install ng unauthorized software or accessing malicious websites using the corporate network
- C. Implementing secure backup and disaster recovery processes for business continuity
- D. Always leave business details over voicemail or email messages
Answer: C
NEW QUESTION # 90
The Malicious code that is installed on the computer without user's knowledge to acquire information from the user's machine and send it to the attacker who can access it remotely is called:
- A. Logic Bomb
- B. Trojan
- C. Worm
- D. Spyware
Answer: D
NEW QUESTION # 91
Mike is an incident handler for PNP Infosystems Inc. One day, there was a ticket submitted regarding a critical incident and Mike was assigned to handle the incident. During the process of incident handling, at one stage, he performed incident analysis and validation to check whether the incident is a genuine incident or a false positive.
Identify the stage he is currently in.
- A. Incident triage
- B. Incident disclosure
- C. Post-incident activities
- D. Incident recording and assignment
Answer: A
Explanation:
Incident triage is the stage in the incident response process where the incident handler, like Mike, performs an initial assessment of the reported incident to determine its validity, severity, and potential impact. This includes analyzing the incident to verify if it is a genuine threat or a false positive. The purpose of incident triage is to prioritize incidents based on their criticality and ensure that resources are allocated effectively to address the most serious threats first. This stage is crucial for efficient incident management, as it helps in filtering out false alarms and focusing on real security incidents that require immediate attention.References:The ECIH v3 curriculum covers the incident response lifecycle, including the importance of incident triage as a key step in ensuring that incident handling efforts are focused on genuine security incidents, thereby optimizing the response process.
NEW QUESTION # 92
Stanley is an incident handler working for TexaCorp., a United States based organization. With the growing concern of increasing emails from outside the organization, Stanley was asked to take appropriate actions to keep the security of the organization intact. In the process of detecting and containing malicious emails, Stanley was asked to check the validity of the emails received by employees. Identify the tool Stanley can use to accomplish this task.
- A. Event Log Analyzer
- B. Polite Mail
- C. Email Dossier
- D. Point of Mail
Answer: D
NEW QUESTION # 93
The following steps describe the key activities in forensic readiness planning:
1. Train the staff to handle the incident and preserve the evidence
2. Create a special process for documenting the procedure
3. Identify the potential evidence required for an incident
4. Determine the source of the evidence
5. Establish a legal advisory board to guide the investigation process
6. Identify if the incident requires full or formal investigation
7. Establish a policy for securely handling and storing the collected evidence
8. Define a policy that determines the pathway to legally extract electronic evidence with minimal disruption Identify the correct sequence of steps involved in forensic readiness planning.
- A. 3-->1-->4-->5-->8-->2-->6-->7
- B. 3-->4-->8-->7-->6-->1-->2-->5
- C. 2-->3-->1-->4-->6-->5-->7-->8
- D. 1-->2-->3-->4-->5-->6-->7-->8
Answer: B
Explanation:
The correct sequence of steps involved in forensic readiness planning, based on the activities described, is as follows:
* Identify the potential evidence required for an incident.
* Determine the source of the evidence.
* Define a policy that determines the pathway to legally extract electronic evidence with minimal disruption.
* Establish a policy for securely handling and storing the collected evidence.
* Identify if the incident requires full or formal investigation.
* Train the staff to handle the incident and preserve the evidence.
* Create a special process for documenting the procedure.
* Establish a legal advisory board to guide the investigation process.This sequence ensures that an organization is prepared to handle incidents efficiently, with a focus on identifying relevant evidence and the legal context of its collection, followed by staff training and the establishment of guiding policies and advisory boards.References:Incident Handler (ECIH v3) courses and study guides include discussions on forensic readiness planning, highlighting the importance of preparing organizations for effective legal and technical handling of incidents.
NEW QUESTION # 94
Rose is an incident-handler and is responsible for detecting and eliminating any kind of scanning attempts over the network by malicious threat actors. Rose uses Wire shark to sniff the network and detect any malicious activities going on.
Which of the following Wireshark filters can be used by her to detect TCP Xmas scan attempt by the attacker?
- A. tcp.flags==0X 029
- B. tcp.flags==0X 000
- C. tcp.dstport== 7
- D. tcp.flags.reset== 1
Answer: A
NEW QUESTION # 95
Clark, a professional hacker, successfully exploited the web application of a target organization by tampering the form and parameter values. In result, Clark gained access to the information assets of the organization. Identify the vulnerability in the web application exploited by the attacker.
- A. Sensitive data exposure
- B. Broken access control
- C. SQL injection
- D. Security misconfiguration
Answer: C
NEW QUESTION # 96
Jason is an incident handler dealing with malware incidents. He was asked to perform memory dump analysis in order to collect the information about the basic functionality of any program. As a part of his assignment, he needs to perform string search analysis to search for the malicious string that could determine harmful actions that a program can perform. Which of the following string-searching tools Jason needs to use to do the intended task?
- A. Dependency Walker
- B. Process Explorer
- C. PEView
- D. BinText
Answer: D
NEW QUESTION # 97
What is the best staffing model for an incident response team if current employees' expertise is very low?
- A. All the above
- B. Fully insourced
- C. Fully outsourced
- D. Partially outsourced
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION # 98
......
Full 212-89 Practice Test and 170 unique questions with explanations waiting just for you, get it now: https://testking.testpassed.com/212-89-pass-rate.html