Our pass rate is high to 98.9% and the similarity percentage between our 212-89 study guide and real exam is 90% based on our seven-year educating experience. Do you want achievements in the EC-Council 212-89 exam in just one try? I am currently studying for the EC-Council 212-89 exam. Latest EC-Council 212-89 Test exam practice questions and answers, Try EC-Council 212-89 Brain Dumps First.
Online EC-Council 212-89 free dumps demo Below:
NEW QUESTION 1
Common name(s) for CSIRT is(are)
- A. Incident Handling Team (IHT)
- B. Incident Response Team (IRT)
- C. Security Incident Response Team (SIRT)
- D. All the above
Answer: D
NEW QUESTION 2
A threat source does not present a risk if NO vulnerability that can be exercised for a particular threat source. Identify the step in which different threat sources are defined:
- A. Identification Vulnerabilities
- B. Control analysis
- C. Threat identification
- D. System characterization
Answer: C
NEW QUESTION 3
In which of the steps of NIST’s risk assessment methodology are the boundary of the IT system, along with the resources and the information that constitute the system identified?
- A. Likelihood Determination
- B. Control recommendation
- C. System characterization
- D. Control analysis
Answer: C
NEW QUESTION 4
Which of the following can be considered synonymous:
- A. Hazard and Threat
- B. Threat and Threat Agent
- C. Precaution and countermeasure
- D. Vulnerability and Danger
Answer: A
NEW QUESTION 5
Incidents are reported in order to:
- A. Provide stronger protection for systems and data
- B. Deal properly with legal issues
- C. Be prepared for handling future incidents
- D. All the above
Answer: D
NEW QUESTION 6
Which of the following terms may be defined as “a measure of possible inability to achieve a goal, objective, or target within a defined security, cost plan and technical limitations that adversely affects the organization’s operation and revenues?
- A. Risk
- B. Vulnerability
- C. Threat
- D. Incident Response
Answer: A
NEW QUESTION 7
ADAM, an employee from a multinational company, uses his company’s accounts to send e-mails to a third party with their spoofed mail address. How can you categorize this type of account?
- A. Inappropriate usage incident
- B. Unauthorized access incident
- C. Network intrusion incident
- D. Denial of Service incident
Answer: A
NEW QUESTION 8
Digital evidence plays a major role in prosecuting cyber criminals. John is a cyber-crime investigator, is asked to investigate a child pornography case. The personal computer of the criminal in question was confiscated by the county police. Which of the following evidence will lead John in his investigation?
- A. SAM file
- B. Web serve log
- C. Routing table list
- D. Web browser history
Answer: D
NEW QUESTION 9
Organizations or incident response teams need to protect the evidence for any future legal actions that may be taken against perpetrators that intentionally attacked the computer system. EVIDENCE PROTECTION is also required to meet legal compliance issues. Which of the following documents helps in protecting evidence from physical or logical damage:
- A. Network and host log records
- B. Chain-of-Custody
- C. Forensic analysis report
- D. Chain-of-Precedence
Answer: B
NEW QUESTION 10
What is the best staffing model for an incident response team if current employees’ expertise is very low?
- A. Fully outsourced
- B. Partially outsourced
- C. Fully insourced
- D. All the above
Answer: A
NEW QUESTION 11
The most common type(s) of intellectual property is(are):
- A. Copyrights and Trademarks
- B. Patents
- C. Industrial design rights & Trade secrets
- D. All the above
Answer: D
NEW QUESTION 12
The Linux command used to make binary copies of computer media and as a disk imaging tool if given a raw disk device as its input is:
- A. “dd” command
- B. “netstat” command
- C. “nslookup” command
- D. “find” command
Answer: A
NEW QUESTION 13
According to US-CERT; if an agency is unable to successfully mitigate a DOS attack it must be reported within:
- A. One (1) hour of discovery/detection if the successful attack is still ongoing
- B. Two (2) hours of discovery/detection if the successful attack is still ongoing
- C. Three (3) hours of discovery/detection if the successful attack is still ongoing
- D. Four (4) hours of discovery/detection if the successful attack is still ongoing
Answer: B
NEW QUESTION 14
An information security incident is
- A. Any real or suspected adverse event in relation to the security of computer systems or networks
- B. Any event that disrupts normal today’s business functions
- C. Any event that breaches the availability of information assets
- D. All of the above
Answer: D
NEW QUESTION 15
CSIRT can be implemented at:
- A. Internal enterprise level
- B. National, government and military level
- C. Vendor level
- D. All the above
Answer: D
NEW QUESTION 16
According to the Evidence Preservation policy, a forensic investigator should make at least ..................... image copies of the digital evidence.
- A. One image copy
- B. Two image copies
- C. Three image copies
- D. Four image copies
Answer: B
NEW QUESTION 17
The IDS and IPS system logs indicating an unusual deviation from typical network traffic flows; this is called:
- A. A Precursor
- B. An Indication
- C. A Proactive
- D. A Reactive
Answer: B
NEW QUESTION 18
The type of relationship between CSIRT and its constituency have an impact on the services provided by the CSIRT. Identify the level of the authority that enables members of CSIRT to undertake any necessary actions on behalf of their constituency?
- A. Full-level authority
- B. Mid-level authority
- C. Half-level authority
- D. Shared-level authority
Answer: A
NEW QUESTION 19
A methodical series of techniques and procedures for gathering evidence, from computing equipment and various storage devices and digital media, that can be presented in a court of law in a coherent and meaningful format is called:
- A. Forensic Analysis
- B. Computer Forensics
- C. Forensic Readiness
- D. Steganalysis
Answer: B
NEW QUESTION 20
An incident is analyzed for its nature, intensity and its effects on the network and systems. Which stage of the incident response and handling process involves auditing the system and network log files?
- A. Incident recording
- B. Reporting
- C. Containment
- D. Identification
Answer: D
NEW QUESTION 21
Overall Likelihood rating of a Threat to Exploit a Vulnerability is driven by :
- A. Threat-source motivation and capability
- B. Nature of the vulnerability
- C. Existence and effectiveness of the current controls
- D. All the above
Answer: D
NEW QUESTION 22
Preventing the incident from spreading and limiting the scope of the incident is known as:
- A. Incident Eradication
- B. Incident Protection
- C. Incident Containment
- D. Incident Classification
Answer: C
NEW QUESTION 23
A living high level document that states in writing a requirement and directions on how an agency plans to protect its information technology assets is called:
- A. Information security Policy
- B. Information security Procedure
- C. Information security Baseline
- D. Information security Standard
Answer: A
NEW QUESTION 24
......
100% Valid and Newest Version 212-89 Questions & Answers shared by Dumpscollection, Get Full Dumps HERE: http://www.dumpscollection.net/dumps/212-89/ (New 163 Q&As)
