
2022 New 212-89 Exam Questions Real EC-COUNCIL Dumps
Course 2022 212-89 Test Prep Training Practice Exam Download
NEW QUESTION 42
An organization faced an information security incident where a disgruntled employee passed sensitive access
control information to a competitor. The organization's incident response manager, upon investigation, found
that the incident must be handled within a few hours on the same day to maintain business continuity and
market competitiveness. How would you categorize such information security incident?
- A. Ultra-High level incident
- B. Middle level incident
- C. High level incident
- D. Low level incident
Answer: C
NEW QUESTION 43
Digital evidence plays a major role in prosecuting cyber criminals. John is a cyber-crime investigator, is asked to investigate a child pornography case. The personal computer of the criminal in question was confiscated by the county police. Which of the following evidence will lead John in his investigation?
- A. Web browser history
- B. SAM file
- C. Web serve log
- D. Routing table list
Answer: A
NEW QUESTION 44
Insiders may be:
- A. All the above
- B. Carless administrators
- C. Disgruntled staff members
- D. Ignorant employees
Answer: A
NEW QUESTION 45
CSIRT can be implemented at:
- A. Internal enterprise level
- B. All the above
- C. National, government and military level
- D. Vendor level
Answer: B
NEW QUESTION 46
Multiple component incidents consist of a combination of two or more attacks in a system. Which of the
following is not a multiple component incident?
- A. An attacker redirecting user to a malicious website and infects his system with Trojan
- B. An insider intentionally deleting files from a workstation
- C. An attacker infecting a machine to launch a DDoS attack
- D. An attacker using email with malicious code to infect internal workstation
Answer: B
NEW QUESTION 47
An assault on system security that is derived from an intelligent threat is called:
- A. Vulnerability
- B. Threat Agent
- C. Risk
- D. Attack
Answer: D
NEW QUESTION 48
Which among the following CERTs is an Internet provider to higher education institutions and various other research institutions in the Netherlands and deals with all cases related to computer security incidents in which a customer is involved either as a victim or as a suspect?
- A. NET-CERT
- B. SURFnet-CERT
- C. DFN-CERT
- D. Funet CERT
Answer: B
NEW QUESTION 49
A self-replicating malicious code that does not alter files but resides in active memory and duplicates itself, spreads through the infected network automatically and takes advantage of file or information transport features on the system to travel independently is called:
- A. RootKit
- B. Trojan
- C. Worm
- D. Virus
Answer: C
NEW QUESTION 50
The message that is received and requires an urgent action and it prompts the recipient to delete certain files or forward it to others is called:
- A. Mail bomb
- B. Spear Phishing
- C. A Virus Hoax
- D. An Adware
Answer: C
NEW QUESTION 51
The insider risk matrix consists of technical literacy and business process knowledge vectors. Considering the matrix, one can conclude that:
- A. If the insider's technical literacy and process knowledge are high, the risk posed by the threat will be insignificant.
- B. If the insider's technical literacy and process knowledge are high, the risk posed by the threat will be high.
- C. If the insider's technical literacy is high and process knowledge is low, the risk posed by the threat will be high.
- D. If the insider's technical literacy is low and process knowledge is high, the risk posed by the threat will be insignificant.
Answer: B
NEW QUESTION 52
The free, open source, TCP/IP protocol analyzer, sniffer and packet capturing utility standard across many
industries and educational institutions is known as:
- A. nmap
- B. Cain & Able
- C. Snort
- D. Wireshark
Answer: D
NEW QUESTION 53
ADAM, an employee from a multinational company, uses his company's accounts to send e-mails to a third party with their spoofed mail address. How can you categorize this type of account?
- A. Denial of Service incident
- B. Inappropriate usage incident
- C. Network intrusion incident
- D. Unauthorized access incident
Answer: B
NEW QUESTION 54
The Linux command used to make binary copies of computer media and as a disk imaging tool if given a raw disk device as its input is:
- A. "find" command
- B. "netstat" command
- C. "nslookup" command
- D. "dd" command
Answer: D
NEW QUESTION 55
A distributed Denial of Service (DDoS) attack is a more common type of DoS Attack, where a single system is targeted by a large number of infected machines over the Internet. In a DDoS attack, attackers first infect multiple systems which are known as:
- A. Trojans
- B. Worms
- C. Zombies
- D. Spyware
Answer: C
NEW QUESTION 56
The policy that defines which set of events needs to be logged in order to capture and review the important
data in a timely manner is known as:
- A. Evidence Collection policy
- B. Logging policy
- C. Audit trail policy
- D. Documentation policy
Answer: B
NEW QUESTION 57
A malicious security-breaking code that is disguised as any useful program that installs an executable
programs when a file is opened and allows others to control the victim's system is called:
- A. RootKit
- B. Trojan
- C. Virus
- D. Worm
Answer: B
Explanation:
Explanation
NEW QUESTION 58
Insider threats can be detected by observing concerning behaviors exhibited by insiders, such as conflicts with
supervisors and coworkers, decline in performance, tardiness or unexplained absenteeism. Select the
technique that helps in detecting insider threats:
- A. Protecting computer systems by implementing proper controls
- B. Categorizing information according to its sensitivity and access rights
- C. Making is compulsory for employees to sign a none disclosure agreement
- D. Correlating known patterns of suspicious and malicious behavior
Answer: D
Explanation:
Explanation
NEW QUESTION 59
......
212-89 Exam Info and Free Practice Test Professional Quiz Study Materials: https://passking.actualtorrent.com/212-89-exam-guide-torrent.html