[Nov 06, 2021] 212-89 Exam Dumps - Try Best 212-89 Exam Questions - BraindumpsPrep [Q39-Q64]

Share

[Nov 06, 2021] 212-89 Exam Dumps - Try Best 212-89 Exam Questions - BraindumpsPrep

Verified 212-89 exam dumps Q&As with Correct 165 Questions and Answers


Detailed Guide on 212-89 Areas

The first tested area is focused on incident handling and response. Thus, the candidates should know how to deal with computer security, information security, and security policies. Moreover, you will also learn about risk management in incident response and threat intelligence. Incident handling is also part of the tested area. Finally, the candidates should possess in-depth knowledge of how information security is implemented to resolve the issues related to security.

When it comes to the second category, it focuses on email security incidents. Particularly, this area involves email security features as well as various email incidents. Also, the candidate's knowledge of how suspicious emails are is measured in such a topic. Besides, you will also need to identify phishing emails as well as to detect deceptive emails to be successful in this domain.

As you remember, the third objective involves process handling. It describes the incident readiness, security auditing, and incident handling alongside response. The candidate will also get knowledge about how to do forensic investigation for incident handling. The eradication and recovery are also included in the exam syllabus.

The fourth section defines application-level incidents. It deals with web application vulnerabilities and threats. Here, you will also be able to identify the web attacks that occur in the application. Finally, it involves the eradication of the web application.

The fifth tested area focuses on mobile & network incidents. It allows the candidates to learn about illegal access, denial-of-service, and wireless networks. You will also come across network attacks, unsuitable usage, and mobile platform risks and vulnerabilities. Moreover, the abolition of mobile recovery and incidents is also part of the official exam.

The sixth domain includes malware incidents. Particularly, it describes the malware as a whole, malicious codes, and malware incidents. What's more, you will learn information about malware facets and how it affects the information system and applications.

The seventh objective revolves around insider threats. It defines insider threat particularities and how to detect and prevent them. Within such a section, you will also get to know about the employee monitoring tools and insider threats eradication.

The eighth area focuses on cloud environment incidents. It involves the security of cloud computing and cloud computing threats. Plus, you will learn about recovery in the cloud and the eradication threats in this area of 212-89 exam. Mainly, the candidate's knowledge about incidents occurring in a cloud environment is assessed during such a test.

The ninth portion is first response and forensic readiness. It focuses on digital evidence, forensic readiness, and volatile evidence. You will also be tested upon computer forensics, the protection of electronic evidence, and static evidence. On top of these, the candidate should also have knowledge of anti-forensics for attempting the final test.


EC-COUNCIL 212-89 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Handling and Responding to Web Application Security Incidents
  • Introduction to Incident Handling and Response
Topic 2
  • Handling and Responding to Network Security Incidents
  • Handling and Responding to Malware Incidents
Topic 3
  • Handling and Responding to Insider Threats
  • Forensic Readiness and First Response
Topic 4
  • Handling and Responding to Cloud Security Incidents
  • Incident Handling and Response Process
Topic 5
  • Handling and Responding to Email Security Incidents

 

NEW QUESTION 39
The state of incident response preparedness that enables an organization to maximize its potential to use
digital evidence while minimizing the cost of an investigation is called:

  • A. Digital Forensic Policy
  • B. Computer Forensics
  • C. Digital Forensic Analysis
  • D. Forensic Readiness

Answer: D

 

NEW QUESTION 40
An active vulnerability scanner featuring high speed discovery, configuration auditing, asset profiling, sensitive data discovery, and vulnerability analysis is called:

  • A. EtherApe
  • B. CyberCop
  • C. Nessus
  • D. nmap

Answer: C

 

NEW QUESTION 41
The open source TCP/IP network intrusion prevention and detection system (IDS/IPS), uses a rule-driven language, performs real-time traffic analysis and packet logging is known as:

  • A. Snort
  • B. SAINT
  • C. Wireshark
  • D. Nessus

Answer: A

 

NEW QUESTION 42
Identify a standard national process which establishes a set of activities, general tasks and a management structure to certify and accredit systems that will maintain the information assurance (IA) and security posture of a system or site.

  • A. NIAAAP
  • B. NIACAP
  • C. NIPACP
  • D. NIASAP

Answer: B

 

NEW QUESTION 43
What is correct about Quantitative Risk Analysis:

  • A. Easily automated
  • B. It is Subjective but faster than Qualitative Risk Analysis
  • C. Uses levels and descriptive expressions
  • D. Better than Qualitative Risk Analysis

Answer: A

 

NEW QUESTION 44
Contingency planning enables organizations to develop and maintain effective methods to handle emergencies. Every organization will have its own specific requirements that the planning should address. There are five major components of the IT contingency plan, namely supporting information, notification activation, recovery and reconstitution and plan appendices. What is the main purpose of the reconstitution plan?

  • A. To provide the introduction and detailed concept of the contingency plan
  • B. To define the notification procedures, damage assessments and offers the plan activation
  • C. To provide a sequence of recovery activities with the help of recovery procedures
  • D. To restore the original site, tests systems to prevent the incident and terminates operations

Answer: D

 

NEW QUESTION 45
Any information of probative value that is either stored or transmitted in a digital form during a computer crime is called:

  • A. Digital Forensic Examiner
  • B. Digital evidence
  • C. Computer Emails
  • D. Digital investigation

Answer: B

 

NEW QUESTION 46
ADAM, an employee from a multinational company, uses his company's accounts to send e-mails to a third party with their spoofed mail address. How can you categorize this type of account?

  • A. Unauthorized access incident
  • B. Inappropriate usage incident
  • C. Network intrusion incident
  • D. Denial of Service incident

Answer: B

 

NEW QUESTION 47
An adversary attacks the information resources to gain undue advantage is called:

  • A. Electronic Warfare
  • B. Offensive Information Warfare
  • C. Defensive Information Warfare
  • D. Conventional Warfare

Answer: B

Explanation:
Explanation/Reference:

 

NEW QUESTION 48
The process of rebuilding and restoring the computer systems affected by an incident to normal operational
stage including all the processes, policies and tools is known as:

  • A. Incident Recovery
  • B. Incident Response
  • C. Incident Handling
  • D. Incident Management

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 49
The most common type(s) of intellectual property is(are):

  • A. Industrial design rights & Trade secrets
  • B. All the above
  • C. Patents
  • D. Copyrights and Trademarks

Answer: B

Explanation:
Explanation/Reference:

 

NEW QUESTION 50
Which policy recommends controls for securing and tracking organizational resources:

  • A. Administrative security policy
  • B. Access control policy
  • C. Asset control policy
  • D. Acceptable use policy

Answer: C

Explanation:
Explanation/Reference:

 

NEW QUESTION 51
The ability of an agency to continue to function even after a disastrous event, accomplished through the deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy is known as:

  • A. Contingency Planning
  • B. Disaster Planning
  • C. Business Continuity
  • D. Business Continuity Plan

Answer: C

 

NEW QUESTION 52
Business Continuity provides a planning methodology that allows continuity in business operations:

  • A. Before a disaster
  • B. Before, during and after a disaster
  • C. Before and after a disaster
  • D. During and after a disaster

Answer: B

 

NEW QUESTION 53
Agencies do NOT report an information security incident is because of:

  • A. Afraid of negative publicity
  • B. All the above
  • C. Have full knowledge about how to handle the attack internally
  • D. Do not want to pay the additional cost of reporting an incident

Answer: A

 

NEW QUESTION 54
The message that is received and requires an urgent action and it prompts the recipient to delete certain files or forward it to others is called:

  • A. An Adware
  • B. Spear Phishing
  • C. Mail bomb
  • D. A Virus Hoax

Answer: D

 

NEW QUESTION 55
Incident prioritization must be based on:

  • A. All the above
  • B. Criticality of affected systems
  • C. Potential impact
  • D. Current damage

Answer: A

 

NEW QUESTION 56
________________ attach(es) to files

  • A. Worms
  • B. Spyware
  • C. Viruses
  • D. adware

Answer: C

 

NEW QUESTION 57
Quantitative risk is the numerical determination of the probability of an adverse event and the extent of the
losses due to the event. Quantitative risk is calculated as:

  • A. (Probability of Loss) X (Loss)
  • B. Significant Risks X Probability of Loss X Loss
  • C. (Loss) / (Probability of Loss)
  • D. (Probability of Loss) / (Loss)

Answer: A

 

NEW QUESTION 58
Identify the network security incident where intended authorized users are prevented from using system,
network, or applications by flooding the network with high volume of traffic that consumes all existing network
resources.

  • A. URL Manipulation
  • B. Denial of Service Attack
  • C. XSS Attack
  • D. SQL Injection

Answer: B

 

NEW QUESTION 59
The very well-known free open source port, OS and service scanner and network discovery utility is called:

  • A. Nmap (Network Mapper)
  • B. SAINT
  • C. Wireshark
  • D. Snort

Answer: A

 

NEW QUESTION 60
The data on the affected system must be backed up so that it can be retrieved if it is damaged during incident response. The system backup can also be used for further investigations of the incident. Identify the stage of the incident response and handling process in which complete backup of the infected system is carried out?

  • A. Containment
  • B. Eradication
  • C. Incident recording
  • D. Incident investigation

Answer: A

 

NEW QUESTION 61
Quantitative risk is the numerical determination of the probability of an adverse event and the extent of the losses due to the event. Quantitative risk is calculated as:

  • A. (Probability of Loss) X (Loss)
  • B. Significant Risks X Probability of Loss X Loss
  • C. (Loss) / (Probability of Loss)
  • D. (Probability of Loss) / (Loss)

Answer: A

 

NEW QUESTION 62
The left over risk after implementing a control is called:

  • A. Critical risk
  • B. Low risk
  • C. Unaccepted risk
  • D. Residual risk

Answer: D

 

NEW QUESTION 63
An access control policy authorized a group of users to perform a set of actions on a set of resources. Access to resources is based on necessity and if a particular job role requires the use of those resources. Which of the following is NOT a fundamental element of access control policy

  • A. Action group: group of actions performed by the users on resources
  • B. Development group: group of persons who develop the policy
  • C. Access group: group of users to which the policy applies
  • D. Resource group: resources controlled by the policy

Answer: B

 

NEW QUESTION 64
......

EC-COUNCIL 212-89 Test Engine PDF - All Free Dumps: https://www.briandumpsprep.com/212-89-prep-exam-braindumps.html

Get New 212-89 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1Yn1vFyMyRE1yakaDn7PshzLGtVgu2bjT