Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

100% Free Real Updated 212-89 Questions & Answers Pass Your Exam Easily [Q104-Q121]

Share

100% Free Real Updated 212-89 Questions & Answers Pass Your Exam Easily

Easily To Pass New 212-89 Verified & Correct Answers

NEW QUESTION # 104
GlobalCorp, a leading software development company, recently launched a cloud-based CRM application.
However, within a week, customers reported unauthorized access incidents. On investigation, it was discovered that the vulnerability was due to improper session management, allowing session fixation attacks.
How should GlobalCorp address this vulnerability?

  • A. Store session IDs in encrypted cookies.
  • B. Implement CAPTCHA on all login pages.
  • C. Rotate session tokens after successful login.
  • D. Increase the complexity of user passwords.

Answer: C

Explanation:
Comprehensive and Detailed Explanation (ECIH-aligned):
This scenario involves a session fixation vulnerability, a well-known web application attack where an attacker forces or predicts a session identifier and then tricks a user into authenticating with that session. According to the ECIH web application security module, proper session management is essential to prevent such attacks.
Option B is correct because rotating or regenerating session tokens immediately after successful authentication ensures that any session identifier known to an attacker becomes invalid. This breaks the attack chain inherent in session fixation attacks. ECIH explicitly identifies session regeneration as a primary mitigation control.
Option A helps against automated abuse but does not address session reuse. Option C strengthens authentication but does not prevent session hijacking. Option D improves confidentiality but does not prevent fixation if the same session ID remains valid.
ECIH stresses that authentication and session management must be treated as distinct security controls. Even strong passwords cannot protect against flawed session handling. Therefore, regenerating session tokens post- login is the correct and most effective remediation.


NEW QUESTION # 105
Lara, a SOC analyst, investigates multiple alerts generated by an IDS showing repeated login failures from a specific workstation to an internal application. When reviewing Windows Event Viewer logs, she discovers a user repeatedly attempting logins outside of working hours. Further checks reveal the user had installed an unauthorized remote desktop tool. Which of the following best describes this situation?

  • A. Inappropriate usage due to policy violation and software installation
  • B. Unauthorized access incident from a third party
  • C. Policy-enforced remote work attempt
  • D. DoS attack against an internal application

Answer: A

Explanation:
The EC-Council Incident Handler (ECIH) curriculum categorizes incidents such as unauthorized software installation and policy violations under inappropriate usage incidents. In this scenario, the activity originated from a legitimate internal workstation and user account, not an external third party.
The repeated login failures outside business hours combined with installation of an unauthorized remote desktop tool indicate a breach of acceptable use policy and potentially malicious intent. However, the key factor is that the actions were performed by an internal user using valid access credentials, making this an insider-related policy violation rather than an external unauthorized access attack.
Option A implies legitimate remote work within policy boundaries, which is contradicted by the unauthorized software installation. Option B suggests a third-party compromise, but logs indicate activity from an internal user account. Option D (DoS attack) involves service disruption via traffic flooding, which is not described here.
ECIH stresses enforcing acceptable use policies, monitoring user behavior, restricting unauthorized software installation, and applying least privilege controls to mitigate insider misuse. Therefore, this scenario best fits inappropriate usage due to policy violation and unauthorized software installation.


NEW QUESTION # 106
Which of the following is NOT part of the static data collection process?

  • A. Password protection
  • B. Evidence acquisition
  • C. System preservation
  • D. Evidence examination

Answer: A


NEW QUESTION # 107
In which of the following stages of the incident handling and response (IH&R) process do the incident handlers try to find the root cause of the incident along with the threat actors behind the incidents, threat vectors, etc.?

  • A. Incident recording and assignment
  • B. Post-incident activities
  • C. Evidence gathering and forensics analysis
  • D. Incident triage

Answer: C


NEW QUESTION # 108
In the gaming industry, Playverse Ltd. noticed that their latest game had an unauthorized "mod" that allowed players unique abilities. However, this mod was malicious, altering in-game purchases and accessing players' financial details. Having tools like a real-time game environment scanner and a user-behavior monitor, what's the best initial approach?

  • A. Use the environment scanner to detect and remove the unauthorized mod.
  • B. Announce the mod's risks on official channels and urge players to uninstall it.
  • C. Monitor player behaviors to identify those using the mod and restrict access.
  • D. Push an update to disable all mods for the game.

Answer: D

Explanation:
This incident involves malware embedded within third-party modifications, affecting financial data and game integrity. The ECIH malware handling framework prioritizes rapid containment to prevent further exploitation before analysis or public communication.
Option B is correct because disabling all mods immediately stops the malicious mod from continuing to operate, preventing additional data theft and financial abuse. This action contains the threat across the entire user base quickly and uniformly.
Option A focuses on detection and removal but may miss distributed instances already in use. Option C is a communication step that should follow containment. Option D delays action and allows continued exploitation.
ECIH stresses that when malware is actively impacting users at scale, containment actions that reduce attack surface globally are preferred. Disabling all mods is the fastest and safest initial containment measure, making Option B correct.


NEW QUESTION # 109
An adversary attacks the information resources to gain undue advantage is called:

  • A. Electronic Warfare
  • B. Defensive Information Warfare
  • C. Offensive Information Warfare
  • D. Conventional Warfare

Answer: C


NEW QUESTION # 110
An organization named Sam Morison Inc. decided to use cloud-based services to reduce the cost of their maintenance. They first identified various risks and threats associated with cloud .. adoption and migrating critical business data to third-party systems. Hence, the organization decided to deploy cloud-based security tools to prevent upcoming threats. Which of the following tools would help the organization to secure cloud resources and services?

  • A. Nmap
  • B. Burp Suite
  • C. Alert Logic
  • D. Wireshark

Answer: C


NEW QUESTION # 111
Oscar receives an email from an unknown source containing his domain name oscar.com. Upon checking the link, he found that it contains a malicious URL that redirects to the website evil site.org.
What type of vulnerability is this?

  • A. Unvalidated redirects and forwards
  • B. SQL injection
  • C. Malware
  • D. Botnet

Answer: A


NEW QUESTION # 112
Incident response team must adhere to the following:

  • A. Stay calm and document everything
  • B. Notify appropriate personnel
  • C. All the above
  • D. Assess the situation

Answer: C


NEW QUESTION # 113
According to the Evidence Preservation policy, a forensic investigator should make at least ..................... image
copies of the digital evidence.

  • A. Two image copies
  • B. One image copy
  • C. Three image copies
  • D. Four image copies

Answer: A

Explanation:
Explanation/Reference:


NEW QUESTION # 114
Aaron, a digital first responder, is dispatched to an R&D lab after a suspected insider data breach involving intellectual property theft. Upon entering the lab, he observes fingerprint smudges on a workstation keyboard, oily residue on a DVD near the printer, and an unplugged USB drive on the desk. He documents the position of each item, uses gloves and evidence tags, covers surfaces to prevent contamination, and restricts access to the area. Which best practice is Aaron demonstrating?

  • A. Safeguarding volatile system state for RAM acquisition
  • B. Preserving trace-level physical indicators for attribution
  • C. Isolating system peripherals for digital chain-of-custody
  • D. Capturing live session activity from open peripherals

Answer: B

Explanation:
Comprehensive and Detailed Explanation (ECIH-aligned):
This scenario focuses on physical forensic evidence preservation, a key concept in the ECIH First Response module. Trace-level indicators such as fingerprints, residues, and physical media can provide attribution in insider investigations.
Option A is correct because Aaron's actions prevent contamination or destruction of physical trace evidence that may later link the incident to a specific individual. ECIH stresses that digital investigations often involve physical evidence, especially in insider cases.
Options B-D focus on digital evidence, which is not the primary concern described here.
Proper preservation of physical trace evidence supports attribution, legal proceedings, and disciplinary action, aligning fully with ECIH forensic readiness principles.


NEW QUESTION # 115
Bob, an incident responder at CyberTech Solutions, is investigating a cybercrime attack occurred in the client company. He acquired the evidence data, preserved it, and started performing analysis on acquired evidentiary data to identify the source of the crime and the culprit behind the incident.
Identify the forensic investigation phase in which Bob is currently in.

  • A. Vulnerability assessment phase
  • B. Post-investigation phase
  • C. Investigation phas
  • D. Pre-investigation phase

Answer: C


NEW QUESTION # 116
Business Continuity provides a planning methodology that allows continuity in business operations:

  • A. Before and after a disaster
  • B. Before, during and after a disaster
  • C. Before a disaster
  • D. During and after a disaster

Answer: B


NEW QUESTION # 117
The data on the affected system must be backed up so that it can be retrieved if it is damaged during incident response. The system backup can also be used for further investigations of the incident. Identify the stage of the incident response and handling process in which complete backup of the infected system is carried out?

  • A. Incident investigation
  • B. Incident recording
  • C. Containment
  • D. Eradication

Answer: C


NEW QUESTION # 118
In which of the following phases of incident handling and response (IH&R) process are the identified security incidents analyzed, validated, categorized, and prioritized?

  • A. Containment
  • B. Incident recording and assignment
  • C. Notification
  • D. Incident triage

Answer: D


NEW QUESTION # 119
The correct sequence of incident management process is:

  • A. Prepare, protect, detect, respond and triage
  • B. Prepare, protect, triage, detect and respond
  • C. Prepare, protect, detect, triage and respond
  • D. Prepare, detect, protect, triage and respond

Answer: C


NEW QUESTION # 120
Which of the following is not called volatile data?

  • A. Open sockets er open ports
  • B. Creation dates of files
  • C. The dale a no Lime of the system
  • D. State of the network interface

Answer: B

Explanation:
Volatile data refers to information that is stored temporarily and is lost when a computer is turned off or restarted, such as RAM contents, including open sockets and open ports, the date and time of the system, and the state of the network interface. The creation dates of files, however, are considered non-volatile data because they are preserved on the hard drive and remain available after the system is restarted or turned off.
Non-volatile data is stored on persistent storage mediums like hard drives, SSDs, and magnetic tapes, where it remains until it is deleted or overwritten.References:The Incident Handler (ECIH v3) certification emphasizes the distinction between volatile and non-volatile data in the context of digital forensics and incident response, highlighting the importance of understanding what data may be lost upon system shutdown and what data persists.


NEW QUESTION # 121
......

Free 212-89 Exam Files Downloaded Instantly: https://troytec.examstorrent.com/212-89-exam-dumps-torrent.html