| Exam Name: | EC Council Certified Incident Handler (ECIH v3) | ||
| Exam Code: | 212-89 Dumps | ||
| Vendor: | ECCouncil | Certification: | ECIH |
| Questions: | 356 Q&A's | Shared By: | kiyaan |
In the wake of a sophisticated cyber attack at a global financial institution involving encrypted data exfiltration, an incident handler must preserve volatile memory for forensic investigation. What should be the incident handler ' s immediate action?
SafePay, an online payment portal, recently introduced an advanced search feature allowing users to search for their transaction history. A week later, an alarming number of users reported unauthorized transactions. Investigation showed that attackers were using advanced search strings, exploiting a previously unidentified vulnerability. What is SafePay ' s best immediate action?
A cloud service provider detected anomalous activities pointing to a potential compromise of their infrastructure. The IH & R team is confronted with vast amounts of data from various cloud-native logging mechanisms. To ensure swift and effective incident triage, what should be their primary course of action?
Which of the following is a type of malicious code or software that appears legitimate but can take control of your computer?