Question 1
Which practice will not help incident responders recover resources after a Google Cloud security incident?
Correct Answer:
Never take snapshots for recreating the disks
Explanation:
The choice to avoid taking snapshots for recreating disks is significant in the context of incident response and resource recovery following a security incident in Google Cloud. Snapshots are critical for preserving the state of a virtual machine's disks at a specific point in time. They allow responders to restore data and configurations to a known good state, which is essential for recovering from incidents and minimizing downtime. By not utilizing snapshots, incident responders miss an opportunity to quickly revert back to a pre-incident state or recover lost data efficiently. Snapshots can serve as a cost-effective and timely solution for regeneration of affected resources without the need to rely solely on longer recovery methods, such as restoring from backups. Snapshots not only aid in resource recovery but also facilitate forensic analysis by allowing responders to access the system state at the moment before the incident. This can provide critical insights for understanding what occurred and how to prevent similar events in the future. In summary, avoiding snapshots impedes effective incident recovery processes, thereby hindering the overall incident response efforts in a cloud environment.
Question 2
Which tool helps incident responders monitor and analyze user-based insider threats?
Correct Answer:
Ekran System
Explanation:
The Ekran System is designed specifically for monitoring and analyzing user activity, making it particularly effective in identifying potential insider threats. This tool focuses on user behavior and allows incident responders to track various activities within systems and applications. It offers features such as session recording, access control, and real-time alerts, all of which are crucial for detecting unusual patterns that may signify malicious intent from within the organization. By leveraging this capability, organizations can gain insights into user actions, investigate suspicious activities promptly, and take necessary responses to mitigate potential threats. In contrast, other tools like Wireshark are primarily used for network traffic analysis, while Infoblox is known for DNS management and security, and Vectra Cognito focuses on network-based threats and anomalies rather than specifically addressing user behavior. Thus, the Ekran System is uniquely positioned to address the challenges associated with insider threats effectively.
Question 3
What attack involves an insider entering a restricted area by following an authorized person?
Correct Answer:
Tailgating
Explanation:
The correct answer is tailgating. This type of attack occurs when an unauthorized individual gains access to a restricted area by closely following an authorized person, taking advantage of the legitimate entry granted to the authorized individual. Tailgating exploits social engineering techniques, where the unauthorized person relies on the trust or unawareness of the authorized individual to gain entry without proper credentials. In scenarios like this, the unauthorized person typically maintains proximity to the authorized user, entering through secure doors and access points without using their own access credentials. This method can be particularly effective in organizations where physical security measures do not prevent someone from following another person closely, thus highlighting the importance of awareness and vigilance in security protocols. The other options highlight different aspects of security and attack methods but do not directly describe the specific action of following someone to gain unauthorized access to a restricted area. Impersonation involves pretending to be someone else to gain access, while a physical breach refers to a more direct unauthorized entry. An access control breach can encompass a variety of unauthorized access methods but does not specifically capture the scenario of following an authorized individual.
Question 4
What is the main purpose of deploying an email filtering tool within an organization?
Correct Answer:
To screen and filter out malicious emails
Explanation:
The primary purpose of deploying an email filtering tool within an organization is to screen and filter out malicious emails. This is crucial for maintaining the security and integrity of the organization's digital communication. Email filtering tools are designed to identify and block spam, phishing attempts, and other potentially harmful content before they reach users' inboxes. By implementing such systems, organizations can significantly reduce the risk of malware infections, data breaches, and other security incidents that often originate from insecure email traffic. While enhancing user experience, tracking employee productivity, and managing company calendars may be beneficial functionalities in different contexts, they do not directly address the critical need for protecting the organization from the threats posed by malicious emails. The focus of email filtering is explicitly on security and the prevention of attacks, making this choice the most relevant answer to the question.
Question 5
What is the reporting timeframe for a DoS attack on a US Federal agency network?
Correct Answer:
2 hours
Explanation:
The reporting timeframe for a Denial of Service (DoS) attack on a US Federal agency network is indeed 2 hours. This timeframe is established to ensure that any potential threats to agency operations and national security are communicated swiftly and effectively. Early reporting allows for more timely intervention, investigation, and mitigation efforts to be initiated, minimizing the impact of the attack. The urgency in this reporting requirement underscores the critical nature of maintaining operational integrity in federal networks, as DoS attacks can disrupt services and impact the ability to perform essential government functions. Reporting within this 2-hour window allows for coordinated responses, involving necessary cybersecurity teams and other relevant stakeholders, facilitating a rapid and organized approach to addressing the incident. Overall, this timeframe reflects a balance between immediate awareness and practical operational capabilities for incident responders while ensuring that appropriate measures can be taken to safeguard information and systems from further risk or deterioration.
Question 1
Exam overview

About this Exam

The Certified Incident Handler (CIH) certification, provided by EC-Council, is a specialist-level program designed for cybersecurity professionals tasked with managing the aftermath of a security breach.

It goes beyond theoretical knowledge to impart the tactical skills needed to effectively plan, record, triage, notify, and contain a cyber incident.

The program is engineered for individuals who are serious about reducing the financial and reputational impact of security events on an organization.

It is ideally suited for incident handlers, risk assessment administrators, penetration testers, cyber forensic investigators, and system administrators who want to specialize in post-breach response. 

More details

Additional Information

What the Course Entails and Exam Details

The CIH curriculum offers a holistic method-driven approach to organizational Incident Handling and Response (IH&R).

You will gain a deep understanding of standard frameworks, legal compliance, and the essential steps of planning an IH&R program.

Key core domains covered in the syllabus include:

  • Introduction to Incident Handling and Response.
  • The Nine-Stage Incident Handling and Response Process: Preparation, Recording & Assignment, Triage, Notification, Containment, Evidence Gathering & Forensic Analysis, Eradication, Recovery, and Post-Incident Activities.
  • First Response Concepts and Digital Evidence Collection.
  • Handling and Responding to Malware Incidents.
  • Handling and Responding to Email Security Incidents.
  • Handling and Responding to Network Security Incidents.
  • Handling and Responding to Web Application Security Incidents.
  • Handling and Responding to Cloud Security Incidents.
  • Handling and Responding to Insider Threats.

 What to Expect in the Final Exam

The final Certified Incident Handler exam is a rigorous assessment of both your theoretical knowledge and practical understanding of IH&R methodologies.

The current exam format typically consists of:

  • Number of Questions: 100 multiple-choice questions.
  • Test Duration: 3 hours.
  • Test Format: Multiple Choice.
  • Passing Score: The passing score is approximately 70%, though this can vary slightly depending on the specific exam form.

The exam is designed to test your ability to apply the correct procedural framework to realistic incident scenarios, ensuring you can make critical decisions under pressure to contain threats and preserve evidence.

 

 

 How to Study and Exam Centers

Preparation for the CIH exam requires a structured approach.

How to Study:

  • Official Training: EC-Council’s official training program is highly recommended. It includes over 1,600 pages of student manual, illustrative slides, and numerous templates, checklists, and playbooks.
  • Hands-On Labs (iLabs): The CIH course is known for its extensive lab component. Candidates should spend significant time in the iLabs environment, which simulates real-world operating systems and incident scenarios using over 800 tools. Practicing the complete 9-stage process in labs is crucial.
  • Practice Tests: Utilize authorized CIH practice exams to familiarize yourself with the question style and identify weak areas in your process management.
  • Study Guides: Create a one-page "must-know" checklist per domain covering indicators to look for, immediate containment options, and mistakes to avoid.

Exam Centers:

The CIH exam is administered through the EC-Council Exam Portal at www.eccexam.com.

Candidates can take the exam remotely proctored or at an authorized EC-Council physical testing center or accredited training school.

 

 

 Job Opportunities from the Course

Earning the CIH certification validates your specialist expertise in the critical area of incident response, opening doors to advanced roles.

This credential unlocks several career paths, including:

  • Incident Responder
  • Security Operations Center (SOC) Analyst (Tier II/III)
  • Cyber Security Incident Response Specialist
  • Incident Response Manager
  • Threat Intelligence Specialist
  • Digital Forensic Analyst
  • Cyber Risk Vulnerability Manager
  • Cyber Defense Analyst
  • Forensics and Incident Response Team Lead
  • Cybersecurity Consultant
Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions