[Q111-Q133] Exam 212-89 Realistic Dumps Verified Questions Free [Sep 11, 2022]

Share

Exam 212-89 Realistic Dumps Verified Questions Free [Sep 11, 2022]

Valid 212-89 Dumps for Helping Passing EC-COUNCIL Exam!

NEW QUESTION 111
The open source TCP/IP network intrusion prevention and detection system (IDS/IPS), uses a rule-driven language, performs real-time traffic analysis and packet logging is known as:

  • A. Snort
  • B. Wireshark
  • C. Nessus
  • D. SAINT

Answer: A

 

NEW QUESTION 112
Chandler is a professional hacker who is targeting an organization called Technote. He wants to obtain important organizational information that is being transmitted between different hierarchies. In the process, he is sniff ng the data packets transmitted through the network and then analyzing them to gather packet details such as network, ports, protocols, devices, issues in network transmission, and other network specifications.
Which of the following tools would Chandler employ to perform packet analysis?

  • A. BeEf
  • B. Omni peek
  • C. IDA Pro
  • D. Sharp

Answer: B

 

NEW QUESTION 113
A methodical series of techniques and procedures for gathering evidence, from computing equipment and various storage devices and digital media, that can be presented in a court of law in a coherent and meaningful format is called:

  • A. Computer Forensics
  • B. Forensic Readiness
  • C. Steganalysis
  • D. Forensic Analysis

Answer: A

 

NEW QUESTION 114
The service organization that provides 24x7 computer security incident response services to any user, company, government agency, or organization is known as:

  • A. Computer Security Incident Response Team CSIRT
  • B. Vulnerability Assessor
  • C. Digital Forensics Examiner
  • D. Security Operations Center SOC

Answer: A

 

NEW QUESTION 115
The typical correct sequence of activities used by CSIRT when handling a case is:

  • A. Log, inform, maintain contacts, release information, follow up and reporting
  • B. Log, maintain contacts, release information, inform, follow up and reporting
  • C. Log, inform, release information, maintain contacts, follow up and reporting
  • D. Log, maintain contacts, inform, release information, follow up and reporting

Answer: A

 

NEW QUESTION 116
According to the Fourth Amendment of USA PATRIOT Act of 2001; if a search does NOT violate a person's "reasonable" or "legitimate" expectation of privacy then it is considered:

  • A. Illegal/ illegitimate
  • B. None of the above
  • C. Constitutional/ Legitimate
  • D. Unethical

Answer: C

 

NEW QUESTION 117
An incident recovery plan is a statement of actions that should be taken before, during or after an incident.
Identify which of the following is NOT an objective of the incident recovery plan?

  • A. Providing assurance that systems are reliable
  • B. Providing a standard for testing the recovery plan
  • C. Avoiding the legal liabilities arising due to incident
  • D. Creating new business processes to maintain profitability after incident

Answer: D

Explanation:
Explanation/Reference:

 

NEW QUESTION 118
Except for some common roles, the roles in an IRT are distinct for every organization. Which among the
following is the role played by the Incident Coordinator of an IRT?

  • A. Links the groups that are affected by the incidents, such as legal, human resources, different business
    areas and management
  • B. Links the appropriate technology to the incident to ensure that the foundation's offices are returned to
    normal operations as quickly as possible
  • C. Applies the appropriate technology and tries to eradicate and recover from the incident
  • D. Focuses on the incident and handles it from management and technical point of view

Answer: A

 

NEW QUESTION 119
An audit trail policy collects all audit trails such as series of records of computer events, about an operating system, application or user activities. Which of the following statements is NOT true for an audit trail policy:

  • A. It helps calculating intangible losses to the organization due to incident
  • B. It helps tracking individual actions and allows users to be personally accountable for their actions
  • C. It helps in compliance to various regulatory laws, rules,and guidelines
  • D. It helps in reconstructing the events after a problem has occurred

Answer: A

 

NEW QUESTION 120
If the loss anticipated is greater than the agreed upon threshold; the organization will:

  • A. Do nothing
  • B. Accept the risk but after management approval
  • C. Mitigate the risk
  • D. Accept the risk

Answer: C

 

NEW QUESTION 121
Absorbing minor risks while preparing to respond to major ones is called:

  • A. Risk Assumption
  • B. Risk Mitigation
  • C. Risk Transfer
  • D. Risk Avoidance

Answer: A

 

NEW QUESTION 122
Which of the following is a term that describes the combination of strategies and services intended to restore data, applications, and other resources to the public cloud or dedicated service providers?

  • A. Eradication
  • B. Cloud recovery
  • C. Analysis
  • D. Mitigation

Answer: B

 

NEW QUESTION 123
Rossi san incident manager (IM) and his team provides support to all users in the organization that are affected by the threat or attack. David, who is the organizational internal auditor, is also part of the Ross's incident response team.
Among the following duties, identify one of the responsibilities of David.

  • A. Identify and report security loopholes to management for necessary action
  • B. Coordinate incident containment activities with the information security officer (ISO)
  • C. Preform the necessary action required to block the network traffic from the suspected intruder
  • D. Configure information security controls

Answer: A

 

NEW QUESTION 124
The IDS and IPS system logs indicating an unusual deviation from typical network traffic flows; this is called:

  • A. A Proactive
  • B. A Reactive
  • C. A Precursor
  • D. An Indication

Answer: D

 

NEW QUESTION 125
The steps followed to recover computer systems after an incident are:

  • A. System monitoring, validation, operation and restoration
  • B. System restoration, validation, operation and monitoring
  • C. System validation, restoration, operation and monitoring
  • D. System restoration, operation, validation, and monitoring

Answer: B

 

NEW QUESTION 126
Computer Forensics is the branch of forensic science in which legal evidence is found in any computer or any digital media device. Of the following, who is responsible for examining the evidence acquired and separating the useful evidence?

  • A. Evidence Supervisor
  • B. Evidence Examiner/ Investigator
  • C. Evidence Manager
  • D. Evidence Documenter

Answer: B

 

NEW QUESTION 127
According to NITS, what are the 5 main actors in cloud computing?

  • A. None of these
  • B. Consumer, provider, carrier, auditor, and broker
  • C. Buyer, consumer, carrier, auditor, and broker
  • D. Provider, carrier, auditor, broker, and seller

Answer: B

 

NEW QUESTION 128
The Linux command used to make binary copies of computer media and as a disk imaging tool if given a raw disk device as its input is:

  • A. "find" command
  • B. "dd" command
  • C. "netstat" command
  • D. "nslookup" command

Answer: B

 

NEW QUESTION 129
An access control policy authorized a group of users to perform a set of actions on a set of resources. Access to resources is based on necessity and if a particular job role requires the use of those resources. Which of the following is NOT a fundamental element of access control policy

  • A. Resource group: resources controlled by the policy
  • B. Action group: group of actions performed by the users on resources
  • C. Access group: group of users to which the policy applies
  • D. Development group: group of persons who develop the policy

Answer: D

 

NEW QUESTION 130
Which of the following email security tools can be used by an incident handler to prevent the organization against evolving email threats?

  • A. Mx Toolbox
  • B. Gpg4win
  • C. G Suite Toolbox
  • D. Email Header Analyzer

Answer: B

 

NEW QUESTION 131
Incidents such as DDoS that should be handled immediately may be considered as:

  • A. Level Four incident
  • B. Level Three incident
  • C. Level Two incident
  • D. Level One incident

Answer: B

 

NEW QUESTION 132
Elizabeth, who works for OBC organization as an incident responder, is assessing the risks to the organizational security. As part of the assessment process, she is calculating the probability of a threat source exploiting an existing system vulnerability.
Which of the following risk assessment steps is Elizabeth currently in?

  • A. Likelihood analysis
  • B. Impact analysis
  • C. System characterization
  • D. Vulnerability identification

Answer: D

 

NEW QUESTION 133
......

212-89 Exam Dumps For Certification Exam Preparation: https://exam-labs.itpassleader.com/EC-COUNCIL/212-89-dumps-pass-exam.html

0
0
0
0