Eccouncil

212-89 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 75-question bank.

Provider
Eccouncil
Question bank
75
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 212-89, a certification listed under Eccouncil. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Eccouncil. The certification credential is issued by Eccouncil, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which of the following terms may be defined as "a measure of possible inability to achieve a goal, objective, or target within a defined security, cost plan and technical limitations that adversely affects the organization's operation and revenues?

    Choose one answer.

    • Risk
    • Vulnerability
    • Threat
    • Incident Response
  2. Question 2 · 1

    Incident handling and response steps help you to detect, identify, respond and manage an incident. Which of the following steps focus on limiting the scope and extent of an incident?

    Choose one answer.

    • Eradication
    • Containment
    • Identification
    • Data collection
  3. Question 3 · 1

    A malware code that infects computer files, corrupts or deletes the data in them and requires a host file to propagate is called:

    Choose one answer.

    • Trojan
    • Worm
    • Virus
    • RootKit
  4. Question 4 · 1

    Identify the malicious program that is masked as a genuine harmless program and gives the attacker unrestricted access to the user's information and system. These programs may unleash dangerous programs that may erase the unsuspecting user's disk and send the victim's credit card numbers and passwords to a stranger.

    Choose one answer.

    • Cookie tracker
    • Worm
    • Trojan
    • Virus
  5. Question 5 · 1

    Which of the following is NOT one of the common techniques used to detect Insider threats:

    Choose one answer.

    • Spotting an increase in their performance
    • Observing employee tardiness and unexplained absenteeism
    • Observing employee sick leaves
    • Spotting conflicts with supervisors and coworkers
  6. Question 6 · 1

    Quantitative risk is the numerical determination of the probability of an adverse event and the extent of the losses due to the event. Quantitative risk is calculated as:

    Choose one answer.

    • (Probability of Loss) X (Loss)
    • (Loss) / (Probability of Loss)
    • (Probability of Loss) / (Loss)
    • Significant Risks X Probability of Loss X Loss
  7. Question 7 · 1

    Which of the following is NOT one of the techniques used to respond to insider threats:

    Choose one answer.

    • Placing malicious users in quarantine network, so that attack cannot be spread
    • Preventing malicious users from accessing unclassified information
    • Disabling the computer systems from network connection
    • Blocking malicious user accounts
  8. Question 8 · 1

    Insiders may be:

    Choose one answer.

    • Ignorant employees
    • Carless administrators
    • Disgruntled staff members
    • All the above
  9. Question 9 · 1

    An incident recovery plan is a statement of actions that should be taken before, during or after an incident. Identify which of the following is NOT an objective of the incident recovery plan?

    Choose one answer.

    • Creating new business processes to maintain profitability after incident
    • Providing a standard for testing the recovery plan
    • Avoiding the legal liabilities arising due to incident
    • Providing assurance that systems are reliable
  10. Question 10 · 1

    The Linux command used to make binary copies of computer media and as a disk imaging tool if given a raw disk device as its input is:

    Choose one answer.

    • "dd" command
    • "netstat" command
    • "nslookup" command
    • "find" command
  11. Question 11 · 1

    To recover, analyze, and preserve computer and related materials in such a way that it can be presented as evidence in a court of law and identify the evidence in short time, estimate the potential impact of the malicious activity on the victim, and assess the intent and identity of the perpetrator is known as:

    Choose one answer.

    • Computer Forensics
    • Digital Forensic Analysis
    • Forensic Readiness
    • Digital Forensic Examiner
  12. Question 12 · 1

    Risk is defined as the probability of the occurrence of an incident. Risk formulation generally begins with the likeliness of an event's occurrence, the harm it may cause and is usually denoted as Risk = ∑(events)X(Probability of occurrence)X?

    Choose one answer.

    • Magnitude
    • Probability
    • Consequences
    • Significance
  13. Question 13 · 1

    The person who offers his formal opinion as a testimony about a computer crime incident in the court of law is known as:

    Choose one answer.

    • Expert Witness
    • Incident Analyzer
    • Incident Responder
    • Evidence Documenter
  14. Question 14 · 1

    An audit trail policy collects all audit trails such as series of records of computer events, about an operating system, application or user activities. Which of the following statements is NOT true for an audit trail policy:

    Choose one answer.

    • It helps calculating intangible losses to the organization due to incident
    • It helps tracking individual actions and allows users to be personally accountable for their actions
    • It helps in compliance to various regulatory laws, rules,and guidelines
    • It helps in reconstructing the events after a problem has occurred
  15. Question 15 · 1

    The ability of an agency to continue to function even after a disastrous event, accomplished through the deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy is known as:

    Choose one answer.

    • Business Continuity Plan
    • Business Continuity
    • Disaster Planning
    • Contingency Planning

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free