Free 212-89 Exam Braindumps (page: 10)

Page 10 of 41

Organizations or incident response teams need to protect the evidence for any future legal actions that may be taken against perpetrators that intentionally attacked the computer system. EVIDENCE PROTECTION is also required to meet legal compliance issues. Which of the following documents helps in protecting evidence from physical or logical damage?

  1. Network and host log records
  2. Chain-of-Custody
  3. Forensic analysis report
  4. Chain-of-Precedence

Answer(s): B



Except for some common roles, the roles in an IRT are distinct for every organization. Which among the following is the role played by the Incident Coordinator of an IRT?

  1. Links the appropriate technology to the incident to ensure that the foundation’s offices are returned to normal operations as quickly as possible
  2. Links the groups that are affected by the incidents, such as legal, human resources, different business areas and management
  3. Applies the appropriate technology and tries to eradicate and recover from the incident
  4. Focuses on the incident and handles it from management and technical point of view

Answer(s): B



The data on the affected system must be backed up so that it can be retrieved if it is damaged during incident response. The system backup can also be used for further investigations of the incident. Identify the stage of the incident response and handling process in which complete backup of the infected system is carried out?

  1. Containment
  2. Eradication
  3. Incident recording
  4. Incident investigation

Answer(s): A



In a qualitative risk analysis, risk is calculated in terms of:

  1. (Attack Success + Criticality ) –(Countermeasures)
  2. Asset criticality assessment – (Risks and Associated Risk Levels)
  3. Probability of Loss X Loss
  4. (Countermeasures + Magnitude of Impact) – (Reports from prior risk assessments)

Answer(s): C



Page 10 of 41



Post your Comments and Discuss EC-Council 212-89 exam with other Community members:

Rohit commented on March 22, 2024
Pass the exam. I am officially certified now. Great questions.
INDIA
upvote

manisha commented on March 22, 2024
for exam practise
INDIA
upvote

Priscila commented on July 22, 2022
i find the xengine test engine simulator to be more fun than reading from pdf.
GERMANY
upvote

Fadil commented on August 08, 2023
It is very good
Anonymous
upvote

Priscila commented on July 22, 2022
I find the Xengine Test Engine Simulator to be more fun than reading from PDF.
GERMANY
upvote

Muhammed Hosain commented on May 31, 2021
I just pass my exam a 907 makr. Thank you team.
INDIA
upvote