WorksheetsECIH Preparation
Total questions: 12
Worksheet time: 12mins
Which of the following terms may be defined as “a measure of possible inability to achieve a goal,
objective, or target within a defined security, cost plan and technical limitations that adversely
affects the organization’s operation and revenues?
Incident Respons
Threat
Vulnerability
Risk
A distributed Denial of Service (DDoS) attack is a more common type of DoS Attack, where a single
system is targeted by a large number of infected machines over the Internet. In a DDoS attack,
attackers first infect multiple systems which are known as:
Trojan
Zombies
Spyware
Worms
The goal of incident response is to handle the incident in a way that minimizes damage and reduces
recovery time and cost. Which of the following does NOT constitute a goal of incident response?
Dealing properly with legal issues that may arise during incidents
Helping personal to recover quickly and efficiently from security incidents, minimizing loss or theft
and disruption of services
Using information gathered during incident handling to prepare for handling future incidents in a
better way and to provide stronger protection for systems and data
Dealing with human resources department and various employee conflict behaviors
An organization faced an information security incident where a disgruntled employee passed
sensitive access control information to a competitor. The organization’s incident response manager,
upon investigation, found that the incident must be handled within a few hours on the same day to
maintain business continuity and market competitiveness. How would you categorize such
information security incident?
Middle level incident
Low level incident
High level incident
Ultra-High level incident
Business continuity is defined as the ability of an organization to continue to function even after a
disastrous event, accomplished through the deployment of redundant hardware and software, the
use of fault tolerant systems, as well as a solid backup and recovery strategy. Identify the plan which
is mandatory part of a business continuity plan?
Sales and Marketing plan
Forensics Procedure Plan
Business Recovery Plan
New business strategy plan
Which of the following is an appropriate flow of the incident recovery steps?
System Operation-System Restoration-System Validation-System Monitoring
System Restoration-System Monitoring-System Validation-System Operations
System Restoration-System Validation-System Operations-System Monitoring
System Validation-System Operation-System Restoration-System Monitoring
A computer Risk Policy is a set of ideas to be implemented to overcome the risk associated with
computer security incidents. Identify the procedure that is NOT part of the computer risk policy?
Procedure for the ongoing training of employees authorized to access the system
Procedure to identify security funds to hedge risk
Procedure to monitor the efficiency of security controls
Provisions for continuing support if there is an interruption in the system or if the system crashes
Identify the network security incident where intended authorized users are prevented from using
system, network, or applications by flooding the network with high volume of traffic that consumes
all existing network resources.
URL Manipulation
XSS Attack
Denial of Service Attack
SQL Injection
Incident handling and response steps help you to detect, identify, respond and manage an incident.
Which of the following steps focus on limiting the scope and extent of an incident?
Eradication
Identification
Data collection
Containment
Policies are designed to protect the organizational resources on the network by establishingthe set rules and procedures. Which of the following policies authorizes a group of users to perform aset of actions on a set of resources
Documentation policy
Access control policy
Logging policy
Audit trail policy
The data on the affected system must be backed up so that it can be retrieved if it is damagedduring incident response. The system backup can also be used for further investigations of theincident. Identify the stage of the incident response and handling process in which complete backupof the infected system is carried out
Eradication
Incident recording
Incident investigation
Containment
The role that applies appropriate technology and tries to eradicate and recover from theincident is known as
Incident coordinator
Incident Handler
Incident Analyst
Incident Manager
