Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 712-50 All Questions

View all questions & answers for the 712-50 exam

Exam 712-50 topic 1 question 261 discussion

Actual exam question from ECCouncil's 712-50
Question #: 261
Topic #: 1
[All 712-50 Questions]

Your incident handling manager detects a virus attack in the network of your company. You develop a signature based on the characteristics of the detected virus.
Which of the following phases in the incident handling process will utilize the signature to resolve this incident?

  • A. Eradication
  • B. Containment
  • C. Recovery
  • D. Identification
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
alfaMegatron
3 months, 2 weeks ago
Selected Answer: A
Virus has already been identified. so, it should be A.
upvoted 1 times
...
johndoe69
5 months, 3 weeks ago
Selected Answer: A
Reference: NIST Special Publication 800-61 Revision 2: According to NIST, the eradication phase involves eliminating the components of the incident, such as deleting malware or disabling breached user accounts. Developing and using a signature based on the characteristics of the detected virus is a key part of this phase, as it helps identify and remove the virus from affected systems (NIST, 2012). SANS Institute Incident Handling Step-by-Step: The SANS Institute also outlines that during the eradication phase, signatures and other detection tools are used to ensure that all instances of the threat are identified and removed from the network (SANS, 2019).
upvoted 1 times
...
Perseus_68
8 months, 3 weeks ago
Selected Answer: A
There is no Identification phase in IR under NIST, Prep, detection and analysis, Containment, eradication and recovery, and post. Eradication involves using AV tools or manual removal techniques. And, the virus has already been identified.
upvoted 2 times
...
musagul
9 months ago
Selected Answer: D
I think the correct answer is Indetification. If the answer is A, can someone tell me according to what, identification of suspicious is going to be done? Of course to signature...
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...