Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

ECCouncil EC Council Certified Incident Handler (ECIH v3) 212-89 Question # 102 Topic 11 Discussion

ECCouncil EC Council Certified Incident Handler (ECIH v3) 212-89 Question # 102 Topic 11 Discussion

212-89 Exam Topic 11 Question 102 Discussion:
Question #: 102
Topic #: 11

A global logistics company recently experienced a targeted ransomware attack that began through a deceptive email campaign. The malicious software encrypted critical files on several systems tied to dispatch and finance operations. Fortunately, the organization had deployed an advanced security setup that could swiftly recognize abnormal behaviors, isolate compromised devices, and alert both the technical support desk and the security operations team.

In parallel, system logs were captured and analyzed using integrated threat detection tools, and a detailed file was automatically created with relevant data such as affected assets, user activity, and potential entry points. Security analysts then assessed the case, adapted containment measures based on the affected departments, and continued tracking suspicious activity across the network. Additional countermeasures were executed based on a mix of pre-approved workflows and expert decisions, ensuring the issue was contained without major disruption. Which combination of technologies is MOST likely supporting this workflow?


A.

A manual log management tool integrated with a physical ticketing desk for report creation


B.

A legacy antivirus solution configured to detect known malware only


C.

A cloud storage backup system with no direct link to detection or containment mechanisms


D.

A coordinated system combining incident response automation with orchestration capabilities


Get Premium 212-89 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.