Cert Prep: EC-Council Certified Incident Handler (ECIH) v2 (212-89)
19h 34mIntermediate2022-04-13
Authors

ACI Learning
Addressing the Global IT Skills Gap
Course details
This course from ITProTV takes an in-depth look at the skills and knowledge you need to become a successful incident handler and response team member, with an eye on taking and passing the EC-Council's Certified Incident Handler v2 (ECIH) exam. ITProTV instructors Daniel Lowrie and Adam Gordon discuss the basic skills needed to handle and respond to security events and address various underlying principles and techniques for detecting and responding to current and emerging computer security threats. The incident handling skills taught in E|CIH are useful for a wide array of cybersecurity jobs and tasks, like penetration testing, vulnerability assessment, risk assessment, network administrators, cyber forensic investigators, and more.
Skills covered
Incident ResponseCybersecurityCert Prep
Concepts
0. Introduction
- 01 - Overview
- 02 - ECIH v2 EC-Council certification overview
1. Incident Handling and Response Process
- 03 - Information security and incident management
- 04 - What is vulnerability management
- 05 - What are threat assessments
- 06 - Risk management - Vocabulary
- 07 - Risk management - The process
- 08 - Risk management - The NIST RMF
- 09 - Incident handling best practices, standards, and frameworks
- 10 - Incident handling and legal compliance
2. Forensic Readiness and First Response
- 11 - Step one - Prepare for incident handling and response
- 12 - Step two - Incident recording and assignment
- 13 - Step three - Incident triage
- 14 - Step four - Notification
- 15 - Step five - Containment
- 16 - Step six - Evidence gathering and forensic analysis
- 17 - Step seven - Eradication
- 18 - Step eight - Recovery
- 19 - Step nine - Postincident activities
3. Handling and Responding to Malware Incidents
- 20 - Forensics and first response
- 21 - Principles of digital evidence collection
- 22 - Data acquisition
- 23 - Volatile evidence collection
- 24 - Static evidence collection and anti-forensics
4. Handling and Responding to Email Security Incidents
- 25 - Preparation for handling malware incidents
- 26 - Detection of malware incidents
- 27 - Containment of malware incidents
- 28 - Eradication of malware incidents
- 29 - Recovery after malware incidents
5. Handling and Responding to Network Security Incidents
- 30 - Handling email security incidents
6. Handling and Responding to Web Application Security Incidents
- 31 - Preparation handling network security incidents
- 32 - Detection and validation of network security incidents
- 33 - Handling unauthorized access incidents
- 34 - Handling inappropriate usage incidents
- 35 - Handling denial-of-service incidents
- 36 - Handling wireless network security incidents
7. Handling and Responding to Cloud Security Incidents
- 37 - Preparation to handle web app security incidents
- 38 - Detecting and analyzing web app security incidents
- 39 - Containment of web app security incidents
- 40 - Eradication of web app security incidents
- 41 - Recovery from web app security incidents
- 42 - Web app security threats and attacks
8. Handling and Responding to Insider Threats
- 43 - Cloud computing concepts
- 44 - Best practices against cloud security incidents
9. Hands-On with ECIH Tools
- 45 - Best practices against insider threats
Conclusion
- 46 - Security checks using buck-security in Linux
- 47 - Volatile evidence collection in Linux and Windows
- 48 - Using OSForensics to find hidden material
- 49 - Analyzing nonvolatile data using the Autopsy tool
- 50 - Malware analysis
- 51 - Collecting information by tracing emails
- 52 - Using OSSIM
- 53 - Using Wireshark and Nmap
- 54 - Using Suricata IDS
- 55 - What does a SQL injection attack look like
- 56 - What does a XSS attack look like
Related courses
- Ethical Hacking: Scanning Networks
- Ethical Hacking: Cryptography (2019)
- Ethical Hacking: Scanning Networks (2016)
- Ethical Hacking: Mobile Devices and Platforms
- Computer Hacking Forensics Investigator (CHFI) Cert Prep
- Ethical Hacking: Footprinting and Reconnaissance (2016)
- CompTIA A+ Core 2 (220-1102) Cert Prep: 1 Getting Started
- Power BI Data Analyst Associate (PL-300) Cert Prep: Connecting to Power BI Data
Related learn paths
- Prepare for Unity Certification
- Become a Certified CAD Designer with SOLIDWORKS
- Prepare for the Linux Professional Institute LPIC-1 (101-500 and 102-500) Exams
- Prepare for the Certified in Risk and Information Systems Control (CRISC) Certification Exam (2021)
- Prepare for the CSA Certificate of Cloud Security Knowledge (CCSK) Exam
- Prepare for the ISC2 Systems Security Certified Practitioner (SSCP) Exam
- Prepare for the Certified Information Systems Auditor (CISA) Exam
- Prepare for the AWS Certified Cloud Practitioner (CLF-C01) Certification Exam