Courseiva

CEH Initial Infection Vector Practice Question

You are a security analyst for a financial institution. The company has deployed a network of 500 Windows 10 workstations and 50 servers running Windows Server 2019. All systems are protected by a next-generation firewall and an endpoint detection and response (EDR) solution. Recently, several employees reported that their workstations are running slowly and exhibiting unusual pop-up messages demanding a ransom note in Bitcoin. The EDR alerts show that a file named 'invoice.docm' was downloaded from an email attachment and executed on multiple workstations. The EDR also indicates that the file dropped a PowerShell script that connected to an external IP address and downloaded additional payloads. After the initial infection, the EDR detected that the ransomware binary 'encryptor.exe' was executed, which began encrypting files. However, the encryption process was stopped by the EDR before all files were encrypted. The incident response team needs to determine the source of the infection and prevent future occurrences. Which of the following is the most effective first step to identify the initial infection vector?

⚠ Common exam trap

EC-Council often tests the distinction between identification steps and containment/remediation steps. The trap is that candidates choose a preventive measure (like enabling macro security or blocking IPs) instead of a forensic step (like reviewing email logs) to identify the root cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reimage all affected workstations to remove the ransomware and then review email logs for the original phishing email.

The question asks for the most effective first step to identify the initial infection vector, and the only identification-oriented action among the choices is reviewing email logs to trace the original phishing email. The scenario already indicates that invoice.docm was delivered by email, so email logs and mail gateway/EDR telemetry are the proper forensic sources to identify sender, recipients, and delivery scope. Although option A includes reimaging, that is a remediation action and should not be performed before evidence collection; however, the key identification step is the email log review. Option C is preventive hardening and does not identify how the current infection started. Option B is containment, and option D is overly broad prevention that breaks legitimate automation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reimage all affected workstations to remove the ransomware and then review email logs for the original phishing email.

    Why this is correct

    Correct: reviewing email logs is the only identification-oriented action and traces the original phishing email. Reimaging is remediation and should occur only after evidence is preserved.

  • ✗

    Block the external IP address at the firewall to prevent further communication with the C2 server.

    Why it's wrong here

    Blocking the external IP is containment; it does not identify the initial infection vector and can be bypassed by changing infrastructure.

  • ✗

    Enable macro security settings in Microsoft Office to block macros from running without explicit user consent, and enforce via Group Policy.

    Why it's wrong here

    Enabling macro security is a preventive hardening measure that reduces future risk but does not identify how this infection started.

  • ✗

    Disable PowerShell across all workstations via Group Policy to prevent script execution.

    Why it's wrong here

    Disabling PowerShell is an overly broad preventive measure that would break legitimate automation and does not identify the initial infection vector.

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.