212-89 Exam Details

  • Exam Code
    :212-89
  • Exam Name
    :EC Council Certified Incident Handler (ECIH v3)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :232 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 212-89 Online Questions & Answers

  • Question 91:

    Which of the following is defined as the identification of the boundaries of an IT system along with the resources and information that constitute the system?

    A. System characterization
    B. Vulnerability identification
    C. Threat ioenLificalion
    D. Control analysis

  • Question 92:

    Rica works as an incident handler for an international company. As part of her role, she must review the present security policy implemented. Upon inspection, Rica finds that the policy is wide open, and only known dangerous services/attacks or behaviors are blocked. Which of the following is the current policy that Rica identified?

    A. Prudent policy
    B. Paranoic policy
    C. Permissive policy
    D. Promiscuous policy

  • Question 93:

    An organization faced an information security incident where a disgruntled employee passed sensitive access control information to a competitor. The organization's incident response manager, upon investigation, found that the incident must be handled within a few hours on the same day to maintain business continuity and market competitiveness. How would you categorize such information security incident?

    A. High level incident
    B. Middle level incident
    C. Ultra-High level incident
    D. Low level incident

  • Question 94:

    Francis received a spoof email asking for his bank information. He decided to use a tool to analyze the email headers. Which of the following should he use?

    A. EventLog Analyzer
    B. MxTooIbox
    C. Email Checker
    D. PoliteMail

  • Question 95:

    Except for some common roles, the roles in an IRT are distinct for every organization. Which among the following is the role played by the Incident Coordinator of an IRT?

    A. Links the appropriate technology to the incident to ensure that the foundation's offices are returned to normal operations as quickly as possible
    B. Links the groups that are affected by the incidents, such as legal, human resources, different business areas and management
    C. Applies the appropriate technology and tries to eradicate and recover from the incident
    D. Focuses on the incident and handles it from management and technical point of view

  • Question 96:

    A malicious, security-breaking program is disguised as a useful program. Such executable programs, which are installed when a file is opened, allow others to control a user's system. What is this type of program called?

    A. Trojan
    B. Worm
    C. Virus
    D. Spyware

  • Question 97:

    A computer virus hoax is a message warning the recipient of non-existent computer virus. The message is usually a chain e-mail that tells the recipient to forward it to every one they know. Which of the following is NOT a symptom of virus hoax message?

    A. The message prompts the end user to forward it to his / her e-mail contact list and gain monetary benefits in doing so
    B. The message from a known email id is caught by SPAM filters due to change of filter settings
    C. The message warns to delete certain files if the user does not take appropriate action
    D. The message prompts the user to install Anti-Virus

  • Question 98:

    Bob, an incident responder at CyberTech Solutions, is investigating a cybercrime attack occurred in the client company. He acquired the evidence data, preserved it, and started performing analysis on acquired evidentiary data to identify the source of the crime and the culprit behind the incident. Identify the forensic investigation phase in which Bob is currently in.

    A. Vulnerability assessment phase
    B. Post-investigation phase
    C. Pre-investigation phase
    D. Investigation phase

  • Question 99:

    Smith employs various malware detection techniques to thoroughly examine the network and its systems for suspicious and malicious malware files. Among all techniques, which one involves analyzing the memory dumps or binary codes for the traces of malware?

    A. Live system
    B. Dynamic analysis
    C. Intrusion analysis
    D. Static analysis

  • Question 100:

    To whom should an information security incident be reported?

    A. It should not be reported at all and it is better to resolve it internally
    B. Human resources and Legal Department
    C. It should be reported according to the incident reporting and handling policy
    D. Chief Information Security Officer

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 212-89 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.