212-89 Exam Details

  • Exam Code
    :212-89
  • Exam Name
    :EC Council Certified Incident Handler (ECIH v3)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :232 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 212-89 Online Questions & Answers

  • Question 101:

    An incident responder captures network traffic in real time without sending packets to the target systems. Which assessment approach is being used?

    A. Active assessment
    B. External assessment
    C. Passive assessment
    D. Internal assessment

  • Question 102:

    Which of the following is a term that describes the combination of strategies and services intended to restore data, applications, and other resources to the public cloud or dedicated service providers?

    A. Mitigation
    B. Analysis
    C. Eradication
    D. Cloud recovery

  • Question 103:

    According to NITS, what are the 5 main actors in cloud computing?

    A. Provider, carrier, auditor, broker, and seller
    B. Consumer, provider, carrier, auditor, ano broker
    C. Buyer, consumer, carrier, auditor, and broker
    D. None of these

  • Question 104:

    Your company sells SaaS, and your company itself is hosted in the cloud (using it as a PaaS). In case of a malware incident in your customer's database, who is responsible for eradicating the malicious software?

    A. Your company
    B. Building management
    C. The PaaS provider
    D. The customer

  • Question 105:

    An attacker traced out and found the kind of websites a target company/individual is frequently surfing and tested those particular websites to identify any possible vulnerabilities. When the attacker detected vulnerabilities in the website, the attacker started injecting malicious script/code into the web application that can redirect the webpage and download the malware onto the victim's machine. After infecting the vulnerable web application, the attacker waited for the victim to access the infected web application.

    Identify the type of attack performed by the attacker.

    A. Watering hole
    B. Obfuscation application
    C. Directory traversal
    D. Cookie/Session poisoning

  • Question 106:

    Alice is a disgruntled employee. She decided to acquire critical information from her organization for financial benefit. To acccomplish this, Alice started running a virtual machine on the same physical host as her victim's virtual machine and took advantage of shared physical resources (processor cache) to steal data (cryptographic key/plain text secrets) from the victim machine. Identify the type of attack Alice is performing in the above scenario.

    A. Side channel attack
    B. Service hijacking
    C. SQL injection attack
    D. Man-in-the-cloud attack

  • Question 107:

    In which of the following stages of incident handling and response (IHandR) process do the incident handlers try to find out the root cause of the incident along with the threat actors behind the incidents, threat vectors, etc.?

    A. Post-incident activities
    B. Incident triage
    C. Evidence gathering and forensics analysis
    D. Incident recording and assignment

  • Question 108:

    Which of the following is a characteristic of adware?

    A. Gathering information
    B. Displaying popups
    C. Intimidating users
    D. Replicating

  • Question 109:

    Alice is an incident handler and she has been informed by her lead that the data on affected systems must be backed up so that it can be retrieved if it is damaged during the incident response process. She was also told that the system backup can also be used for further investigation of the incident. In which of the following stages of the incident handling and response (IHandR) process does Alice need to do a complete backup of the infected system?

    A. Containment
    B. Incident recording
    C. Incident triage
    D. Eradication

  • Question 110:

    Which log source is MOST useful for identifying repeated failed login attempts across multiple systems?

    A. Application logs
    B. Network traffic captures
    C. Authentication logs
    D. Database transaction logs

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 212-89 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.