212-89 Exam Details

  • Exam Code
    :212-89
  • Exam Name
    :EC Council Certified Incident Handler (ECIH v3)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :232 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 212-89 Online Questions & Answers

  • Question 111:

    Which of the following are malicious software programs that infect computers and corrupt or delete the data on them?

    A. Worms
    B. Trojans
    C. Spyware
    D. Virus

  • Question 112:

    Bonney's system has been compromised by a gruesome malware.

    What is the primary step that is advisable to Bonney in order to contain the malware incident from spreading?

    A. Turn off the infected machine
    B. Leave it to the network administrators to handle
    C. Complaint to police in a formal way regarding the incident
    D. Call the legal department in the organization and inform about the incident

  • Question 113:

    Which of the following terms refers to the personnel that the incident handling and response (IHandR) team must contact to report the incident and obtain the necessary permissions?

    A. Civil litigation
    B. Point of contact
    C. Criminal referral
    D. Ticketing

  • Question 114:

    An insider threat response plan helps an organization minimize the damage caused by malicious insiders. One of the approaches to mitigate these threats is setting up controls from the human resources department. Which of the following guidelines can the human resources department use?

    A. Access granted to users should be documented and vetted by a supervisor.
    B. Disable the default administrative account to ensure accountability.
    C. Implement a person-to-person rule to secure the backup process and physical media.
    D. Monitor and secure the organization's physical environment.

  • Question 115:

    Chandler is a professional hacker who is targeting Technote organization. He wants to obtain important organizational information that is being transmitted between different hierarchies. In the process, he is sniffing the data packets transmitted through the network and then analyzing them to gather packet details such as network, ports, protocols, devices, issues in network transmission, and other network specifications. Which of the following tools Chandler must employ to perform packet analysis?

    A. BeEf
    B. IDAPro
    C. Omnipeek
    D. shARP

  • Question 116:

    Based on the some statistics; what is the typical number one top incident?

    A. Phishing
    B. Policy violation
    C. Un-authorized access
    D. Malware

  • Question 117:

    Which of the following processes is referred to as an approach to respond to the security incidents that occurred in an organization and enables the response team by ensuring that they know exactly what process to follow in case of security incidents?

    A. Risk assessment
    B. Incident response orchestration
    C. Vulnerability management
    D. Threat assessment

  • Question 118:

    In which of the following types of insider threats an insider who is uneducated on potential security threats or simply bypasses general security procedures to meet workplace efficiency?

    A. Compromised insider
    B. Negligent insider
    C. Professional insider
    D. Malicious insider

  • Question 119:

    Michael is a part of the computer incident response team of a company. One of his responsibilities is to handle email incidents. The company receives an email from an unknown source, and one of the steps that he needs to take is to check the validity of the email. Which of the following tools should he use?

    A. Zendio
    B. Email Dossier
    C. Yesware
    D. G Suite Toolbox

  • Question 120:

    Which of the following tools helps incident responders effectively contain a potential cloud security incident and gather required forensic evidence?

    A. Alert Logic
    B. CloudPassage Quarantine
    C. Qualys Cloud Platform
    D. Cloud Passage Halo

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 212-89 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.