212-89 Exam Details

  • Exam Code
    :212-89
  • Exam Name
    :EC Council Certified Incident Handler (ECIH v3)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :232 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 212-89 Online Questions & Answers

  • Question 131:

    Which of the following is NOT part of the static data collection process?

    A. Evidence oxa mi nation
    B. System preservation
    C. Password protection
    D. Evidence acquisition

  • Question 132:

    Mr. Smith is a lead incident responder of a small financial enterprise having few branches in Australia. Recently, the company suffered a massive attack losing USD 5 million through an inter-banking system. After in-depth investigation on the case, it was found out that the incident occurred because 6 months ago the attackers penetrated the network through a minor vulnerability and maintained the access without any user being aware of it. Then, he tried to delete users' fingerprints and performed a lateral movement to the computer of a person with privileges in the inter-banking system.

    Finally, the attacker gained access and did fraudulent transactions. Based on the above scenario, identify the most accurate kind of attack.

    A. Ransomware attack
    B. Denial-of-service attack
    C. APT attack
    D. Phishing

  • Question 133:

    Which of the following is not a countermeasure to eradicate inappropriate usage incidents?

    A. Avoid VPN and other secure network channels
    B. Register the user activity logs and keep monitoring them regularly
    C. Install firewall and IDS/IPS to block services that violate the organization's policy
    D. Always store the sensitive data in far located servers and restrict its access

  • Question 134:

    Adam is an attacker who along with his team launched multiple attacks on target organization for financial benefits. Worried about getting caught, he decided to forge his identity. To do so, he created a new identity by obtaining information from different victims. Identify the type of identity theft Adam has performed.

    A. Medical identity theft
    B. Tax identity theft
    C. Synthetic identity theft
    D. Social identity theft

  • Question 135:

    Clark is investigating a cybercrime at TechSoft Solutions. While investigating the case, he needs to collect volatile information such as running services, their process IDs, startmode, state, and status. Which of the following commands will help Clark to collect such information from running services?

    A. Openfiles
    B. netstat b
    C. wmic
    D. net file

  • Question 136:

    Which of the following is an attack that attempts to prevent the use of systems, networks, or applications by the intended users?

    A. Denial of service (DoS) attack
    B. Fraud and theft
    C. Unauthorized access
    D. Malicious code or insider threat attack

  • Question 137:

    An attack on a network is BEST blocked using which of the following?

    A. IPS device inline
    B. HIPS
    C. Web proxy
    D. Load balancer

  • Question 138:

    The very well-known free open source port, OS and service scanner and network discovery utility is called:

    A. Wireshark
    B. Nmap (Network Mapper)
    C. Snort
    D. SAINT

  • Question 139:

    During the vulnerability assessment phase, the incident responders perform various steps as below:

    1.

    Run vulnerability scans using tools

    2.

    Identify and prioritize vulnerabilities

    3.

    Examine and evaluate physical security

    4.

    Perform OSINT information gathering to validate the vulnerabilities

    5.

    Apply business and technology context to scanner results

    6.

    Check for misconfigurations and human errors

    7.

    Create a vulnerability scan report

    Identify the correct sequence of vulnerability assessment steps performed by the incident responders.

    A. 3-->6-->1-->2-->5-->4-->7
    B. 1-->3-->2-->4-->5-->6-->7
    C. 4-->1-->2-->3-->6-->5-->7
    D. 2-->1-->4-->7-->5-->6-->3

  • Question 140:

    Investigator Ian gives you a drive image to investigate. What type of analysis are you performing?

    A. Real-time
    B. Static
    C. Dynamic
    D. Live

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 212-89 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.