212-89 Exam Details

  • Exam Code
    :212-89
  • Exam Name
    :EC Council Certified Incident Handler (ECIH v3)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :232 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 212-89 Online Questions & Answers

  • Question 141:

    Which stage of the incident response and handling process involves auditing the system and network log files?

    A. Containment
    B. Incident triage
    C. Incident disclosure
    D. Incident eradication

  • Question 142:

    Matt is an incident handler working for one of the largest social network companies, which was affected by malware. According to the company's reporting timeframe guidelines, a malware incident should be reported within 1 h of discovery/detection after its spread across the company. Which category does this incident belong to?

    A. CAT 1
    B. CAT 4
    C. CAT 2
    D. CAT 3

  • Question 143:

    An organization's customers are experiencing either slower network communication or unavailability of services. In addition, network administrators are receiving alerts from security tools such as IDS/IPS and firewalls about a possible DoS/DDoS attack. In result, the organization requests the incident handling and response (IHandR) team further investigates the incident. The IHandR team decides to use manual techniques to detect DoS/DDoS attack. Which of the following commands helps the IHandR team to manually detect DoS/DDoS attack?

    A. netstat -r
    B. nbtstat /c
    C. netstat an
    D. nbtstat/S

  • Question 144:

    Farheen is an incident responder at reputed IT Firm based in Florida. Farheen was asked to investigate a recent cybercrime faced by the organization. As part of this process, she collected static data from a victim system. She used DD tool command to perform forensic duplication to obtain an NTFS image of the original disk. She created a sector-by-sector mirror imaging of the disk and saved the output image file as image.dd. Identify the static data collection process step performed by Farheen while collecting static data.

    A. Comparison
    B. Administrative consideration
    C. System preservation
    D. Physical presentatio

  • Question 145:

    Eric works as a system administrator in ABC organization. He granted privileged users with unlimited permissions to access the systems. These privileged users can misuse their rights unintentionally or maliciously or attackers can trick them to perform malicious activities. Which of the following guidelines helps incident handlers to eradicate insider attacks by privileged users?

    A. Do not use encryption methods to prevent administrators and privileged users from accessing backup tapes and sensitive information
    B. Do not control the access to administrators and privileged users
    C. Do not enable the default administrative accounts to ensure accountability
    D. Do not allow administrators to use unique accounts during the installation process

  • Question 146:

    A colleague wants to minimize their security responsibility because they are in a small organization. They are evaluating a new application that is offered in different forms. Which form would result in the least amount of responsibility for the colleague?

    A. On-prom installation
    B. saaS
    C. laaS
    D. PaaS

  • Question 147:

    XYZ Inc. was affected by a malware attack and James, being the incident handling and response (IHandR) team personnel handling the incident, found out that the root cause of the incident is a backdoor that has bypassed the security perimeter due to an existing vulnerability in the deployed firewall. James had contained the spread of the infection and removed the malware completely. Now the organization asked him to perform incident impact assessment to identify the impact of the incident over the organization and he was also asked to prepare a detailed report of the incident.

    Which of the following stages in IHandR process is James working on?

    A. Notification
    B. Evidence gathering and forensics analysis
    C. Post-incident activities
    D. Eradication

  • Question 148:

    Which one of the following is the correct flow of the stages in an incident handling and response (IHandR) process?

    A. Preparation -* Incident recording -> Incident triage -* Containment -*# Eradication -?Recovery -* Post-incident activities
    B. Containment -* Incident recording -* Incident triage -> Preparation -* Recovery -> Eradication -* Post-incident activities
    C. Incident recording -> Preparation -> Containment * Incident triage -> Recovery > Eradication -?Post- incident activities
    D. Incident triage -?Eradication -# Containment -* Incident recording -* Preparation -* Recovery -* Post-incident activities

  • Question 149:

    In which of the following phases of the incident handling and response (IHandR) process is the identified security incidents analyzed, validated, categorized, and prioritized?

    A. Incident triage
    B. Incident recording and assignment
    C. Containment
    D. Notification

  • Question 150:

    Which of the following email security tools can be used by an incident handler to prevent the organization against evolving email threats?

    A. Email Header Analyzer
    B. G Suite Toolbox
    C. MxToolbox
    D. Gpg4win

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 212-89 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.