212-89 Exam Details

  • Exam Code
    :212-89
  • Exam Name
    :EC Council Certified Incident Handler (ECIH v3)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :232 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 212-89 Online Questions & Answers

  • Question 151:

    Which of the following terms refers to an organization's ability to make optimal use of digital evidence in a limited period of time and with minimal investigation costs?

    A. Threat assessment
    B. Data analysis
    C. Risk assessment
    D. Forensic readiness

  • Question 152:

    Alexis is working as an incident responder in XYZ organization. She was asked to identify and attribute the actors behind an attack that took place recently. In order to do so, she is performing threat attribution that deals with the identification of the specific person, society, or a country sponsoring a well-planned and executed intrusion or attack over its target. Which of the following types of threat attributions Alexis performed?

    A. Nation-state attribution
    B. Intrusion-set attribution
    C. True attribution
    D. Campaign attributio

  • Question 153:

    Bit stream image copy of the digital evidence must be performed in order to:

    A. Prevent alteration to the original disk
    B. Copy the FAT table
    C. Copy all disk sectors including slack space
    D. All the above

  • Question 154:

    Spyware tool used to record malicious user's computer activities and keyboard stokes is called:

    A. adware
    B. Keylogger
    C. Rootkit
    D. Firewall

  • Question 155:

    Sam. an employee of a multinational company, sends emails to third-party organizations with a spoofed email address of his organization. How can you categorize this type of incident?

    A. Network intrusion incident
    B. Inappropriate usage incident
    C. Unauthorized access incident.
    D. Denial-of-service incicent

  • Question 156:

    Zaimasoft, a prominent IT organization, was attacked by perpetrators who directly targeted the hardware and caused irreversible damage to the hardware. In result, replacing or reinstalling the hardware was the only solution. Identify the type of denial-of-service attack performed on Zaimasoft.

    A. ddos
    B. DoS
    C. PDoS
    D. DRDoS

  • Question 157:

    For analyzing the system, the browser data can be used to access various credentials.

    Which of the following tools is used to analyze the history data files in Microsoft Edge browser?

    A. ChromeHistoryView
    B. BrowsingHistoryView
    C. MZCacheView
    D. MZHistoryView

  • Question 158:

    Otis is an incident handler working in Delmont organization. Recently, the organization is facing several setbacks in the business and thereby its revenues are going down. Otis was asked to take the charge and look into the matter. While auditing the enterprise security, he found the traces of an attack, where the proprietary information was stolen from the enterprise network and was passed onto the competitors. Which of the following information security incidents Delmont organization faced?

    A. Network and resource abuses
    B. Unauthorized access
    C. Espionage
    D. Email-based abuse

  • Question 159:

    Raven is a part of an IHandR team and was informed by her manager to handle and lead the removal of the root cause for an incident and to close all attack vectors to prevent similar incidents in the future. Raven notifies the service providers and developers of affected resources. Which of the following steps of the incident handling and response process does Raven need to implement to remove the root cause of the incident?

    A. Evidence gathering and forensic analysis
    B. Eracicotion
    C. Containment
    D. Incident triage

  • Question 160:

    Which characteristic of digital evidence ensures that the evidence is complete and includes all relevant data related to the incident?

    A. Authenticity
    B. Reliability
    C. Completeness
    D. Admissibility

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 212-89 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.