212-89 Exam Details

  • Exam Code
    :212-89
  • Exam Name
    :EC Council Certified Incident Handler (ECIH v3)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :232 Q&As
  • Last Updated
    :May 26, 2026

EC-COUNCIL 212-89 Online Questions & Answers

  • Question 161:

    A Host is infected by worms that propagates through a vulnerable service; the sign(s) of the presence of the worm include:

    A. Decrease in network usage
    B. Established connection attempts targeted at the vulnerable services
    C. System becomes instable or crashes
    D. All the above

  • Question 162:

    Which of the following is an attack that occurs when a malicious program causes a user's browser to perform an unwanted action on a trusted site for which the user is currently authenticated?

    A. Cross-site scripting
    B. Insecure direct object references
    C. Cross-site request forgery
    D. SQL injection

  • Question 163:

    Shiela is working at night as an incident handler. During a shift, servers were affected by a massive cyberattack. After she classified and prioritized the incident, she must report the incident, obtain necessary permissions, and perform other incident response functions. What list should she check to notify other responsible personnel?

    A. HR log book
    B. Point of contact
    C. Email list
    D. Phone number list

  • Question 164:

    Which of the following is the ECIH phase that involves removing or eliminating the root cause of an incident and closing all attack vectors to prevent similar incidents in the future?

    A. Recovery
    B. Containment
    C. Eradication
    D. Vulnerability management phase

  • Question 165:

    Which of the following information security personnel handles incidents from management and technical point of view?

    A. Network administrators
    B. Incident manager (IM)
    C. Threat researchers
    D. Forensic investigators

  • Question 166:

    Tibson works as an incident responder for MNC based in Singapore. He is investigating a web application security incident recently faced by the company. The attack is performed on a MS SQL Server hosted by the company. In the detection and analysis phase, he used regular expressions to analyze and detect SQL meta-characters that led to SQL injection attack. Identify the regular expression used by Tibson to detect SQL injection attack on MS SQL Server.

    A. /exec(\s|\+)+(s|x)p\w+/ix
    B. ((\.\.\\)|(\.\.\/))
    C. ((\.|%2E)(\.|%2E)(\/|%2F|\\|%5C))
    D. ((\%3C)|)

  • Question 167:

    Dan is a newly appointed information security professional in a renowned organization. He is supposed to follow multiple security strategies to eradicate malware incidents. Which of the following is not considered as a good practice for maintaining information security and eradicating malware incidents?

    A. Do not download or execute applications from third-party sources
    B. Do not click on web browser pop-up windows
    C. Do not open files with file extensions such as .bat, .com, ,exe, .pif, .vbs, and so on
    D. Do not download or execute applications from trusted sources

  • Question 168:

    Sam received an alert through an email monitoring tool indicating that their company was targeted by a phishing attack. After analyzing the incident, Sam identified that most of the targets of the attack are high- profile executives of the company. What type of phishing attack is this?

    A. Pharming
    B. Whaling
    C. Puddle phishing
    D. Spear phishing

  • Question 169:

    Rose is an incident-handling person and she is responsible for detecting and eliminating any kind of scanning attempts over the network by any malicious threat actors. Rose uses Wireshark tool to sniff the network and detect any malicious activities going on. Which of the following Wireshark filters can be used by her to detect TCP Xmas scan attempt by the attacker?

    A. tcp.dstport==7
    B. tcp.flags==0X000
    C. tcp.flags.reset==1
    D. tcp.flags==0X029

  • Question 170:

    A payroll system has a vulnerability that cannot be exploited by current technology. Which of the following is correct about this scenario:

    A. The risk must be urgently mitigated
    B. The risk must be transferred immediately
    C. The risk is not present at this time
    D. The risk is accepted

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 212-89 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.