212-89 Sample Questions & Answers
Working through the incident handling and response workflow, malware incidents, and network attacks such as denial-of-service share the heaviest weighting, alongside first response and evidence gathering, and email, web, cloud, and endpoint cases.
Launch the full 212-89 simulator →Free 212-89 Sample Questions with Answers
Real questions from the Certified Incident Handler (ECIH) practice test — answers and explanations included. Showing 20 of 40 free samples.
- Question 1
An incident is analyzed for its nature, intensity and its effects on the network and systems. Which stage of the incident response and handling process involves auditing the system and network log files?
Show answer & explanation
Correct answer: D
The Identification stage of incident response involves analyzing incidents for their nature, intensity, and effects, which includes auditing system and network log files to understand what occurred. This stage focuses on determining whether a security event is actually an incident requiring response. Incident recording documents the incident, reporting communicates findings, and containment focuses on limiting the incident spread rather than initial analysis.
- Question 2
Incident Response Plan requires
Show answer & explanation
Correct answer: D
Incident Response Plans require all of the above components: financial and management support for resources and authority, expert team composition with skilled personnel from various disciplines, and adequate resources including technology, tools, and budget. A comprehensive incident response plan cannot be effective without any of these critical elements, as each component is essential for successful incident handling and organizational preparedness.
- Question 3
A software application in which advertising banners are displayed while the program is running that delivers ads to display pop-up windows or bars that appears on a computer screen or browser is called:
Show answer & explanation
Correct answer: A
Adware is software that displays advertising banners while running and delivers ads through pop-up windows or bars on computer screens or browsers, often generating revenue for developers through ad display. Unlike malicious malware, adware primarily focuses on advertising rather than system damage. Trojans disguise malicious functionality, rootkits hide system presence, viruses self-replicate and infect files, and worms spread across networks, none of which primarily focus on advertising display.
- Question 4
According to the Evidence Preservation policy, a forensic investigator should make at least................image copies of the digital evidence.
Show answer & explanation
Correct answer: B
According to Evidence Preservation policy, a forensic investigator should make at least two image copies of digital evidence to ensure data integrity and provide backup protection against corruption or damage during analysis. One copy serves as a working copy for examination while the other remains pristine for verification and legal presentation. Single copies risk evidence loss, while three or more copies may be excessive for most investigations, but two copies specifically provide the minimum redundancy needed for proper evidence preservation and chain of custody maintenance.
- Question 5
The most common type(s) of intellectual property is(are):
Show answer & explanation
Correct answer: D
The most common types of intellectual property include all the mentioned forms: copyrights protecting creative works, trademarks protecting brand identifiers, patents protecting inventions, and trade secrets protecting confidential business information. Each type provides different legal protections for intangible assets. Since intellectual property encompasses multiple categories of legal protection for different types of creative and business assets, all the above represents the complete range of common intellectual property types that organizations must protect.
- Question 6
Business continuity is defined as the ability of an organization to continue to function even after a disastrous event, accomplished through the deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy. Identify the plan which is mandatory part of a business continuity plan?
Show answer & explanation
Correct answer: B
Business Recovery Plan is the comprehensive strategy that enables organizations to continue functioning after disastrous events through redundant hardware/software, fault-tolerant systems, and robust backup procedures. This plan specifically focuses on operational continuity and system restoration. While disaster recovery plans address immediate response, business impact analysis evaluates potential losses, and contingency plans provide alternative procedures, the Business Recovery Plan encompasses the full spectrum of organizational continuity measures.
- Question 7
Agencies do NOT report an information security incident is because of:
Show answer & explanation
Correct answer: A
Organizations often fail to report information security incidents primarily due to fear of negative publicity, which could damage their reputation, customer trust, and stock value. This concern about public perception frequently outweighs the benefits of incident reporting and information sharing. While costs, legal concerns, and technical challenges may be factors, the fear of reputational damage remains the predominant reason organizations avoid incident disclosure.
- Question 8
Which among the following CERTs is an Internet provider to higher education institutions and various other research institutions in the Netherlands and deals with all cases related to computer security incidents in which a customer is involved either as a victim or as a suspect?
Show answer & explanation
Correct answer: D
SURFnet-CERT is the Computer Emergency Response Team that serves as an Internet provider to higher education institutions and research institutions in the Netherlands, handling all computer security incidents involving their customers. This specialized CERT focuses on the academic and research community. Other CERTs serve different constituencies: CERT/CC coordinates global incident response, AusCERT serves Australia, and JPCERT serves Japan, but none specifically focus on Dutch higher education institutions.
- Question 9
Which of the following service(s) is provided by the CSIRT:
Show answer & explanation
Correct answer: D
Computer Security Incident Response Teams (CSIRTs) provide all the services mentioned including incident handling, vulnerability management, security awareness training, threat intelligence sharing, forensic analysis, and coordination with other security teams. CSIRTs offer comprehensive security services to support organizational incident response capabilities. Since the question asks about CSIRT services in general and multiple options would be correct, all the above represents the complete range of services these teams typically provide.
- Question 10
Ensuring the integrity, confidentiality and availability of electronic protected health information of a patient is known as:
Show answer & explanation
Correct answer: B
The Health Insurance Portability and Accountability Act (HIPAA) ensures the integrity, confidentiality, and availability of electronic protected health information (ePHI) of patients through comprehensive privacy and security requirements. HIPAA establishes national standards for protecting medical records and personal health information in healthcare organizations. Other acts like FISMA, SOX, and GLBA address different regulatory requirements but do not specifically focus on patient health information protection.
- Question 11Intermediate
Introduction to Incident Handling and Response · Incident Classification
An organization is establishing a new Incident Response Team (IRT) and defining the metric thresholds for incident classification. According to the NIST SP 800-61 Rev. 2 guidelines, which vector primarily assesses the 'Functional Impact' of an incident?
Show answer & explanation
Correct answer: B
According to NIST SP 800-61, Functional Impact refers to the negative impact on the organization's ability to provide services (e.g., None, Low, Medium, High). Information Impact refers to confidentiality/integrity loss, and Recoverability Effort refers to the resources required to recover.
- Question 12Advanced
Introduction to Incident Handling and Response · Threat Modeling
During the 'Preparation' phase of the incident response lifecycle, an organization is conducting a risk assessment to identify potential attack vectors. Which threat modeling methodology focuses specifically on the 'Adversary, Capability, Infrastructure, and Victim' to analyze intrusions?
Show answer & explanation
Correct answer: C
The Diamond Model of Intrusion Analysis explicitly consists of four core features: Adversary, Capability, Infrastructure, and Victim. It is used to analyze intrusion events and pivot between these points to discover more about the attack.
- Question 13Intermediate
Introduction to Incident Handling and Response · Incident Response Plan
A multinational corporation is updating its Incident Response Plan (IRP). Which component of the IRP is critical for ensuring that specific technical procedures for handling common incident types (e.g., Ransomware, DDoS) are documented and standardized?
Show answer & explanation
Correct answer: B
SOPs or Playbooks (sometimes called Runbooks) are the specific, step-by-step technical guides within an IRP that detail how to handle specific incident scenarios like ransomware or DDoS to ensure consistency and completeness.
- Question 14Beginner
Handling Cloud Security Incidents · Shared Responsibility Model
True or False: According to the Shared Responsibility Model in cloud computing, the customer is always responsible for the security 'of' the cloud, including physical hardware and host infrastructure.
Show answer & explanation
Correct answer: B
False. The Cloud Service Provider (CSP) is responsible for security 'of' the cloud (physical, infrastructure, compute hosts), while the customer is responsible for security 'in' the cloud (data, IAM, OS configuration in IaaS).
- Question 15Beginner
Introduction to Incident Handling and Response · Legal and Regulatory Compliance
Which of the following legal acts requires financial institutions in the United States to protect the confidentiality and integrity of consumer financial information, and is a critical compliance consideration during incident handling?
Show answer & explanation
Correct answer: C
The Gramm-Leach-Bliley Act (GLBA) specifically applies to financial institutions and mandates the protection of consumer financial information. HIPAA applies to healthcare, and FISMA applies to federal agencies.
- Question 16Intermediate
Incident Handling and Response Process · Containment Strategy
Following the 'Triage' phase, an Incident Handler has confirmed a malware infection on a critical database server. The handler must now move to the 'Containment' phase. Which of the following containment strategies is MOST appropriate to preserve volatile evidence while preventing lateral movement?
Show answer & explanation
Correct answer: C
Isolating the system from the network (physically or logically via VLAN) stops lateral movement and Command & Control (C2) communication while keeping the system powered on. This preserves the contents of RAM (volatile memory) for forensic acquisition. Powering off destroys RAM data.
- Question 17Intermediate
Incident Handling and Response Process · Post-Incident Activity
An incident handler is performing post-incident activities. A 'Lessons Learned' meeting is convened. What is the PRIMARY output expected from this meeting according to NIST SP 800-61?
Show answer & explanation
Correct answer: B
The primary goal of the Lessons Learned phase is to produce a report that documents the incident timeline, evaluates the team's performance, identifies gaps (what went wrong), and provides actionable recommendations to improve future response and security posture.
- Question 18IntermediateSelect 2
Incident Handling and Response Process · Eradication
Select TWO key objectives of the 'Eradication' phase in the Incident Handling process. (Select TWO)
Show answer & explanation
Correct answers: B, D
Eradication involves removing the root cause (malware, bad accounts) and mitigating vulnerabilities to prevent re-infection. Restoration happens in the Recovery phase, and Evidence Preservation happens in Containment/First Response.
Eradication involves removing the root cause (malware, bad accounts) and mitigating vulnerabilities to prevent re-infection. Restoration happens in the Recovery phase, and Evidence Preservation happens in Containment/First Response.
- Question 19Advanced
Incident Handling and Response Process · Recovery and Validation
Case Study Scenario:
An organization detects unusual outbound traffic from a Finance Department server (10.10.20.5) to a known malicious IP address. The traffic occurs every night at 3:00 AM. The Incident Response Team (IRT) suspects a Command and Control (C2) beacon.
The team has decided to implement a 'Validation' step before declaring the incident closed. Which action BEST represents the validation step in the Recovery phase?
Show answer & explanation
Correct answer: C
Validation is a critical part of Recovery. Before fully closing the incident, the team must verify that the remediation was successful. Monitoring the system for recurrence of the specific symptom (C2 beaconing) is the best validation method.
- Question 20Intermediate
Incident Handling and Response Process · Communication
You are the incident lead. During the 'Notification' phase, you must inform stakeholders. However, the incident involves a potential insider threat within the IT admin team. Which communication method is MOST secure and appropriate to avoid tipping off the suspect?
Show answer & explanation
Correct answer: C
When dealing with insider threats, especially within IT, standard corporate channels (Email, Slack, VoIP) may be monitored by the suspect. Out-of-Band (OOB) communication is required to maintain operational security.
Ready for the real thing?
The full 212-89 simulator has every exam-style question, timed mode, and instant scoring.