212-89 Sample Questions

212-89 Sample Questions & Answers

Working through the incident handling and response workflow, malware incidents, and network attacks such as denial-of-service share the heaviest weighting, alongside first response and evidence gathering, and email, web, cloud, and endpoint cases.

Launch the full 212-89 simulator →

Free 212-89 Sample Questions with Answers

Real questions from the Certified Incident Handler (ECIH) practice test — answers and explanations included. Showing 20 of 40 free samples.

  1. Question 1

    An incident is analyzed for its nature, intensity and its effects on the network and systems. Which stage of the incident response and handling process involves auditing the system and network log files?

    Show answer & explanation

    Correct answer: D

    The Identification stage of incident response involves analyzing incidents for their nature, intensity, and effects, which includes auditing system and network log files to understand what occurred. This stage focuses on determining whether a security event is actually an incident requiring response. Incident recording documents the incident, reporting communicates findings, and containment focuses on limiting the incident spread rather than initial analysis.

  2. Question 2

    Incident Response Plan requires

    Show answer & explanation

    Correct answer: D

    Incident Response Plans require all of the above components: financial and management support for resources and authority, expert team composition with skilled personnel from various disciplines, and adequate resources including technology, tools, and budget. A comprehensive incident response plan cannot be effective without any of these critical elements, as each component is essential for successful incident handling and organizational preparedness.

  3. Question 3

    A software application in which advertising banners are displayed while the program is running that delivers ads to display pop-up windows or bars that appears on a computer screen or browser is called:

    Show answer & explanation

    Correct answer: A

    Adware is software that displays advertising banners while running and delivers ads through pop-up windows or bars on computer screens or browsers, often generating revenue for developers through ad display. Unlike malicious malware, adware primarily focuses on advertising rather than system damage. Trojans disguise malicious functionality, rootkits hide system presence, viruses self-replicate and infect files, and worms spread across networks, none of which primarily focus on advertising display.

  4. Question 4

    According to the Evidence Preservation policy, a forensic investigator should make at least................image copies of the digital evidence.

    Show answer & explanation

    Correct answer: B

    According to Evidence Preservation policy, a forensic investigator should make at least two image copies of digital evidence to ensure data integrity and provide backup protection against corruption or damage during analysis. One copy serves as a working copy for examination while the other remains pristine for verification and legal presentation. Single copies risk evidence loss, while three or more copies may be excessive for most investigations, but two copies specifically provide the minimum redundancy needed for proper evidence preservation and chain of custody maintenance.

  5. Question 5

    The most common type(s) of intellectual property is(are):

    Show answer & explanation

    Correct answer: D

    The most common types of intellectual property include all the mentioned forms: copyrights protecting creative works, trademarks protecting brand identifiers, patents protecting inventions, and trade secrets protecting confidential business information. Each type provides different legal protections for intangible assets. Since intellectual property encompasses multiple categories of legal protection for different types of creative and business assets, all the above represents the complete range of common intellectual property types that organizations must protect.

  6. Question 6

    Business continuity is defined as the ability of an organization to continue to function even after a disastrous event, accomplished through the deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy. Identify the plan which is mandatory part of a business continuity plan?

    Show answer & explanation

    Correct answer: B

    Business Recovery Plan is the comprehensive strategy that enables organizations to continue functioning after disastrous events through redundant hardware/software, fault-tolerant systems, and robust backup procedures. This plan specifically focuses on operational continuity and system restoration. While disaster recovery plans address immediate response, business impact analysis evaluates potential losses, and contingency plans provide alternative procedures, the Business Recovery Plan encompasses the full spectrum of organizational continuity measures.

  7. Question 7

    Agencies do NOT report an information security incident is because of:

    Show answer & explanation

    Correct answer: A

    Organizations often fail to report information security incidents primarily due to fear of negative publicity, which could damage their reputation, customer trust, and stock value. This concern about public perception frequently outweighs the benefits of incident reporting and information sharing. While costs, legal concerns, and technical challenges may be factors, the fear of reputational damage remains the predominant reason organizations avoid incident disclosure.

  8. Question 8

    Which among the following CERTs is an Internet provider to higher education institutions and various other research institutions in the Netherlands and deals with all cases related to computer security incidents in which a customer is involved either as a victim or as a suspect?

    Show answer & explanation

    Correct answer: D

    SURFnet-CERT is the Computer Emergency Response Team that serves as an Internet provider to higher education institutions and research institutions in the Netherlands, handling all computer security incidents involving their customers. This specialized CERT focuses on the academic and research community. Other CERTs serve different constituencies: CERT/CC coordinates global incident response, AusCERT serves Australia, and JPCERT serves Japan, but none specifically focus on Dutch higher education institutions.

  9. Question 9

    Which of the following service(s) is provided by the CSIRT:

    Show answer & explanation

    Correct answer: D

    Computer Security Incident Response Teams (CSIRTs) provide all the services mentioned including incident handling, vulnerability management, security awareness training, threat intelligence sharing, forensic analysis, and coordination with other security teams. CSIRTs offer comprehensive security services to support organizational incident response capabilities. Since the question asks about CSIRT services in general and multiple options would be correct, all the above represents the complete range of services these teams typically provide.

  10. Question 10

    Ensuring the integrity, confidentiality and availability of electronic protected health information of a patient is known as:

    Show answer & explanation

    Correct answer: B

    The Health Insurance Portability and Accountability Act (HIPAA) ensures the integrity, confidentiality, and availability of electronic protected health information (ePHI) of patients through comprehensive privacy and security requirements. HIPAA establishes national standards for protecting medical records and personal health information in healthcare organizations. Other acts like FISMA, SOX, and GLBA address different regulatory requirements but do not specifically focus on patient health information protection.

Ready for the real thing?

The full 212-89 simulator has every exam-style question, timed mode, and instant scoring.

Go to the 212-89 simulator →