Pre-Winter Special Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: spcl70

Practice Free 212-89 EC Council Certified Incident Handler (ECIH v3) Exam Questions Answers With Explanation

We at Crack4sure are committed to giving students who are preparing for the ECCouncil 212-89 Exam the most current and reliable questions . To help people study, we've made some of our EC Council Certified Incident Handler (ECIH v3) exam materials available for free to everyone. You can take the Free 212-89 Practice Test as many times as you want. The answers to the practice questions are given, and each answer is explained.

Question # 6

Zoe, a security analyst, deploys a high-interaction honeypot in the DMZ that mimics critical systems and monitors logs for scans, exploit attempts, and lateral movement techniques. What is the main purpose of Zoe’s activity?

A.

Deceiving attackers to study their behavior.

B.

Preventing malware execution using sandboxing.

C.

Blocking DDoS traffic through ACL rules.

D.

Testing the organization’s backup and recovery systems.

Question # 7

Which of the following is a technique used by attackers to make a message difficult to understand through the use of ambiguous language?

A.

Steganography

B.

Spoofing

C.

Encryption

D.

Obfuscation

Question # 8

A large multinational enterprise recently integrated a digital HR onboarding system to streamline applicant submissions and document collection. During a cybersecurity audit, it was revealed that attackers had set up a phishing site mimicking the official HR document submission portal. Several employees and new hires uploaded their resumes and downloaded pre-filled form templates, believing them to be legitimate. Upon opening the downloaded Word documents, the system silently connected to external servers and fetched additional template data without any user consent or visible macro execution warnings. This bypassed email gateway filters and endpoint antivirus tools, leading to lateral malware spread across systems used by HR, finance, and legal departments.

Digital forensic analysis showed that the documents did not contain visible scripts or macros but relied on hidden structural definitions to retrieve malicious payloads dynamically from attacker-controlled servers. Which of the following web-based malware distribution techniques best explains the observed behavior?

A.

Distribution of malware through remotely hosted RTF injection.

B.

Distribution of malware through spear-phishing emails that impersonate social media contacts.

C.

Distribution of malware through compromised browser extensions embedded in PDF rendering engines.

D.

Distribution of malware through peer-to-peer file propagation mechanisms within internal networks.

Question # 9

Ross is an incident manager (IM) at an organization, and his team provides support to all users in the organization who are affected by threats or attacks. David, who is the organization ' s internal auditor, is also part of Ross ' s incident response team. Which of the following is David ' s responsibility?

A.

Configure information security controls.

B.

Identify and report security loopholes to the management for necessary action.

C.

Coordinate incident containment activities with the information security officer (ISO).

D.

Perform the- necessary action to block the network traffic from the suspectoc intruder.

Question # 10

Which of the following risk mitigation strategies involves execution of controls to

reduce the risk factor and brings it to an acceptable level or accepts the potential risk

and continues operating the IT system?

A.

Risk assumption

B.

Risk avoidance

C.

Risk planning

D.

Risk transference

Question # 11

You are talking to a colleague who Is deciding what information they should include in their organization’s logs to help with security auditing. Which of the following items should you tell them to NOT log?

A.

Timestamp

B.

Session ID

C.

Source IP eddross

D.

userid

Question # 12

A regional healthcare provider leveraging a platform-as-a-service (PaaS) cloud model detects suspicious activity involving unauthorized access to patient records. During the investigation, the incident response team attempts to retrieve system logs from virtual machines used during the breach. However, they realize that crucial log files are unavailable, as the short-lived instances were automatically terminated shortly after the event. This hampers their ability to reconstruct a complete activity trail and trace the attacker ' s movements. Which core cloud forensic challenge does this situation most likely reflect?

A.

Limited log access from containerized workloads.

B.

Metadata misalignment resulting from inconsistent log normalization.

C.

Evaporation of logs due to volatile storage.

D.

Log encryption hindered by poor key management practices.

Question # 13

Michael is an incident handler at CyberTech Solutions. He is performing detection and analysis of a cloud security incident. He is analyzing the file systems, slack spaces, and

metadata of the storage units to find hidden malware and evidence of malice.

Identify the cloud security incident handled by Michael.

A.

Network-related incident

B.

Storage-related incident

C.

Application-related incident

D.

Server-related incident

Question # 14

Which of the following is the ECIH phase that involves removing or eliminating the root cause of an incident and closing all attack vectors to prevent similar incidents in the future?

A.

Recovery

B.

Containment

C.

Eradication

D.

Vulnerability management phase

Question # 15

During a security audit, analysts identified unusual GET requests to a financial application where external resources were fetched using numeric IPs combined with unexpected trailing characters. These inputs were not properly filtered by the system, allowing external content to be processed and embedded in server responses. The issue was traced to a feature that dynamically loads input-specified content without strict validation. Which type of attack/technique is most likely being analyzed in this scenario?

A.

Hidden field manipulation exploiting weak client-side validation logic.

B.

Stored cross-site scripting targeting input validation vulnerabilities.

C.

Command injection via improperly sanitized backend shell interaction.

D.

Remote file inclusion using parameter-level URL obfuscation techniques.

Question # 16

Ethan, part of the IH & R team, receives a phishing email targeting employees with a link to reset passwords. He hovers over the link and notices a discrepancy between the visible URL and the hyperlink. He cross-verifies the sender’s email structure and subject tone to detect further red flags. Which phishing detection approach is Ethan using?

A.

Content encoding validation

B.

Firewall signature matching

C.

URL shortening detection

D.

Manual phishing email verification

Question # 17

An organization implemented an encoding technique to eradicate SQL injection

attacks. In this technique, if a user submits a request using single-quote and some

values, then the encoding technique will convert it into numeric digits and letters

ranging from a to f. This prevents the user request from performing SQL injection

attempt on the web application.

Identify the encoding technique used by the organization.

A.

Unicode encoding

B.

Base64 encoding

C.

Hex encoding

D.

URL encoding

Question # 18

After a recent upgrade, users of TrendSpot, a popular blogging platform, started encountering slow website load times. Upon analysis, it was found that attackers were exploiting a vulnerability and flooding the application with fake search requests, causing an application-layer Denial-of-Service (DoS) attack. How should TrendSpot primarily respond to this attack?

A.

Shift to a more robust hosting provider with higher bandwidth.

B.

Introduce rate limiting on search request functionality.

C.

Regularly clear the server cache to free up resources.

D.

Implement IP address-based blocking for suspicious traffic.

Question # 19

Which of the following is not the responsibility of first responders?

A.

Protecting the crime scene

B.

Identifying the crime scene

C.

Packaging and transporting the electronic evidence

D.

Preserving temporary and fragile evidence and then shut down or reboot the victim’s computer

Question # 20

Malicious downloads that result from malicious office documents being manipulated are caused by which of the following?

A.

Clickjacking

B.

Impersonation

C.

Registry key manipulation

D.

Macro abuse

Question # 21

Meera, part of the Incident Handling & Response (IH & R) team, identifies an ongoing phishing campaign targeting internal employees. She immediately circulates an organization-wide alert, warning staff not to engage with the suspicious email. Along with the alert, she provides visual cues and instructions on how to recognize similar phishing threats in the future. Her goal is to prevent further damage and strengthen employee awareness. What additional action would best align with Meera’s eradication efforts?

A.

Installing anti-DDoS tools

B.

Sharing threat details with security forums

C.

Issuing server restart commands

D.

Deleting user accounts

Question # 22

A malicious, security-breaking program is disguised as a useful program. Such executable programs, which are installed when a file is opened, allow others to control a user ' s system. What is this type of program called?

A.

Trojan

B.

Worm

C.

Virus

D.

Spyware

Question # 23

After experiencing a large-scale distributed denial-of-service (DDoS) attack that caused service outages and degraded performance to its online subscriber portal, a national telecom provider was able to recover and restore its web platform. With customer trust on the line and concerns about similar future incidents, the organization ' s IH & R team has been tasked with implementing robust post-recovery measures that enhance the resilience of web services against traffic-based disruptions. The team is evaluating several options to maintain service availability while mitigating the potential impact of recurring DDoS attempts. Which of the following actions would be most effective in strengthening the provider ' s defenses as part of the recovery process?

A.

Remove antivirus to speed up application response.

B.

Configure a CDN and implement blackhole routing.

C.

Add guest user accounts for remote diagnostics.

D.

Increase FTP access for easier maintenance.

Question # 24

In which of the following phases of the incident handling and response (IH & R) process is the identified security incidents analyzed, validated, categorized, and prioritized?

A.

Incident triage

B.

Incident recording and assignment

C.

Containment

D.

Notification

Question # 25

BetaCorp, a multinational corporation, identified an employee selling company secrets to competitors. BetaCorp wants to prevent such incidents in the future. Which action will be most effective?

A.

Conduct surprise bag checks at office exits.

B.

Implement an Employee Monitoring Tool to track digital activities.

C.

Regularly change office locations of employees.

D.

Introduce random polygraph tests.

Question # 26

After a successful exploitation attempt, a university web server started exhibiting anomalies such as high server load, random form submission errors, and repeated spam complaints. Hosting providers flagged the domain as suspicious and disabled the web application. The IH & R team discovered new unknown files within the web root directory. Which action would be most appropriate to contain the incident and avoid further damage?

A.

Perform a scan to identify injection points and isolate the affected component from the network.

B.

Reconfigure form validations for improved user experience.

C.

Run a stress test to ensure hosting capacity is sufficient.

D.

Immediately re-enable the application after restoring from backup.

Question # 27

A cybersecurity analyst at a technology firm discovers suspicious activity on a network segment dedicated to research and development. The initial indicators suggest a possible compromise of several endpoints with potential intellectual property theft. Given the sensitive nature of the data involved, what is the most effective method for the analyst to detect and validate the security incident?

A.

Immediately notify law enforcement and regulatory bodies.

B.

Isolate the affected network segment and manually inspect each endpoint.

C.

Deploy an endpoint detection and response (EDR) solution to identify and investigate suspicious activities.

D.

Conduct a network-wide vulnerability scan.

Question # 28

A multinational law firm suffered a sophisticated malware attack that encrypted critical legal documents. During recovery, there is concern that some archived backups may already be compromised. Which recovery-focused action should the organization prioritize to ensure safe restoration?

A.

Perform comprehensive scans of all backup data using updated antivirus and heuristics.

B.

Deploy host-based firewalls and restrict outbound traffic.

C.

Restore services from live file shares synchronized with other offices.

D.

Wipe all endpoints completely before restoring files.

Question # 29

Jason is setting up a computer forensics lab and must perform the following steps: 1. physical location and structural design considerations; 2. planning and budgeting; 3. work area considerations; 4. physical security recommendations; 5. forensic lab licensing; 6. human resource considerations. Arrange these steps in the order of execution.

A.

2 - > 1 - > 3 - > 6 - > 4 - > 5

B.

2- > 3- > l - > 4- > 6- > 5

C.

5- > 2- > l- > 3- > 4- > 6

D.

3 . > 2 - > 1 - > 4- > 6- > 5

Question # 30

Zaimasoft, a prominent IT organization, was attacked by perpetrators who directly targeted the hardware and caused irreversible damage to the hardware. In result, replacing or reinstalling the hardware was the only solution.

Identify the type of denial-of-service attack performed on Zaimasoft.

A.

ddos

B.

DoS

C.

PDoS

D.

DRDoS

Question # 31

You are a systems administrator for a company. You are accessing your file server remotely for maintenance. Suddenly, you are unable to access the server. After contacting others in your department, you find out that they cannot access the file server either. You can ping the file server but not connect to it via RDP. You check the Active Directory Server, and all is well. You check the email server and find that emails are sent and received normally. What is the most likely issue?

A.

An e-mail service issue

B.

The file server has shut down

C.

A denial-of-service issue

D.

An admin account issue

Question # 32

Sophia, an incident handler at a cloud hosting provider, is investigating reports of intermittent web server slowdowns and timeouts. Upon analyzing router logs, she finds an unusually high number of incomplete connection attempts, causing the server’s memory and CPU resources to spike. Suspecting a form of resource exhaustion attack, she applies a protective configuration to the router that allows it to validate connection requests before they reach the server. Soon after this change, the number of partial connections decreases, and the server regains stable performance. What was the purpose of this action?

A.

To scan for malicious payloads

B.

To prevent brute-force logins

C.

To block SYN flood attempts

D.

To monitor port scans

Question # 33

Which of the following email security tools can be used by an incident handler to

prevent the organization against evolving email threats?

A.

Email Header Analyzer

B.

G Suite Toolbox

C.

MxToolbox

D.

Gpg4win

Question # 34

Which of the following does NOT reduce the success rate of SQL injection?

A.

Close unnecessary application services and ports on the server.

B.

Automatically lock a user account after a predefined number of invalid login attempts within a predefined interval.

C.

Constrain legitimate characters to exclude special characters.

D.

Limit the length of the input field.

Question # 35

Daniel, a system administrator, was discovered accessing encrypted project files that had no relevance to his job responsibilities. A security audit revealed that his account had unrestricted access to all file servers, and there were no alerts or enforcement mechanisms in place to block or flag such access. Which countermeasure should have been in place to prevent this abuse?

A.

Manual surveillance at workstations

B.

Strictly configured personal firewall rules

C.

Disabling the use of removable media

D.

User segmentation through Zero Trust access

Question # 36

John, a professional hacker, is attacking an organization, where he is trying to destroy the connectivity between an AP and client to make the target unavailable to other

wireless devices.

Which of the following attacks is John performing in this case?

A.

Routing attack

B.

EAP failure

C.

Disassociation attack

D.

Denial-of-service

Question # 37

Sam received an alert through an email monitoring tool indicating that their company was targeted by a phishing attack. After analyzing the incident, Sam identified that most of the targets of the attack are high-profile executives of the company. What type of phishing attack is this?

A.

Pharming

B.

Whaling

C.

Puddle phishing

D.

Spear phishing

Question # 38

Zoe, a security analyst at a multinational technology firm, is tasked with enhancing the organization ' s threat detection capabilities. To proactively understand potential attack vectors, she deploys a high-interaction honeypot within the company ' s demilitarized zone (DMZ). The honeypot mimics critical systems, exposing deliberate but non-harmful vulnerabilities to simulate a real target environment. Zoe integrates this setup with intrusion detection systems and begins monitoring the logs for connection attempts, exploit patterns, and lateral movement techniques. Over the next few days, she observes multiple access attempts, port scans, and unauthorized login trials from various IP addresses, which she documents to identify trends in attacker behavior. What is the main purpose of Zoe ' s activity?

A.

Preventing malware execution using sandboxing

B.

Blocking DDoS traffic through ACL rules

C.

Deceiving attackers to study their behavior

D.

Testing the organization ' s backup and recovery systems

Question # 39

Stenley is an incident handler working for Texa Corp. located in the United States. With the growing concern of increasing emails from outside the organization, Stenley was

asked to take appropriate actions to keep the security of the organization intact. In the process of detecting and containing malicious emails, Stenley was asked to check the

validity of the emails received by employees.

Identify the tools he can use to accomplish the given task.

A.

PointofMail

B.

Email Dossier

C.

PoliteMail

D.

EventLog Analyzer

Question # 40

NeuroNet, a pioneer in neural network research, was alarmed when it identified an insider siphoning off critical research data. Post-investigation, it was determined that the employee was disgruntled because of recent management decisions. To minimize such threats in the future, which measure should NeuroNet prioritize?

A.

Implement a robust Data Loss Prevention (DLP) system.

B.

Conduct monthly one-on-one sessions between employees and HR.

C.

Introduce an anonymous feedback system for employees.

D.

Restrict all employees from accessing research data unless explicitly authorized.

Question # 41

In response to suspicious communications originating from executive accounts, the organization ' s response team traced the root cause to spoofed identity relays exploiting unsecured DNS entries. The attack had triggered internal alerts but required deeper remediation to eliminate recurring forged message injections and restore the integrity of interdepartmental mail routing. What action reflects an appropriate eradication strategy in this context?

A.

Requesting legal review of communication failures post-incident

B.

Investigating the delay in threat detection due to analysis

C.

Sharing phishing indicators with external peer communities

D.

Strengthening SPF, DKIM, and DMARC configurations

Question # 42

Ren is assigned to handle a security incident of an organization. He is tasked with forensics investigation to find the evidence needed by the management. Which of the following steps falls under the investigation phase of the computer forensics investigation process?

A.

Secure the evidence

B.

Risk assessment

C.

Setup a computer forensics lab

D.

Evidence assessment

Question # 43

Mr. Smith is a lead incident responder of a small financial enterprise having few

branches in Australia. Recently, the company suffered a massive attack losing USD 5

million through an inter-banking system. After in-depth investigation on the case, it was

found out that the incident occurred because 6 months ago the attackers penetrated the

network through a minor vulnerability and maintained the access without any user

being aware of it. Then, he tried to delete users’ fingerprints and performed a lateral

movement to the computer of a person with privileges in the inter-banking system.

Finally, the attacker gained access and did fraudulent transactions.

Based on the above scenario, identify the most accurate kind of attack.

A.

Ransomware attack

B.

Denial-of-service attack

C.

APT attack

D.

Phishing

Question # 44

Which of the following is not a countermeasure to eradicate cloud security incidents?

A.

Patch the database vulnerabilities and improve the isolation mechanism

B.

Remove the malware files and traces from the affected components

C.

Check for data protection at both design and runtime

D.

Disable security options such as two factor authentication and CAPTCHA

Question # 45

After experiencing a web application attack, HealthFirst, a health records management company, traced the breach to an insecure Direct Object Reference (IDOR) vulnerability. They seek to patch this vulnerability and fortify their application against future incidents. What should be their primary action?

A.

Conduct regular penetration testing on the application.

B.

Introduce a Web Application Firewall (WAF) with default rules.

C.

Implement role-based access controls (RBAC) for data access.

D.

Encrypt all data at rest and in transit.

Question # 46

A company facing a wave of spoofed payment emails launched an investigation and found that employees had unknowingly interacted with malicious sender domains. Despite blocking initial IPs and purging visible email content, similar threats resurfaced using altered variants. The team moved to eliminate recurring delivery mechanisms and close technical loopholes. Which step is most aligned with this eradication initiative?

A.

Contacting email domain registrars to request WHOIS masking of sender information

B.

Launching email-based simu-lation drills to evaluate user response to phishing

C.

Reviewing the email training curriculum related to financial transaction safety

D.

Creating email-specific URL deny-lists from decoded message components

Question # 47

DeltaCorp, a global e-commerce company, recently received an email sent to the financial department. The email claimed to be from the CEO, instructing an urgent transfer of funds to a vendor for a new project. The email appeared to come from the CEO ' s official email address, contained a signature, and seemed professionally written, but raised suspicions because of the urgency and lack of prior discussion about such a project. The incident response team was alerted. To determine the legitimacy of this potentially deceptive and suspicious email, which of the following should be the primary focus of the team ' s investigation?

A.

Inspect the email headers for signs of spoofing or irregularities in the sender ' s IP address.

B.

Review the CEO ' s past emails to check for similar language and tone.

C.

Scan the company ' s email server for malware to ensure that no unauthorized access occurred.

D.

Contact the vendor mentioned in the email to verify whether they are expecting a fund transfer.

Question # 48

Which of the following digital evidence temporarily stored on a digital device that

requires a constant power supply and is deleted if the power supply is interrupted?

A.

Swap file

B.

Event logs

C.

Slack space

D.

Process memory

Question # 49

Racheal is an incident handler working in InceptionTech organization. Recently,

numerous employees are complaining about receiving emails from unknown senders. In

order to prevent employees against spoofing emails and keeping security in mind,

Racheal was asked to take appropriate actions in this matter. As a part of her

assignment, she needs to analyze the email headers to check the authenticity of received

emails.

Which of the following protocol/authentication standards she must check in email

header to analyze the email authenticity?

A.

DKIM

B.

SNMP

C.

POP

D.

ARP

Question # 50

A mid-sized healthcare organization undergoing digital modernization is working toward ISO/IEC 27001 certification to enhance patient data safeguards and regulatory compliance. During a readiness review, the CISO identifies significant gaps—staff lack clear channels to raise concerns about potential system weaknesses, outcome tracking after adverse events is inconsistent, and there is no formalized way to assess what went right or wrong following such disruptions. Furthermore, insights from previous security challenges are not being applied to strengthen preparedness or prevent similar future occurrences. To comply with ISO/IEC 27001 Annex A.16, which action should be prioritized to address these shortcomings?

A.

Define and implement structured procedures for flaw escalation and integrating post-incident response knowledge.

B.

Deploy EDR agents across endpoints to block malware propagation and initiate automatic quarantine.

C.

Conduct tabletop exercises to simulate various insider threat scenarios.

D.

Implement a centralized SIEM dashboard to provide real-time threat correlation and alerting.

Question # 51

Which of the following is NOT part of the static data collection process?

A.

Evidence oxa mi nation

B.

System preservation

C.

Password protection

D.

Evidence acquisition

Question # 52

Aarav, an IT support specialist, identifies that multiple employees have engaged with an email promoting free shopping vouchers, which appears suspicious. To minimize the potential threat, he instructs staff to report the message, classify it as junk, and remove it from their inboxes. He further advises them not to interact with similar messages in the future, even if they seem to come from internal contacts. Which best practice is Aarav reinforcing?

A.

Sort emails by priority

B.

Digitally sign email attachments

C.

Disable preview pane in the inbox

D.

Avoid replying to or forwarding suspicious emails

Question # 53

Mike is an incident handler for PNP Infosystems Inc. One day, there was a ticket submitted regarding a critical incident and Mike was assigned to handle the incident. During the process of incident handling, at one stage, he performed incident analysis and validation to check whether the incident is a genuine incident or a false positive.

Identify the stage he is currently in.

A.

Post-incident activities

B.

Incident disclosure

C.

Incident recording and assignment

D.

Incident triage

Question # 54

Ikeo Corp, hired an incident response team to assess the enterprise security. As part of the incident handling and response process, the IR team is reviewing the current security policies implemented by the enterprise. The IR team finds that employees of the organization do not have any restrictions on Internet access: they are allowed to visit any site, download any application, and access a computer or network from a remote location. Considering this as the main security threat, the IR team plans to change this policy as it can be easily exploited by attackers. Which of the following security policies is the IR team planning to modify?

A.

Paranoid policy

B.

Prudent policy

C.

Promiscuous policy

D.

Permissive policy

Question # 55

Which of the following is a standard framework that provides recommendations for implementing information security controls for organizations that initiate, implement, or maintain information security management systems (ISMSs)?

A.

ISO/IEC 27002

B.

ISO/IEC 27035

C.

PCI DSS

D.

RFC 219G

Question # 56

During a routine investigation, Daniel, a threat analyst, notices repetitive failed login attempts in server logs with HTTP POST requests and status code 200 across several entries. At log entry 117, a 302 redirect status is recorded for the same user account. What type of attack is this indicative of?

A.

Dictionary attack

B.

Session hijacking

C.

SQL injection

D.

CSRF attack

Question # 57

MegaHealth, a global healthcare provider, experienced a sudden malfunction in its MRI machines. Investigations revealed malware that tweaked MRI results and communicated with an external command-and-control server. With tools like an advanced endpoint protection system and a network monitor, what should be the first step?

A.

Inform the patients about a potential compromise of their data.

B.

Use the network monitor to identify and block the C & C server communication.

C.

Update the MRI machines ' firmware and software.

D.

Deploy the endpoint protection on MRI machines to detect and halt the malware.

Question # 58

Elizabeth, who works for OBC organization as an incident responder, is assessing the risks to the organizational security. As part of the assessment process, she is calculating the probability of a threat source exploiting an existing system vulnerability. Which of the following risk assessment steps is Elizabeth currently in?

A.

Vulnerability identification

B.

Impact analysis

C.

Likelihood analysis

D.

System characterization

Question # 59

An incident handler is analyzing email headers to find out suspicious emails.

Which of the following tools he/she must use in order to accomplish the task?

A.

Barracuda Email Security Gateway

B.

Gophish

C.

SPAMfighter

Question # 60

AlphaTech, a technology firm, recently discovered signs of an advanced persistent threat (APT) in its infrastructure. The incident response team is trying to gather more information about the threat to form a comprehensive response strategy. While leveraging threat intelligence platforms, which of the following approaches would be most effective in gathering detailed and actionable insights about the APT to improve the firm ' s defense against such threats?

A.

Obtaining historical data on common cyber threats and using it to predict future APT movements.

B.

Collaborating with industry peers to understand similar threats they have faced and the tactics, techniques, and procedures (TTPs) observed.

C.

Searching for IOCs (Indicators of Compromise) related to known APT campaigns and comparing them with the observed patterns.

D.

Gathering information about APTs from open-source forums and integrating this with their internal threat database.

Question # 61

A company utilizing multiple cloud services aims to enhance its posture against cloud security incidents. Among the following options, which constitutes the best practice for achieving this goal?

A.

Regularly conduct penetration testing exclusively on critical cloud assets.

B.

Focus on physical security measures at company offices.

C.

Centralize logging and monitoring across all cloud services for improved visibility and anomaly detection.

D.

Implement a single cloud service provider strategy.

Question # 62

A cybersecurity team at a financial services firm detects abnormal behavior on several endpoints, suggesting a possible breach. The anomalies include unexpected data transfers and processes running with unusual permissions. Given the potential impact, the team needs to quickly validate whether these are indicators of a security incident or benign anomalies. What method should the team prioritize to detect and validate the incident effectively?

A.

Utilize an advanced behavioral analysis tool to differentiate between legitimate and malicious activities.

B.

Implement strict access control measures to limit permissions on all endpoints immediately.

C.

Disconnect the affected endpoints from the network to prevent potential data exfiltration.

D.

Engage an external cybersecurity consultancy to conduct an independent assessment.

Question # 63

Jake, a senior incident responder in a financial institution ' s SOC, receives a high-severity alert from the intrusion detection system (IDS). The alert indicates a flood of SYN packets targeting the internal web server, which has now become sluggish and unresponsive to legitimate client requests. The sudden surge in half-open connections is causing resource exhaustion on the server. Suspecting a SYN flood attack—a type of denial-of-service (DoS) attack—Jake needs to verify the source and nature of the traffic to determine the appropriate containment and mitigation strategy while preserving system integrity and uptime. What step should Jake take first in response to this suspected DoS incident?

A.

Notify HR to instruct employees on mandatory password resets

B.

Disconnect all users from the network to isolate the server

C.

Inspect network traffic to confirm the attack pattern and verify source behavior

D.

Reboot the affected server to restore availability

Question # 64

Jason, a cybersecurity analyst in the incident response team, begins investigating several complaints from employees who received emails urgently requesting wire transfers to an overseas account. The emails appeared to come from the company’s CEO, using a tone of authority and pressure to bypass standard procedures. Upon closer inspection, Jason identifies that the sender ' s email address includes a minor alteration in the domain name—a form of domain spoofing. He examines the email headers, confirms the falsified sender identity, and cross-checks with the actual CEO’s activity logs to ensure there was no internal compromise. Immediately, Jason blocks the sender’s IP address at the firewall level, alerts the finance department to prevent any unauthorized transactions, and issues a company-wide advisory about the impersonation attempt. What type of phishing is Jason handling?

A.

Whaling

B.

Mail bombing

C.

Credential stuffing

D.

Spimming

Question # 65

At a major healthcare provider, staff received phishing emails impersonating HR. Reporting via email failed due to mail system issues. The IR team introduced VOIP and SMS-based reporting mechanisms. Which preparatory step was implemented?

A.

Training on phishing indicators

B.

Creating backup archives

C.

Email content filtering

D.

Establishing out-of-band communication

Question # 66

NovoMed discovers encrypted data transfers of drug research and participant data to an unknown location and receives an extortion-like message implying the formula may be released. What is the most prudent course of action?

A.

Immediately recall the drug from the market.

B.

Publicly announce the breach warning competitors and authorities.

C.

Negotiate with the attackers discreetly to buy time and retrieve data.

D.

Engage local law enforcement and international cybercrime agencies to trace the transfer’s origins.

Question # 67

Otis is an incident handler working in Delmont organization. Recently, the organization is facing several setbacks in the business and thereby its revenues are going down. Otis

was asked to take the charge and look into the matter. While auditing the enterprise security, he found the traces of an attack, where the proprietary information was stolen

from the enterprise network and was passed onto the competitors.

Which of the following information security incidents Delmont organization faced?

A.

Network and resource abuses

B.

Unauthorized access

C.

Espionage

D.

Email-based abuse

Question # 68

In which of the following confidentiality attacks attackers try to lure users by posing themselves as authorized AP by beaconing the WLAN ' s SSID?

A.

Evil twin AP

B.

Session hijacking

C.

Honeypot AP

D.

Masqueradin

Question # 69

Bob, an incident responder at CyberTech Solutions, is investigating a cybercrime attack occurred in the client company. He acquired the evidence data, preserved it, and started

performing analysis on acquired evidentiary data to identify the source of the crime and the culprit behind the incident.

Identify the forensic investigation phase in which Bob is currently in.

A.

Vulnerability assessment phase

B.

Post-investigation phase

C.

Pre-investigation phase

D.

Investigation phase

Question # 70

A multinational law firm suffered a sophisticated malware attack that encrypted critical legal documents and disrupted access to client records across several regional offices. After isolating infected infrastructure and eradicating active threats, the incident response team enters the recovery phase, aiming to restore systems and resume operations globally.

Plans involve using archived contents and collaboration media; however, threat intelligence reports suggest that some of these archives may originate from already compromised environments. This raises concern about reinfection risks if latent malware is unknowingly reintroduced during system restoration. To prevent reinfection, ensure service continuity, and avoid legal and reputational consequences, recovery must be executed securely and with caution. Given this context, which recovery-focused action should the organization prioritize to ensure the safe reconstitution of its systems and services?

A.

Deploy host-based firewalls and restrict all non-essential outbound traffic until recovery is completed.

B.

Perform comprehensive scans of all backup data using antivirus tools with updated signatures and heuristics.

C.

Wipe all endpoints, including user profiles and non-system partitions, before file restoration.

D.

Restore services from live file shares synchronized with unaffected offices.

Question # 71

Clark is investigating a cybercrime at TechSoft Solutions. While investigating the case,

he needs to collect volatile information such as running services, their process IDs,

startmode, state, and status.

Which of the following commands will help Clark to collect such information from

running services?

A.

Openfiles

B.

netstat –ab

C.

wmic

D.

net file

Question # 72

Mason, an incident responder, detects a large volume of traffic from an internal host to external IP addresses during non-business hours. The affected host also shows signs of elevated memory and CPU consumption. AIDA64 Extreme logs confirm the system was under continuous strain for hours. What should Mason suspect as the primary issue?

A.

High resource utilization due to inappropriate usage

B.

Network misconfiguration

C.

Unauthorized hardware installation

D.

Improper access control policy

Question # 73

Mei, a forensic analyst, is analyzing logs from a compromised blog platform. She finds evidence that an attacker posted content using a valid account, and later, users who visited the blog were redirected to a phishing site containing session cookies in the URL. What kind of attack does this best describe?

A.

Reflected XSS

B.

Man-in-the-middle attack

C.

Stored XSS

D.

Directory traversal

Question # 74

Which of the following methods help incident responders to reduce the false-positive

alert rates and further provide benefits of focusing on topmost priority issues reducing

potential risk and corporate liabilities?

A.

Threat profiling

B.

Threat contextualization

C.

Threat correlation

D.

Threat attribution

Question # 75

An international insurance provider observed a sharp rise in endpoint infections across geographically dispersed offices. The IR team correlated the infections with recent access to a series of trusted informational websites visited during routine research activities. After cross-referencing network telemetry and endpoint logs, analysts uncovered that these sites had been covertly altered by threat actors to include obfuscated scripts that launched on page render. Upon visiting the tampered content, a series of exploit chains were executed, targeting unpatched vulnerabilities in rendering engines of commonly used client applications. The malicious code was injected directly into volatile memory, allowing the payload to operate stealthily without initiating file creation events or prompting user interaction. Security tools failed to detect the compromise in real time due to the absence of conventional indicators such as user-triggered executions or external file transfers. Which web-based malware delivery technique is MOST consistent with the described attack?

A.

Spam email propagation using malicious file attachments disguised as legitimate documents

B.

Search engine poisoning using black hat search engine optimization

C.

Drive-by download attacks that exploit vulnerabilities

D.

Malvertising via poisoned ad banners embedded in third-party ad-serving platforms

Question # 76

In an online retail company, a severe security incident occurred where attackers exploited a zero-day vulnerability in the website ' s backend. This exploit allowed the theft of thousands of customers ' credit card details. While the tech team races to patch the vulnerability, what should be the primary focus of the IH & R team?

A.

Coordinating with financial institutions to monitor suspicious transactions.

B.

Commencing legal actions against the attackers.

C.

Immediately emailing all customers advising them to cancel cards.

D.

Analyzing server logs using Incident Response Automation and Orchestration tools to understand the breach ' s origin.

Question # 77

EcoEarth Inc. detects abnormal archival data access from dormant employee profiles, modification of critical datasets, and suspicious encrypted packet transmissions. Given the risk, what is the first responder’s primary action?

A.

Decrypt the suspicious packets to understand the breach.

B.

Notify global ecological partners to review shared data.

C.

Initiate a rollback to a previous safe state using real-time backups.

D.

Isolate and shut down sections of the server showing abnormal activity.

Question # 78

Employee monitoring tools are mostly used by employers to find which of the following?

A.

Lost registry keys

B.

Conspiracies

C.

Malicious insider threats

D.

Stolen credentials

Question # 79

Following a high-profile breach investigation at a multinational corporation, an incident handler is tasked with the critical role of preserving, packaging, and transporting digital evidence from a server believed to be compromised and utilized as part of a global botnet operation. The challenge lay not only in the technical complexities of the operation but also in adhering to stringent legal and procedural frameworks to ensure the evidence remained admissible in court. The server, containing potentially millions of records of illicit transactions, represented a key piece of the puzzle in understanding the breadth of the breach. The incident handler had to navigate through multiple layers of security protocols to access the server, all while ensuring that the evidence was handled in a manner that prevented any form of tampering or degradation during the collection, packaging, and transport process. Which of the following options ensures the highest level of evidence integrity during its transport?

A.

On-site encryption of the server ' s data, followed by its upload to a secure cloud storage solution, with the entire process meticulously documented for future verification.

B.

Transferring the server data onto a newly secured drive using a write blocker, placing it within a tamper-evident bag, and employing GPS tracking for the transport process.

C.

Creating a forensic image of the server ' s drives, conducting verification of the image hashes, storing these images on encrypted drives, and completing a detailed log of the transport procedure.

D.

Encasing the server in anti-static packaging, labeling it meticulously with the chain-of-custody documentation, and securing it in a locked container for transportation.

Question # 80

Which of the following information security personnel handles incidents from management and technical point of view?

A.

Network administrators

B.

Incident manager (IM)

C.

Threat researchers

D.

Forensic investigators

Question # 81

A large healthcare provider with an extensive network of endpoints, including desktops in administrative offices and mobile devices used by field staff, experiences a significant ransomware attack. The attack encrypts critical patient data and demands a substantial ransom for decryption keys. The incident highlights the vital need for an effective endpoint security incident handling and response framework, especially in sectors where data sensitivity and uptime are crucial. What underscores the importance of this framework in such a context?

A.

The need to review and possibly overhaul the entire IT infrastructure post-incident.

B.

The necessity of maintaining operational continuity in healthcare services to ensure patient care.

C.

The potential for reputational damage exceeding the immediate financial costs of the ransom.

D.

The requirement to report the incident to regulatory bodies within a specified timeframe.

Question # 82

Rachel, a first responder, finds a smartphone in an executive’s office that is powered ON and actively displaying a messaging app with potentially incriminating information. She avoids locking the screen or turning off the device, photographs the current display, and collects its charging cable. She then safely packages the device and ensures it is kept charged during transport. What principle is Rachel applying in her evidence handling approach?

A.

Extracting deleted messages from the cache.

B.

Preserving screen-based digital evidence.

C.

Forcing a factory reset to preserve evidence.

D.

Allowing device shutdown to save battery.

Question # 83

Which of the following is an Inappropriate usage incident?

A.

Access-control attack

B.

Reconnaissance attack

C.

Insider threat

D.

Denial-of-service attack

Question # 84

Joseph is an incident handling and response (IH & R) team lead in Toro Network Solutions Company. As a part of IH & R process, Joseph alerted the service providers,

developers, and manufacturers about the affected resources.

Identify the stage of IH & R process Joseph is currently in.

A.

Eradication

B.

Containment

C.

Incident triage

D.

Recovery

Question # 85

David, an incident responder, investigates an email-based breach where the CFO ' s email account was compromised and used to send invoice modification requests to vendors. Logs reveal that the attacker accessed the account using valid credentials after the CFO clicked on a fake Microsoft 365 login prompt sent via email. Which technique did the attacker most likely use?

A.

Spimming

B.

Pharming

C.

Mail bombing

D.

Spear phishing

Question # 86

A global bank ' s IH & R team is investigating an intricate cyber-espionage campaign. Advanced persistent threat (APT) actors exfiltrated sensitive financial data over several months using both software vulnerabilities and human errors. What is the MOST appropriate immediate action for the IH & R team?

A.

Conduct organization-wide cybersecurity awareness training.

B.

Publicize the breach to comply with laws.

C.

Focus solely on patching known vulnerabilities.

D.

Leverage an Incident Response Automation and Orchestration (IRAO) tool to correlate data and automate threat hunting.

Question # 87

Liam, a senior incident responder at a manufacturing company, is alerted to an email campaign distributing malware through fake invoice attachments. He confirms that some users opened the attachment, resulting in system slowdown and unauthorized access attempts. He disconnects affected machines, scans and removes malware, disables compromised accounts, restores systems from clean backups, and documents file hashes, sender IPs, and malicious domains. Which of the following best describes Liam’s objective?

A.

To simulate future phishing scenarios

B.

To conduct forensic preservation

C.

To upgrade the internal mail server infrastructure

D.

To eradicate all traces of the incident

Question # 88

Which of the following port scanning techniques involves resetting the TCP connection

between client and server abruptly before completion of the three-way handshake

signals, making the connection half-open?

A.

Null scan

B.

Full connect scan

C.

Stealth scan

D.

Xmas scan

Question # 89

During an internal audit following a surge in unauthorized financial transactions, a multinational investment firm ' s IR team uncovers evidence of an orchestrated campaign targeting senior staff. The attackers had pieced together fragments of sensitive data by mining executive digital footprints, reviewing online publications, and analyzing company-related mentions on external platforms. Later, they engaged directly with employees under fabricated personas, conducting scripted interviews to extract missing identifiers. With the assembled profile data, the adversaries submitted diversion requests for financial correspondence and used these to impersonate executives and execute fraudulent transfers. Forensic analysis revealed no signs of malware infection or system-level compromise. Which technique best aligns with the adversary ' s method of obtaining the initial sensitive information?

A.

Phishing through spoofed emails embedded with malicious macros targeting employee laptops

B.

Social engineering using open-source intelligence followed by pretexting

C.

Pharming attack that redirected login traffic from internal systems to malicious replicas

D.

Skimming magnetic card data through modified payment devices in the company cafeteria

Question # 90

An attack on a network is BEST blocked using which of the following?

A.

IPS device inline

B.

HIPS

C.

Web proxy

D.

Load balancer

Question # 91

Nina, an experienced network incident responder working for a financial services firm, receives a series of high-priority alerts from Splunk Enterprise Security. The alerts are triggered by anomalous HTTP traffic patterns coming from a workstation within the internal network. Specifically, the system flagged repeated attempts to access untrusted external URLs, followed by the download of executable (.exe) files during non-business hours. Suspecting malicious activity, Nina begins investigating the web proxy logs and correlates them with endpoint detection logs. Her analysis confirms that the downloaded executables were not digitally signed and were flagged as malware by the organization ' s endpoint protection system shortly after execution. She also finds evidence that the malware attempted to establish outbound communication, likely for command-and-control (C2) purposes.

Nina immediately initiates containment by isolating the affected endpoint from the network. She proceeds to perform a wider investigation using system-wide and firewall logs to assess if the malware spread laterally or exfiltrated any sensitive data. What is the most likely cause of this incident?

A.

Inappropriate resource usage through malicious downloads

B.

Wi-Fi spoofing from a rogue device

C.

Malware injected through a SQL vulnerability

D.

Unauthorized privilege escalation attempt

Question # 92

In the lead-up to a major product launch, a technology company reviews its endpoint security strategy to safeguard intellectual property. What is the most essential element to incorporate into their incident response strategy for endpoints?

A.

An employee training program focused on phishing defense

B.

A dedicated crisis management team

C.

A robust endpoint detection and response (EDR) system with automated response

D.

Comprehensive encryption strategies for data at rest and in transit

Question # 93

A large retail company recently migrated its customer data to a public cloud service. Shortly after, they noticed suspicious activities indicating a potential data breach. The incident response team faces multiple challenges due to the cloud ' s shared responsibility model, including limited access to underlying infrastructure and logs. Which action is most critical for the incident response team to perform first?

A.

Request immediate access to all infrastructure logs from the cloud service provider.

B.

Begin an internal audit of all cloud service configurations and permissions.

C.

Notify customers about the potential data breach to comply with data protection regulations.

D.

Isolate affected systems by modifying cloud security group settings.

Question # 94

Which of the following terms refers to an organization’s ability to make optimal use of digital evidence in a limited period of time and with minimal investigation costs?

A.

Threat assessment

B.

Data analysis

C.

Risk assessment

D.

Forensic readiness

Question # 95

David, a certified digital first responder, arrives at the scene of a reported security breach in the HR department of a corporate office. The breach involves multiple digital endpoints, including desktop systems and mobile devices. Upon entering the scene, David observes that one desktop computer is still powered ON and logged in, showing a sensitive financial dashboard on the screen. Realizing the importance of preserving this evidence, David refrains from interacting directly with the keyboard or running applications. Instead, he takes high-resolution photographs of the screen to capture the current session details, including open applications and time-sensitive data. To avoid altering the system state, David gently moves the mouse without clicking, just enough to dismiss a screen saver without triggering any on-screen changes. He records the system’s behavior, notes any visible alerts or programs running, and tags all connected cables and peripheral ports for proper documentation. What step in the evidence handling process is David demonstrating?

A.

Seizing off-site backups

B.

Preserving volatile evidence from an active system

C.

Executing a shutdown script on Linux

D.

Handling a powered-off device

Question # 96

Stanley works as an incident responder at a top MNC based in Singapore. He was asked to investigate a cybersecurity incident that recently occurred in the company. While investigating the incident, he collected evidence from the victim systems. He must present this evidence in a clear and comprehensible manner to the members of a jury so that the evidence clarifies the facts and further helps in obtaining an expert opinion on the incident to confirm the investigation process. In the above scenario, which of the following characteristics of the digital evidence did Stanley attempt to preserve?

A.

Completeness

B.

Admissibility

C.

Believability

D.

Authenticity

Question # 97

During routine checks, EduSoft, an educational software provider, identified malware within their digital examination tools. This malware not only provided answers to students but mined personal data. With a digital forensic tool and an encryption protocol tool, what ' s the ideal primary action?

A.

Disable the examination tool until further notice.

B.

Alert educational institutions about the compromised software.

C.

Use the forensic tool to ascertain the malware ' s source and method of operation.

D.

Deploy the encryption tool to safeguard students ' data.

Question # 98

Who is mainly responsible for providing proper network services and handling network-related incidents in all the cloud service models?

A.

Cloud consumer

B.

Cloud auditor

C.

Cloud brokers

D.

Cloud service provide

Question # 99

Tibson works as an incident responder for MNC based in Singapore. He is investigating

a web application security incident recently faced by the company. The attack is

performed on a MS SQL Server hosted by the company. In the detection and analysis

phase, he used regular expressions to analyze and detect SQL meta-characters that led

to SQL injection attack.

Identify the regular expression used by Tibson to detect SQL injection attack on MS

SQL Server.

A.

/exec(\s|\+)+(s|x)p\w+/ix

B.

((\.\.\\)|(\.\.\/))

C.

((\.|%2E)(\.|%2E)(\/|%2F|\\|%5C))

D.

((\%3C)| < )((\%2F)|\/)*(script)((\%3E)| > )

Question # 100

Otis is an incident handler working in an organization called Delmont. Recently, the organization faced several setbacks in business, whereby its revenues are decreasing. Otis was asked to take charge and look into the matter. While auditing the enterprise security, he found traces of an attack through which proprietary information was stolen from the enterprise network and passed onto their competitors. Which of the following information security incidents did Delmont face?

A.

Network and resource abuses

B.

Espionage

C.

Email-based abuse

D.

Unauthorized access

Question # 101

A global manufacturing company detected unauthorized privilege escalation on one of its OT workstations connected to critical production systems. The IH & R team must respond without alerting the attacker or risking deletion of forensic artifacts. The attacker ' s persistence mechanisms and data exfiltration activity are not yet fully identified. The CISO instructs the team to implement a strategy that limits the threat ' s lateral movement without tipping off the adversary. Which of the following containment actions best aligns with this objective?

A.

Restore the system using the latest verified backup image.

B.

Initiate a system-wide shutdown to prevent any further compromise.

C.

Disable select services and maintain a low profile using passive monitoring.

D.

Notify all employees immediately to change their credentials across the domain.

Question # 102

Which of the following is not called volatile data?

A.

Open sockets er open ports

B.

The dale a no Lime of the system

C.

Creation dates of files

D.

State of the network interface

Question # 103

An IT security analyst at a logistics firm is alerted to unusual outbound traffic originating from an employee ' s mobile device, which is actively connected to the corporate VPN. Initial investigation confirms the presence of malware. Although antivirus scans are run multiple times, the malicious activity continues, suggesting the infection is deeply embedded or resistant to standard removal methods. The organization cannot afford further data leakage or operational disruptions caused by this device. Which action should the incident handler take next to ensure complete removal of the persistent threat and restore device integrity?

A.

Disable the SIM card.

B.

Switch the device to airplane mode.

C.

Perform a factory reset or reinstall the mobile OS.

D.

Restrict background app refresh for social apps.

Question # 104

For analyzing the system, the browser data can be used to access various credentials.

Which of the following tools is used to analyze the history data files in Microsoft Edge browser?

A.

ChromeHistoryView

B.

BrowsingHistoryView

C.

MZCacheView

D.

MZHistoryView

Question # 105

After a recent upgrade, users of Trend Spot encountered slow website load times. Analysis revealed attackers flooding the application with fake search requests, causing an application-layer DoS attack. How should Trend Spot primarily respond?

A.

Regularly clear the server cache.

B.

Shift to a more robust hosting provider.

C.

Introduce rate limiting on search request functionality.

D.

Implement IP address-based blocking for suspicious traffic.

Question # 106

What is the most recent NIST standard for incident response?

A.

800-61r2

B.

800-61r3

C.

800-53r3

D.

800-171r2

212-89 PDF

$33

$109.99

3 Months Free Update

  • Printable Format
  • Value of Money
  • 100% Pass Assurance
  • Verified Answers
  • Researched by Industry Experts
  • Based on Real Exams Scenarios
  • 100% Real Questions

212-89 PDF + Testing Engine

$52.8

$175.99

3 Months Free Update

  • Exam Name: EC Council Certified Incident Handler (ECIH v3)
  • Last Update: Oct 8, 2026
  • Questions and Answers: 356
  • Free Real Questions Demo
  • Recommended by Industry Experts
  • Best Economical Package
  • Immediate Access

212-89 Engine

$39.6

$131.99

3 Months Free Update

  • Best Testing Engine
  • One Click installation
  • Recommended by Teachers
  • Easy to use
  • 3 Modes of Learning
  • State of Art Technology
  • 100% Real Questions included