EC-COUNCIL 212-89 Dumps Updated Sep 03, 2026 WIith 447 Questions
View All 212-89 Actual Free Exam Questions Sep 03, 2026 Updated
The ECIH certification exam is a 2-hour, computer-based exam that consists of 100 multiple-choice questions. 212-89 exam is designed to test an individual's knowledge and skills in incident handling and response. 212-89 exam covers various topics such as incident handling process, incident handling procedures, communication and documentation, and various types of incidents. To pass the ECIH certification exam, an individual must score at least 70% on the exam.
NEW QUESTION # 116
During the eradication phase of a web application security incident at a major online retail platform, the incident response team discovers that the application was compromised through a previously unknown zero-day vulnerability. This vulnerability allowed the attacker to access user credit card information. The incident has severe financial and reputational implications. In this highly sensitive scenario, what is the best course of action for the incident response team?
- A. Conceal the incident to protect the company's reputation
- B. Focus solely on tracking the attacker without addressing the vulnerability
- C. Patch the vulnerability, remove all traces of the attacker, inform affected users, and coordinate with relevant authorities
- D. Immediately go public with the details of the zero-day vulnerability
Answer: C
NEW QUESTION # 117
An international logistics firm runs a smart hub where IT systems interface with warehouse automation for tasks like sorting, routing, and conveyor coordination via programmable units and dashboards. A recent cyberattack, initiated through a compromised third-party remote maintenance tunnel, disrupted communication between backend scheduling applications and embedded automation units, leading to halted processing lines and shipment delays.
After isolating affected segments, removing malicious components, and restoring critical workflows, the recovery team begins validating the reinstated operations. While reviewing logs and configurations, they find excessive permissions granted between internal authentication servers and embedded automation modules.
They also detect anomalies in authentication tokens used to verify communications across system interfaces, including unidentified fingerprints not matching the original configuration. Which action should be prioritized as part of a secure restoration plan?
- A. Enforce granular role-based access policies across control systems and validate trusted device certificates
- B. Conduct red-team simulations to test OT segmentation defenses
- C. Apply new IDS signatures to detect malware variants targeting SCADA devices
- D. Reboot all systems to verify stable firmware operation
Answer: A
Explanation:
The EC-Council Incident Handler (ECIH) curriculum emphasizes that recovery must not only restore functionality but also eliminate residual security weaknesses that could enable reinfection or continued compromise. In operational technology (OT) and industrial environments, identity validation, certificate trust, and strict access control between interconnected systems are critical.
The scenario highlights two major issues: excessive permissions between authentication servers and automation modules, and anomalies in authentication tokens with unidentified fingerprints. These findings indicate compromised trust relationships and over-privileged system communications.
ECIH recovery guidance stresses revalidating authentication mechanisms, enforcing the Principle of Least Privilege, reviewing trust relationships, and ensuring certificate integrity before declaring systems fully restored. Implementing granular role-based access controls (RBAC) and validating trusted device certificates directly addresses both excessive permissions and authentication anomalies.
Option A improves detection but does not correct trust misconfigurations. Option B (red-team simulation) is useful but secondary to securing authentication controls. Option C (system reboot) does not resolve permission or certificate validation issues.
Therefore, enforcing granular role-based access policies and validating trusted device certificates is the most critical secure restoration action.
NEW QUESTION # 118
Which of the following is not the responsibility of first responders?
- A. Identifying the crime scene
- B. Preserving temporary and fragile evidence and then shut down or reboot the victim's computer
- C. Protecting the crime scene
- D. Packaging and transporting the electronic evidence
Answer: C
NEW QUESTION # 119
Shally, an incident handler, is working for a company named Texas Pvt. Ltd. based in Florida. She was asked to work on an incident response plan. As part of the plan, she decided to enhance and improve the security infrastructure of the enterprise. She has incorporated a security strategy that allows security professionals to use several protection layers throughout their information system. Due to multiple layer protection, this security strategy assists in preventing direct attacks against the organization's information system as a break in one layer only leads the attacker to the next layer.
Identify the security strategy Shally has incorporated in the incident response plan.
- A. Exponential backoff algorithm
- B. Defense-in-depth
- C. Three-way handshake
- D. Covert channels
Answer: B
Explanation:
Shally has incorporated the Defense-in-depth strategy into the incident response plan for Texas Pvt. Ltd.
Defense-in-depth is a layered security approach that involves implementing multiple security measures and controls throughout an information system. This strategy is designed to provide several defensive barriers to protect against threats and attacks, ensuring that if one layer is compromised, others still provide protection.
The goal is to create a multi-faceted defense that addresses potential vulnerabilities in various areas, including physical security, network security, application security, and user education.
References:The Incident Handler (ECIH v3) courses and study guides often emphasize the importance of a Defense-in-depth strategy in creating robust security infrastructures to protect against a wide range of cyber threats.
NEW QUESTION # 120
Attackers or insiders create a backdoor into a trusted network by installing an unsecured access point inside a firewall. They then use any software or hardware access point to perform an attack. Which of the following is this type of attack?
- A. Malware attack
- B. Rogue- access point attack
- C. Email infection
- D. Password-based attack
Answer: B
Explanation:
A rogue-access point attack occurs when attackers or insiders install an unsecured access point within a trusted network, typically behind a firewall, to create a backdoor. This allows them to bypass network security measures and perform various malicious activities undetected. The use of any software or hardware access point to gain unauthorized access and conduct an attack characterizes a rogue-access point attack. This contrasts with password-based attacks, malware attacks, and email infections, which involve different methodologies and objectives, such as stealing credentials, distributing malicious software, or propagating through email systems, respectively.References:The ECIH v3 certification materials discuss various types of network attacks, including rogue-access point attacks, highlighting the risk they pose by providing unauthorized network access to attackers.
NEW QUESTION # 121
In which of the following stages of incident handling and response (IH&R) process do the incident handlers try to find out the root cause of the incident along with the threat actors behind the incidents, threat vectors, etc.?
- A. Incident triage
- B. Incident recording and assignment
- C. Post-incident activities
- D. Evidence gathering and forensics analysis
Answer: D
Explanation:
During the incident handling and response (IH&R) process, the stage of "Evidence gathering and forensics analysis" involves the collection of evidence, forensic analysis, and detailed investigation to uncover the root cause of the incident. This stage is crucial for understanding how the incident occurred, identifying the threat actors involved, the methods they used (threat vectors), and the extent of the impact. By analyzing evidence, incident responders can reconstruct the sequence of events, identify the vulnerabilities exploited, and determine the scope of the incident. This information is vital for resolving the incident effectively and taking steps to prevent future occurrences.
NEW QUESTION # 122
As a senior network security analyst at a multinational corporation, you are part of an expert team overseeing the security of a complex network. An alert comes through one morning, indicating potential unauthorized access through a vulnerable Wi-Fi connection in one of your global offices.
The nature of the breach suggests possible intellectual property theft. Your team is assigned to validate and respond to the incident. In this complex scenario, what is the primary goal of a network security incident response plan?
- A. Identifying, containing, eradicating, and recovering from the incident
- B. Implementing new business strategies for the company
- C. Minimizing costs associated with the incident response
- D. Expanding the company's global reach and market share
Answer: A
NEW QUESTION # 123
A company has migrated its infrastructure and services to the cloud to leverage its scalability and flexibility. However, they are facing challenges in effectively handling and responding to security incidents in the cloud environment. What is one of the key challenges in cloud incident handling and response?
- A. Limited availability of cloud service provider's security tools and features.
- B. Inadequate incident response team training and skills.
- C. Difficulty in conducting forensic investigations in a shared cloud environment.
- D. Lack of visibility and control over cloud infrastructure and data.
Answer: D
NEW QUESTION # 124
A network administrator reviews firewall and IDS/IPS configurations to ensure logging is properly set, updates logging to centralize alerts from all network devices, and confirms that all response team members know their responsibilities. Which preparatory activity is he performing?
- A. Conducting vulnerability scanning.
- B. Coordinating external law enforcement.
- C. Hardening backup systems.
- D. Ensuring network monitoring readiness.
Answer: D
NEW QUESTION # 125
Emily, a member of the cybersecurity response team, receives an alert indicating suspicious login attempts on the company's internal HR portal. Upon inspection, she finds several failed login attempts from a foreign IP address targeting administrative accounts. Further investigation reveals that one of the accounts was compromised and its privileges were escalated. What indicator most strongly suggests this is an unauthorized access incident?
- A. Log entries showing access to critical files
- B. New system process creation
- C. Suspicious DNS activity
- D. High CPU utilization
Answer: A
Explanation:
The ECIH incident validation phase emphasizes the importance of direct evidence when confirming unauthorized access. Log entries that show access to sensitive or restricted files provide concrete proof that an attacker successfully breached controls.
Option B is correct because access logs tied to critical resources confirm both authentication success and unauthorized activity. Failed logins or system performance issues alone do not confirm compromise.
Option A, C, and D are indirect indicators that may signal suspicious behavior but cannot independently confirm unauthorized access.
Therefore, verified log evidence is the strongest indicator, aligning with ECIH incident triage and validation principles.
NEW QUESTION # 126
Sam, an employee from a multinational company, send se-mails to third-party organizations with a spoofed email address of his organization.
How can you categorize this type of incident?
- A. Network intrusion incident
- B. Inappropriate usage incident
- C. Denial-of-service incident
- D. Unauthorized access incident
Answer: B
NEW QUESTION # 127
The IT security team of a multinational corporation identifies a breach in its BYOD policy, with several employees' mobile devices infected with spyware through a malicious app. These devices had access to the corporate email system. What is the most immediate action the security team should take?
- A. Launch an awareness campaign on unauthorized apps.
- B. Implement an enterprise mobility management (EMM) solution.
- C. Mandate a password reset for all corporate email accounts.
- D. Disconnect the infected devices from the corporate network and initiate forensic analysis.
Answer: D
Explanation:
This scenario involves active mobile spyware infections, representing an immediate confidentiality risk. The ECIH Endpoint and Mobile Incident Handling guidance prioritizes containment when active compromise is detected.
Option C is correct because disconnecting infected devices immediately prevents further data leakage and lateral movement. Initiating forensic analysis allows responders to determine scope, data accessed, and persistence mechanisms. ECIH emphasizes that containment must precede long-term control improvements.
Option A is preventive and strategic but not immediate. Option B addresses future behavior. Option D mitigates credential risk but does not stop spyware activity.
Thus, immediate isolation and forensic analysis is the correct first response.
NEW QUESTION # 128
Olivia, a cybersecurity responder at a multinational firm, is alerted late at night by the NOC team about unusual latency and degraded performance across several critical applications hosted on the company's internal servers. Upon initial inspection, she notices that the internal routers are experiencing an unusually high volume of ARP requests being broadcast across the network. The network bandwidth utilization has spiked, and multiple routers are reporting elevated CPU usage.
As she digs deeper into the diagnostics, Olivia finds that the NAT tables on edge routers are saturated with numerous entries coming from the same IP range within a short time frame. These entries appear to be initiating simultaneous connections to different ports across various endpoints. The firewall logs also show repeated attempts to access unused services, and the ISP reports an overflow of incoming requests from various geolocations.
Based on these symptoms, what should Olivia suspect?
- A. Rogue DHCP server activity
- B. Data exfiltration
- C. Application vulnerability scanning
- D. Distributed DoS attack
Answer: D
Explanation:
The indicators described align closely with a Distributed Denial-of-Service (DDoS) attack, a major topic in the ECIH Network Security Incidents module. DDoS attacks overwhelm network and system resources using traffic from multiple sources, often distributed across geographic regions.
Excessive ARP traffic, NAT table exhaustion, elevated CPU usage on routers, and simultaneous connection attempts are classic symptoms of volumetric and protocol-based DDoS attacks. The involvement of multiple geolocations, as reported by the ISP, further confirms the distributed nature of the attack.
Option B is correct because no single-host misconfiguration or reconnaissance activity would generate this volume and diversity of traffic. Option A would cause IP conflicts, not global traffic floods. Option C focuses on stealthy outbound activity, not inbound saturation. Option D is low-volume and targeted.
ECIH emphasizes early identification of DDoS conditions to enable rapid containment using rate limiting, blackholing, or ISP coordination. Recognizing these indicators is critical to protecting service availability.
NEW QUESTION # 129
Which of the following digital evidence temporarily stored on a digital device that requires a constant power supply and is deleted if the power supply is interrupted?
- A. Swap file
- B. Process memory
- C. Slack space
- D. Event logs
Answer: B
NEW QUESTION # 130
The flow chart gives a view of different roles played by the different personnel of CSIRT. Identify the incident response personnel denoted by A, B, C, D, E, F and G.
- A. A- Incident Coordinator, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Manager
- B. A- Incident Coordinator, B- Constituency, C-Administrator, D-Incident Manager, E- Human Resource, F-Incident Analyst, G-Public relations
- C. A-Incident Analyst, B- Incident Coordinator, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Manager
- D. A- Incident Manager, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-Constituency, G-Incident Coordinator
Answer: B
NEW QUESTION # 131
A software application in which advertising banners are displayed while the program is running that delivers
ads to display pop-up windows or bars that appears on a computer screen or browser is called:
- A. adware (spelled all lower case)
- B. Trojan
- C. RootKit
- D. Worm
- E. Virus
Answer: A
NEW QUESTION # 132
EduTech University noticed unauthorized access to student records, including academic and financial details. As the semester's examinations approached, there were concerns about potential leaks or manipulations of question papers. In this complex digital scenario, what is the optimal step for the first responder?
- A. Isolate the academic systems, ensuring the integrity of upcoming examinations.
- B. Notify students and staff, urging them to change their university portal passwords.
- C. Capture logs from the academic servers, focusing on recent access and modifications.
- D. Collaborate with faculty to develop alternative exam papers as a backup.
Answer: A
Explanation:
The ECIH Incident Handling lifecycle prioritizes containment during first response when active compromise threatens data integrity and operational continuity. In this scenario, the risk extends beyond data theft to potential manipulation of examination materials.
Option C is correct because isolating the affected academic systems immediately prevents further unauthorized access and preserves the integrity of examination content. Containment ensures that attackers cannot alter or leak sensitive academic materials while investigations proceed.
Option A supports investigation but does not stop ongoing risk. Option B is a contingency plan, not a response action. Option D is premature and does not address system compromise.
According to ECIH, first responders must act decisively to prevent further damage before moving into analysis and recovery, making Option C correct.
NEW QUESTION # 133
Which of the following may be considered as insider threat(s):
- A. An employee who gets an annual 7% salary raise
- B. Disgruntled system administrators
- C. An employee with an insignificant technical literacy and business process knowledge
- D. An employee having no clashes with supervisors and coworkers
Answer: B
NEW QUESTION # 134
A logistics company relying heavily on cloud-based inventory management discovered unauthorized activity initiated by a third-party contractor. The investigation revealed that the contractor's login was reused across multiple departments and lacked any tracking mechanism or role-specific restrictions to limit its scope. What cloud security best practice should be implemented to prevent such violations?
- A. Implementation of Secure Sockets Layer (SSL) encryption on internal systems
- B. Enforcement of strict user access control and credential isolation
- C. Use of anonymized data during inventory analytics
- D. Routine vulnerability scans on mobile apps used by delivery teams
Answer: B
Explanation:
The EC-Council Incident Handler (ECIH) curriculum emphasizes Identity and Access Management (IAM) as a foundational control in cloud security. In cloud environments, shared credentials and lack of role-based restrictions significantly increase the risk of misuse, unauthorized access, and privilege abuse.
The scenario clearly identifies two major violations: credential reuse across departments and absence of role-specific restrictions. ECIH highlights that cloud best practices require enforcing strict user access control using the Principle of Least Privilege (PoLP) and role-based access control (RBAC). Each user--including third-party contractors--must have unique credentials with clearly defined permissions aligned strictly with their job responsibilities.
Credential isolation ensures accountability and traceability, enabling effective logging, auditing, and forensic investigation. Without unique user tracking, organizations cannot accurately attribute actions, which weakens incident response and compliance efforts.
NEW QUESTION # 135
Zaimasoft, a prominent IT organization, was attacked by perpetrators who directly targeted the hardware and caused irreversible damage to the hardware. In result, replacing or reinstalling the hardware was the only solution.
Identify the type of denial-of-service attack performed on Zaimasoft.
- A. DoS
- B. DRDoS
- C. ddos
- D. PDoS
Answer: D
NEW QUESTION # 136
......
New 212-89 Exam Questions Real EC-COUNCIL Dumps: https://www.trainingdumps.com/212-89_exam-valid-dumps.html
Pass Authentic EC-COUNCIL 212-89 with Free Practice Tests and Exam Dumps: https://drive.google.com/open?id=1V30Bti7y6HGuLpcLo4BgZdLztZpPHct7

