Get Ready with 212-89 Exam Dumps (2026) [Q45-Q62]

Share

Get Ready with 212-89 Exam Dumps (2026)

Realistic 212-89 Dumps are Available for Instant Access


What Are Domains Covered by ECIH Test?

Overall, this certification exam has nine domains that have a specific weightage in the official validation. The candidates who take this exam need to master the following topics:

  • Malware incidents 8%;
  • Cloud environment incidents 8%;
  • Incident handling and response 16%;
  • Application-level incidents 8%;
  • First response and forensic readiness 13%.
  • Process handling 14%;
  • Insider threats 7%;
  • Email security incidents 10%;

 

NEW QUESTION # 45
An incident is analyzed for its nature, intensity and its effects on the network and systems. Which stage of the
incident response and handling process involves auditing the system and network log files?

  • A. Reporting
  • B. Identification
  • C. Containment
  • D. Incident recording

Answer: B


NEW QUESTION # 46
A global manufacturing company detected unauthorized privilege escalation on an OT workstation connected to production systems. The attacker's persistence and data exfiltration are not fully identified. The CISO wants to limit lateral movement without alerting the attacker. Which containment action best aligns with this objective?

  • A. Restore the system using the latest verified backup.
  • B. Disable select services and maintain a low profile using passive monitoring.
  • C. Notify all employees to change credentials immediately.
  • D. Initiate system-wide shutdown.

Answer: B

Explanation:
This scenario requires stealthy containment, a technique emphasized in ECIH when dealing with advanced threats, particularly in OT environments.
Option A is correct because disabling selective services while maintaining passive monitoring restricts attacker movement without tipping them off. ECIH stresses that premature disruption can cause attackers to destroy evidence or accelerate damage.
Options B, C, and D are noisy actions that alert the adversary and risk operational disruption.
ECIH recommends low-profile containment for advanced and persistent threats, especially in critical infrastructure, making Option A the correct response.


NEW QUESTION # 47
ThetaTec, a global fintech giant, identified that an employee was siphoning off funds using a sophisticated method undetectable by traditional monitoring tools. The firm decided to employ advanced techniques to detect such hidden insider threats. What should be its primary focus?

  • A. Conduct polygraph tests on all employees quarterly.
  • B. Use behavioral analytics to identify potential risks based on employee actions and patterns.
  • C. Mandate all employees to provide access to their personal bank statements.
  • D. Install hidden microphones in the office to capture conversations.

Answer: B

Explanation:
Comprehensive and Detailed Explanation (ECIH-aligned):
Insider threats are among the most difficult risks to detect because insiders often operate within legitimate access boundaries. The ECIH Insider Threat module emphasizes that behavioral analytics is the most effective approach for identifying sophisticated, low-and-slow insider activity.
Option B is correct because behavioral analytics correlates user actions over time to detect anomalies such as unusual transaction patterns, abnormal access times, or deviations from job role norms. This allows detection of malicious behavior that traditional rule-based monitoring may miss.
Options A, C, and D are invasive, unethical, and often illegal, and they contradict ECIH guidance on lawful, proportional monitoring.
ECIH stresses that insider threat programs must balance security, privacy, and legality while providing meaningful detection. Behavioral analytics meets these requirements and provides actionable insights, making Option B the correct answer.


NEW QUESTION # 48
Which of the following processes is referred to as an approach to respond to the security incidents that occurred in an organization and enables the response team by ensuring that they know exactly what process to follow in case of security incidents?

  • A. Incident response orchestration
  • B. Risk assessment
  • C. Threat assessment
  • D. Vulnerability management

Answer: A

Explanation:
Incident response orchestration refers to the process and technologies used to coordinate and streamline the response to security incidents. This approach ensures that incident response teams have clear procedures and workflows to follow, enabling them to act swiftly and effectively when dealing with security incidents. By orchestrating the response, organizations can minimize the impact of incidents, ensure consistent and thorough investigation and remediation activities, and improve their overall security posture. Incident response orchestration involves integrating various security tools, automating response actions where possible, and providing a centralized platform for managing incidents.
References:The concept of incident response orchestration and its role in enhancing the effectiveness of incident handling and response efforts is discussed in cybersecurity literature and training, including ECIH v3 study materials, which highlight the benefits of having a structured and organized approach to managing security incidents.


NEW QUESTION # 49
Jake, a senior incident responder in a financial institution's SOC, receives a high-severity alert from the intrusion detection system (IDS). The alert indicates a flood of SYN packets targeting the internal web server, which has now become sluggish and unresponsive to legitimate client requests. The sudden surge in half-open connections is causing resource exhaustion on the server. Suspecting a SYN flood attack-a type of denial-of- service (DoS) attack-Jake needs to verify the source and nature of the traffic to determine the appropriate containment and mitigation strategy while preserving system integrity and uptime. What step should Jake take first in response to this suspected DoS incident?

  • A. Notify HR to instruct employees on mandatory password resets
  • B. Reboot the affected server to restore availability
  • C. Inspect network traffic to confirm the attack pattern and verify source behavior
  • D. Disconnect all users from the network to isolate the server

Answer: C

Explanation:
The EC-Council Incident Handler (ECIH) curriculum states that during the detection and analysis phase, responders must validate the incident before taking disruptive containment actions. In suspected DoS attacks, traffic analysis is critical to confirm attack patterns such as SYN floods characterized by numerous half-open TCP connections.
Inspecting network traffic using packet captures, firewall logs, and IDS telemetry allows responders to confirm the nature of the attack, identify source IP behavior, and determine whether IP spoofing or distributed sources are involved. This ensures appropriate mitigation such as SYN cookies, rate limiting, or upstream filtering.
Option A is unrelated. Option B may disrupt business operations prematurely. Option D (rebooting) does not address the attack and may temporarily relieve symptoms without mitigation.
ECIH emphasizes evidence preservation, traffic validation, and controlled response during DoS incidents.
Therefore, the first step is to inspect network traffic to confirm the attack pattern and verify source behavior.


NEW QUESTION # 50
Rica works as an incident handler for an international company. As part of her role, she must review the present security policy implemented. Upon inspection, Rica finds that the policy is wide open, and only known dangerous services/attacks or behaviors are blocked. Which of the following is the current policy that Rica identified?

  • A. Promiscuous policy
  • B. Prudent policy
  • C. Permissive policy
  • D. Paranoic policy

Answer: C

Explanation:
A permissive security policy is characterized by allowing all activities except those that are explicitly blocked.
This approach starts with a default state of allowing access and functionality, with restrictions applied only to known dangerous services, attacks, or behaviors. Such a policy can lead to a wider attack surface because it assumes services and behaviors are safe unless proven otherwise.
* A prudent policy would typically involve more conservative security measures, applying necessary restrictions to protect against identified and potential threats.
* A paranoic policy would be at the extreme end of security measures, possibly blocking more than necessary to ensure the highest level of security, often at the expense of usability or functionality.
* A promiscuous policy, in contrast, would be even more open than a permissive policy, essentially allowing nearly all traffic or actions with minimal restrictions, which is not what Rica observed.
References:In the context of the ECIH v3 course by EC-Council, reviewing and understanding the implications of security policies, like the permissive policy identified by Rica, is crucial for incident handlers to assess and improve organizational security postures.


NEW QUESTION # 51
Which of the following is an attack that attempts to prevent the use of systems, networks, or applications by the intended users?

  • A. Fraud and theft
  • B. Unauthorized access
  • C. Denial of service (DoS) attack
  • D. Malicious code or insider threat attack

Answer: C

Explanation:
A Denial of Service (DoS) attack aims to make a computer resource, network, or application unavailable to its intended users, thereby preventing legitimate users from using the service. This is achieved by overwhelming the target with a flood of internet traffic or sending information that triggers a crash. In contrast, fraud and theft involve the unauthorized acquisition of data or assets, unauthorized access refers to gaining entry into systems without permission, and malicious code or insider threat attacks relate to software designed to cause harm or unauthorized actions by trusted users within the organization. The specific intent of a DoS attack is to disrupt service, making it a distinct category focused on denial of availability.


NEW QUESTION # 52
The EC-Council Certified Incident Handler (ECIH) at an organization suspects an employee to be an insider threat due to unusual network activities. The handler is currently using the ActivTrak Employee Monitoring Solution for insider threat detection. Which of the following actions is the most appropriate first step for the incident handler to perform in this scenario?

  • A. Analyzing the screenshots captured by ActivTrak and the resources involved in the suspected activities.
  • B. Immediately report the suspicious activity to senior management to seek further advice.
  • C. Contact law enforcement agencies and legal authorities for a thorough investigation.
  • D. Blocking all access for the suspected employee, including email, application accounts, physical access cards, and network credentials.

Answer: A


NEW QUESTION # 53
In an international bank, the IT security team identified unusual network traffic indicating a potential malware infection. Further analysis revealed that several high-value transaction servers were communicating with an external command and control server. The team needs to decide the immediate action to best handle this malware incident triage. What should they prioritize to mitigate the threat and safeguard sensitive data effectively?

  • A. Initiating a controlled shutdown of the transaction servers to preserve their current state
  • B. Disconnecting the affected servers from the network to prevent further data exfiltration
  • C. Performing a memory dump of the affected servers for in-depth forensic analysis
  • D. Immediately updating antivirus signatures on all network devices and servers

Answer: B

Explanation:
This scenario describes an active malware infection with confirmed command-and-control (C2) communication, which represents an immediate and severe risk to sensitive financial data. According to the EC-Council ECIH malware incident handling process, the first priority in such cases is containment, specifically stopping ongoing malicious activity and preventing further data exfiltration.
Option A is correct because disconnecting the affected servers from the network immediately severs the attacker's control channel and halts outbound data leakage. ECIH emphasizes that when C2 traffic is observed, responders must act decisively to isolate compromised systems before pursuing deeper forensic analysis or remediation. Containment minimizes damage and reduces legal, financial, and reputational impact.
Option B may preserve system state but allows continued exfiltration until shutdown is complete and may disrupt critical banking operations. Option C is a preventive measure and does not stop an active infection.
Option D is valuable for investigation but should occur after containment, not before.
ECIH guidance consistently prioritizes stopping harm over gathering evidence when critical assets are at risk.
Therefore, immediate network disconnection of affected servers is the correct triage action.


NEW QUESTION # 54
Sophia, a security analyst, notices that a sensitive folder on a file server was accessed during off- hours by an intern using authorized credentials. The access was not flagged because the intern's permissions had not been reviewed in months, even after their project ended. What process should have been enforced to avoid this insider threat?

  • A. Regular auditing of user access rights
  • B. Surveillance camera monitoring
  • C. Data classification and encryption
  • D. Account lockout policies

Answer: A

Explanation:
Regular access rights audits ensure permissions are reviewed and removed when users no longer need them. This would have identified the intern's outdated folder access after the project ended and reduced the risk of unauthorized insider activity.


NEW QUESTION # 55
The USB tool (depicted below) that is connected to male USB Keyboard cable and not detected by anti-spyware tools is most likely called:

  • A. Hardware Keylogger
  • B. Software Key Grabber
  • C. Anti-Keylogger
  • D. USB adapter

Answer: A


NEW QUESTION # 56
A multinational consultancy firm recently conducted a mobile security awareness session after noticing repeated incidents of suspicious activity on corporate-linked Android devices. During the session, IT discovered that several employees had been sideloading APK files from unofficial third- party websites to access premium apps for free. These unauthorized installations introduced malware that compromised login credentials, triggered unauthorized data exfiltration, and bypassed existing security filters. Further investigation revealed that the company lacked enforcement of application certification checks on enrolled Android devices, and employees were unaware of the risks of using unverified sources. What security control should be prioritized to prevent such behavior in the future?

  • A. Enable remote location tracking for corporate Android devices
  • B. Enforce MDM policies that allow only signed app installations
  • C. Restrict Bluetooth and NFC-based application communication channels
  • D. Acquire full-disk encryption for both device storage and application data

Answer: B

Explanation:
The EC-Council Incident Handler (ECIH) curriculum stresses that mobile malware often enters enterprise environments through sideloaded applications obtained from untrusted sources.
Android devices that allow installation from unknown sources significantly increase organizational risk.
Mobile Device Management (MDM) solutions are recommended to enforce application control policies, including restricting installations to digitally signed applications from approved app stores. By enforcing signed app installation policies, organizations prevent the execution of tampered or malicious APK files.


NEW QUESTION # 57
If the browser does not expire the session when the user fails to logout properly, which of the following OWASP Top 10 web vulnerabilities is caused?

  • A. A7: Cross-site scripting
  • B. A5: Broken access control
  • C. A2: Broken authentication
  • D. A3: Sensitive- data exposure

Answer: C

Explanation:
When a browser does not expire a session after the user fails to logout properly, it is indicative of a vulnerability related to broken authentication. Broken authentication is a security issue where attackers can exploit flaws in the authentication mechanism to impersonate other users or take over their sessions. Failure to properly manage session lifetimes, such as not expiring sessions on logout, can allow an attacker to reuse old sessions or session IDs, potentially gaining unauthorized access to user accounts. This vulnerability is classified under A2: Broken Authentication in the OWASP Top 10, which lists the most critical web application security risks. The OWASP Top 10 serves as a guideline for developers and web application providers to understand and mitigate common security risks.References:The OWASP Top 10 is a widely recognized standard for web application security, often referenced in cybersecurity training and certifications, including the EC-Council's Incident Handler (ECIH v3) curriculum, which covers identification and mitigation of various web application vulnerabilities, including broken authentication.


NEW QUESTION # 58
An AWS user notices unusual activity in their EC2 instances, including unexpected outbound traffic. When suspecting a security compromise, what is the most effective immediate step to take to contain the incident?

  • A. Increase the logging level and monitor network traffic for further anomalies.
  • B. Snapshot the affected instances for forensic analysis and then isolate them using network ACLs.
  • C. Reboot the affected instances to disrupt unauthorized processes.
  • D. Terminate all affected EC2 instances to stop the suspicious activity.

Answer: B

Explanation:
This scenario reflects a suspected cloud workload compromise. The ECIH Cloud Incident Handling module stresses that responders must balance containment, evidence preservation, and service continuity.
Option D is correct because creating snapshots preserves forensic evidence while isolating instances using network ACLs or security groups immediately halts malicious communication.
This approach aligns with ECIH guidance to preserve evidence before destructive actions while still containing the threat.
Option B destroys evidence and hinders investigation. Option C alters system state and may trigger attacker countermeasures. Option A delays containment.
ECIH explicitly warns against terminating or rebooting compromised cloud assets before evidence capture. Snapshot-and-isolate is therefore the most effective immediate containment step.


NEW QUESTION # 59
Rose is an incident-handler and is responsible for detecting and eliminating any kind of scanning attempts over the network by malicious threat actors. Rose uses Wire shark to sniff the network and detect any malicious activities going on.
Which of the following Wireshark filters can be used by her to detect TCP Xmas scan attempt by the attacker?

  • A. tcp.flags==0X 000
  • B. tcp.flags.reset== 1
  • C. tcp.flags==0X 029
  • D. tcp.dstport== 7

Answer: C


NEW QUESTION # 60
Which of the following digital evidence temporarily stored on a digital device that requires a constant power supply and is deleted if the power supply is interrupted?

  • A. Process memory
  • B. Event logs
  • C. Swap file
  • D. Slack space

Answer: A

Explanation:
Process memory, or volatile memory (RAM), is digital evidence that requires a constant power supply to retain data and is deleted or lost when the power supply is interrupted. It contains information about the system's ongoing processes and operations. This type of evidence can be crucial for forensic investigations as it may hold information about user actions, system events, and the state of applications and services at the time of an incident. Unlike swap files, event logs, and slack space, which can retain information without a constant power supply, process memory is inherently volatile and its contents are lost when a device is powered off or restarts.
References:The ECIH v3 certification program includes discussions on digital forensics and the importance of different types of digital evidence, including volatile and non-volatile memory, in the context of incident response and investigation.


NEW QUESTION # 61
Which of the following are malicious software programs that infect computers and corruptor delete the data on them?

  • A. Virus
  • B. Trojans
  • C. Worms
  • D. Spyware

Answer: A


NEW QUESTION # 62
......


Prerequisites

The target candidates for the EC-Council 212-89 exam are the risk assessment administrators, penetration testers, cyber forensic investigators, incident handlers, venerability assessment auditors, firewall administrators, system engineers, network managers, system administrators, IT managers, and other IT professionals looking to gain validation for their skills in incident handling & response.

Please note that you are required to fulfill one prerequisite before going for the exam. You need to complete the ECIH training course, which can be taken as the instructor-led option, academia studying, or online learning. Those candidates who opt for self-study must possess at least one year of practical work experience in the domain of information security. Also, you are required to submit a completed eligibility form to get approval to take the test.

 

Download Exam 212-89 Practice Test Questions with 100% Verified Answers: https://www.bootcamppdf.com/212-89_exam-dumps.html

Share Latest 212-89Test Practice Test Questions, Exam Dumps: https://drive.google.com/open?id=12WyfNmull_o_DDx2TkE5kfMDw6vtYMW6