Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free EC-Council EC-Council Certified Incident Handler 212-89 Exam Questions

Page: 1 / 24 Total 356 questions

Want more questions? Get Premium Access.

Question 1

After unearthing malware within their AI-based prediction systems, Future Tech Corp realized that their business projections were skewed. This malware was not just altering data but was equipped with machine learning capabilities, evolving its methods. With access to a dedicated AI security module and a database restoration tool, what's the primary step?

Correct Answer: B. Deploy the AI-security module to counteract and remove the evolved malware.
Explanation:

This incident involves adaptive malware embedded within an AI system, actively evolving its behavior. The ECIH malware incident handling methodology prioritizes containment and eradication of the threat before recovery actions. Restoring data without removing the malware risks immediate reinfection and continued manipulation.

Option B is correct because deploying the AI-security module directly targets the malware's adaptive mechanisms, allowing responders to detect, contain, and eradicate the malicious logic within the AI environment. ECIH emphasizes using appropriate, context-aware security controls that match the technology stack involved in the incident. For AI-driven environments, specialized tools are necessary to counter threats that traditional controls may not detect.

Option A is premature and unsafe prior to eradication. Option C disrupts business operations without resolving the threat. Option D is a communication step that should follow containment and validation.

Therefore, neutralizing the evolved malware using the AI-security module is the correct primary step.


Question 2

Dan is a newly appointed information security professional in a renowned organization. He is supposed to follow multiple security strategies to eradicate malware incidents. Which of the following is not considered as a good practice for maintaining information security and eradicating malware incidents?

Correct Answer: D. Do not download or execute applications from trusted sources
Explanation:

The statement 'Do not download or execute applications from trusted sources' is incorrect and not considered a good practice for maintaining information security and eradicating malware incidents. In contrast, downloading or executing applications from trusted sources is a fundamental security best practice. Trusted sources are vetted and are generally considered safe for downloading software, updates, and applications. This practice helps to minimize the risk of introducing malware into the organizational environment. The other options (A, B, C) represent good practices that help in reducing the likelihood of malware infections by avoiding potentially harmful actions.


Question 3

Mr. Smith is a lead incident responder of a small financial enterprise having few

branches in Australia. Recently, the company suffered a massive attack losing USD 5

million through an inter-banking system. After in-depth investigation on the case, it was

found out that the incident occurred because 6 months ago the attackers penetrated the

network through a minor vulnerability and maintained the access without any user

being aware of it. Then, he tried to delete users' fingerprints and performed a lateral

movement to the computer of a person with privileges in the inter-banking system.

Finally, the attacker gained access and did fraudulent transactions.

Based on the above scenario, identify the most accurate kind of attack.

Correct Answer: C. APT attack
Explanation:

The scenario described fits the characteristics of an Advanced Persistent Threat (APT) attack. APTs are sophisticated, stealthy, and continuous computer hacking processes often orchestrated by groups targeting a specific entity. These attackers penetrate the network through vulnerabilities, maintain access without detection, and achieve their objectives, such as data exfiltration or financial theft, over an extended period. The fact that attackers exploited a minor vulnerability, maintained access for six months, and performed lateral movements to access critical systems for fraudulent transactions highlights the strategic planning and persistence typical of APT attacks.


Question 4

A mid-sized healthcare organization undergoing digital modernization is working toward ISO/IEC 27001 certification. During a readiness review, the CISO identifies gaps: staff lack clear channels to raise concerns about system weaknesses, outcome tracking after adverse events is inconsistent, and there is no formalized way to assess what went right or wrong following disruptions. To comply with ISO/IEC 27001 Annex A.16, which action should be prioritized?

Correct Answer: C. Define and implement structured procedures for flaw escalation and integrating post-incident response knowledge.
Explanation:

ISO/IEC 27001 Annex A.16 focuses on information security incident management, including reporting, assessment, response, and learning. The ECIH curriculum aligns closely with these requirements, emphasizing structured procedures and continuous improvement.

Option C is correct because it directly addresses the identified gaps: clear escalation channels, consistent outcome tracking, and incorporation of lessons learned. ECIH stresses that post-incident activities---often overlooked---are essential for improving readiness and preventing recurrence.

Option A supports preparedness but does not address systemic process gaps. Option B improves visibility but not governance. Option D is a technical control unrelated to incident learning and escalation.

Thus, implementing structured incident escalation and post-incident knowledge integration is the priority action for compliance and resilience.


Question 5

Smith employs various malware detection techniques to thoroughly examine the

network and its systems for suspicious and malicious malware files. Among all

techniques, which one involves analyzing the memory dumps or binary codes for the

traces of malware?

Correct Answer: D. Static analysis
Explanation:

Static analysis involves examining the malware's memory dumps or binary codes without executing the code. This technique is used to find traces of malware by analyzing the code to understand its purpose, functionality, and potential impact. Static analysis allows for the identification of malicious signatures, strings, or other indicators of compromise within the malware's code. This method is contrasted with dynamic analysis, which studies the malware's behavior during execution, live system analysis, which examines running systems, and intrusion analysis, which focuses on detecting and analyzing breaches.


Question 6

Chandler is a professional hacker who is targeting Technote organization. He wants to obtain important organizational information that is being transmitted between

different hierarchies. In the process, he is sniffing the data packets transmitted through the network and then analyzing them to gather packet details such as network, ports,

protocols, devices, issues in network transmission, and other network specifications. Which of the following tools Chandler must employ to perform packet analysis?

Correct Answer: C. Omnipeek
Explanation:

Omnipeek is a network analyzer tool that allows for the capture and analysis of data packets transmitted across a network. It is designed to provide deep insights into network traffic, enabling users to examine various aspects of the data packets, including network protocols, ports, devices, and potential issues in network transmission. This tool would be ideal for Chandler, who is targeting the Technote organization with the intent of intercepting and analyzing network traffic to obtain sensitive organizational information. Omnipeek's capabilities in packet analysis make it suitable for such activities, offering detailed visibility into the network's operation and data flows.


Question 7

The following steps describe the key activities in forensic readiness planning:

1. Train the staff to handle the incident and preserve the evidence

2. Create a special process for documenting the procedure

3. Identify the potential evidence required for an incident

4. Determine the source of the evidence

5. Establish a legal advisory board to guide the investigation process

6. Identify if the incident requires full or formal investigation

7. Establish a policy for securely handling and storing the collected evidence

8. Define a policy that determines the pathway to legally extract electronic evidence

with minimal disruption

Identify the correct sequence of steps involved in forensic readiness planning.

Correct Answer: B. 3-->4-->8-->7-->6-->1-->2-->5
Explanation:

The correct sequence of steps involved in forensic readiness planning, based on the activities described, is as follows:

Identify the potential evidence required for an incident.

Determine the source of the evidence.

Define a policy that determines the pathway to legally extract electronic evidence with minimal disruption.

Establish a policy for securely handling and storing the collected evidence.

Identify if the incident requires full or formal investigation.

Train the staff to handle the incident and preserve the evidence.

Create a special process for documenting the procedure.


Question 8

Following a spear-phishing campaign targeting executive-level employees, a mid-sized financial firm experienced unauthorized access to internal systems, leading to widespread disruption of customer-facing applications. Although the technical issues were resolved within days, the breach triggered legal scrutiny and negative press coverage. Several major customers expressed concern about the firm's risk posture and began transitioning to competitors. Investor confidence was impacted as the stock value dipped, and senior leadership initiated a damage control campaign. Which of the following best categorizes the broader consequences experienced by the organization?

Correct Answer: C. Intangible business effects involving stakeholder defection and public image decline.
Explanation:

The scenario describes consequences extending beyond technical remediation into reputational, financial, and stakeholder trust impacts. According to ECIH risk assessment and post-incident analysis guidance, these outcomes are classified as intangible business effects.

Option C is correct because customer loss, investor confidence decline, and reputational damage cannot be easily quantified yet often exceed direct incident response costs. ECIH emphasizes that post-incident reviews must consider both tangible and intangible impacts to accurately assess business risk.

Options A, B, and D describe operational or technical impacts, which were resolved quickly in this scenario. The lasting damage occurred at the business and market perception level.

Understanding intangible impacts is critical for executive reporting, risk management, and long-term resilience planning, making Option C correct.


Question 9

An attacker after performing an attack decided to wipe evidences using artifact wiping techniques to evade forensic investigation. He applied magnetic field to the digital

media device, resulting in an entirely clean device of any previously stored data.

Identify the artifact wiping technique used by the attacker.

Correct Answer: B. Disk degaussing/destruction
Explanation:

The technique described, where an attacker applies a magnetic field to a digital media device to clean it of any previously stored data, is known as disk degaussing. Degaussing is a method used to erase a disk or tape by exposing it to a strong magnetic field, destroying the magnetic data storage mechanism and leaving the device clean of any data. This process is effectively used for wiping digital evidence in a way that makes recovery impossible, serving as a method of anti-forensics. Unlike file wiping utilities or disk cleaning utilities, which overwrite or delete data (potentially leaving traces that can be recovered), degaussing physically alters the storage medium itself, making data recovery unfeasible.


Question 10

Which of the following options describes common characteristics of phishing emails?

Correct Answer: C. Urgency, threatening, or promising subject lines
Explanation:

Phishing emails often share common characteristics designed to manipulate the recipient into taking immediate action. One of the hallmark features is the use of urgency, threatening language, or promising subject lines in the emails. These tactics are intended to create a sense of urgency or fear, compelling the recipient to respond quickly without giving due consideration to the legitimacy of the email. Phishing emails may claim that the recipient's account has been compromised, that they need to confirm personal information immediately, or that they have won a prize. The goal is to trick the recipient into clicking on malicious links, opening attachments, or providing sensitive information.


Question 11

A large insurance enterprise recently completed an internal phishing simulation to evaluate its incident reporting workflow. Upon reviewing the ticketing system logs, the IR lead discovered that several phishing-related reports submitted by employees had been mistakenly logged as routine IT service requests. This misrouting prevented timely review by the IH&R team, delaying appropriate follow-up actions.

The root cause was traced to frontline support staff misinterpreting subtle incident indicators as generic technical issues. Recognizing the potential risk this poses to early issue detection, the Chief Information Security Officer directed an overhaul of the alert-handling procedures. This included refining the reporting workflow, embedding clearer triage rules within the ticketing platform, and initiating refresher training to strengthen tier-one decision-making when handling ambiguous user reports. Which IR concern is being addressed through this corrective action?

Correct Answer: C. Improving accuracy in initial threat categorization and escalation
Explanation:

The EC-Council Incident Handler (ECIH) curriculum highlights the importance of accurate triage and incident categorization during the detection and analysis phase. Misclassification of security events as routine IT issues delays escalation and increases risk exposure.

In this case, phishing reports were incorrectly logged as service requests due to poor triage decision-making by frontline staff. The corrective measures---refining workflows, embedding clearer triage rules, and providing refresher training---directly target improving the accuracy of initial threat identification and proper escalation to the IH&R team.

ECIH stresses that effective incident response depends on well-defined classification procedures, escalation criteria, and trained personnel capable of recognizing subtle security indicators. Early detection and proper routing significantly reduce dwell time and potential impact.

Option A concerns asset tracking, not incident triage. Option B relates to containment, not categorization. Option D addresses alert fatigue, which is not the root issue described.

Therefore, the corrective action addresses improving accuracy in initial threat categorization and escalation.


Question 12

An organization suffers a financial loss after an executive responds to a fraudulent email crafted as part of a spear phishing attack. After isolating affected systems and notifying internal stakeholders, the incident response team prepares a detailed report outlining the attack timeline, suspicious IP addresses, email metadata, phone scam details, and the amount lost. This report is forwarded to a government agency specializing in cybercrime to aid further investigation and potential restitution. Which aspect of the recovery process is the organization addressing?

Correct Answer: A. Legal escalation and investigation support
Explanation:

This scenario reflects the post-incident recovery and reporting phase outlined in the ECIH curriculum. After containment and eradication, organizations must address legal, regulatory, and investigative requirements, especially when financial fraud and executive compromise are involved.

Option A is correct because forwarding detailed incident reports to a government cybercrime agency constitutes legal escalation and investigation support. ECIH stresses the importance of cooperation with law enforcement in cases involving fraud, financial loss, or cross-border criminal activity. Proper documentation supports potential prosecution, restitution efforts, and regulatory compliance.

Options B, C, and D are technical recovery actions unrelated to legal follow-up.

By engaging authorities with verified evidence, the organization fulfills its recovery obligations beyond technical remediation, aligning with ECIH best practices.


Question 13

Which of the following does NOT reduce the success rate of SQL injection?

Correct Answer: A. Close unnecessary application services and ports on the server.
Explanation:

Reducing the success rate of SQL injection attacks is focused on minimizing vulnerabilities within the application's database interactions, rather than the broader server or network services. SQL injection prevention techniques typically involve input validation, parameterized queries, and the use of stored procedures, rather than changes to the network or server configuration.

A) Closing unnecessary application services and ports on the server is a general security best practice to reduce the attack surface but does not directly impact the success rate of SQL injection attacks. This action limits access to potential vulnerabilities across the network and server but doesn't address the specific ways SQL injection exploits input handling within web applications.

B) Automatically locking a user account after a predefined number of invalid login attempts within a predefined interval can help mitigate brute force attacks but has no direct effect on preventing SQL injection, which exploits code vulnerabilities to manipulate database queries.

C) Constraining legitimate characters to exclude special characters and D) Limiting the length of the input field are both direct methods to reduce the risk of SQL injection. They focus on controlling user input, which is the vector through which SQL injection attacks are launched. By restricting special characters that could be used in SQL commands and limiting input lengths, an application can reduce the potential for malicious input to form a part of SQL queries executed by the backend database.


Question 14

A national healthcare organization with multiple branches is facing growing cybersecurity challenges due to unmanaged systems, inconsistent configurations, and a lack of asset visibility. In response, leadership has asked the security team to implement a proactive strategy aimed at minimizing exposure across all departments. This includes identifying hardware and software in use, enforcing consistent security settings, and establishing a routine process to detect system weaknesses before they can be exploited.

The security team is seeking a well-established, practical framework that emphasizes prioritized, real-world security practices and can be implemented efficiently with available resources. Which of the following frameworks would BEST support this proactive security initiative?

Correct Answer: A. Employing CIS Critical Security Controls for foundational defensive actions
Explanation:

The EC-Council Incident Handler (ECIH) curriculum highlights the importance of proactive security controls, asset management, configuration management, and vulnerability management as foundational elements of forensic readiness and incident prevention.

The scenario describes challenges related to unmanaged systems, inconsistent configurations, and lack of asset visibility---core issues addressed by the CIS Critical Security Controls (CIS CSC). The CIS Controls provide prioritized, actionable cybersecurity best practices designed to mitigate the most common attack vectors. These include inventory and control of hardware assets, inventory and control of software assets, secure configuration of enterprise assets, continuous vulnerability management, and controlled use of administrative privileges.

ECIH emphasizes that organizations must first establish visibility into assets and enforce baseline security configurations to reduce attack surfaces. The CIS framework is specifically designed for practical implementation, making it ideal for organizations seeking efficient deployment using available resources.

Option B (NIST 800-61) focuses on incident response lifecycle management, not proactive exposure reduction. Option C (ITIL) focuses on IT service management and service restoration, not cybersecurity hardening. Option D (COBIT) provides high-level governance and enterprise control objectives but does not offer the hands-on, prioritized technical safeguards described in the scenario.

Therefore, consistent with ECIH guidance on preventive controls and security baselining, the CIS Critical Security Controls framework is the best fit for implementing proactive, real-world defensive measures.


Question 15

Which of the following is a volatile evidence collecting tool?

Correct Answer: A. Netstat
Explanation:

Netstat (network statistics) is a command-line tool that displays network connections (both incoming and outgoing), routing tables, and a number of network interface (and network protocol) statistics. It is considered a volatile evidence collecting tool because it gathers information that exists in the system's memory, which is lost upon shutdown or reboot. This makes it invaluable for collecting evidence of active connections and processes that are present at the time of the incident response but does not persistently store data that can be recovered later. This contrasts with tools like FTK Imager or ProDiscover Forensics, which are used for acquiring digital evidence in a non-volatile manner, such as disk imaging, and HashTool, which is used for validating the integrity of collected digital evidence through hashing.