Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

212-89 Exam Questions & Answers

EC-Council Certified Incident Handler v3  •  Eccouncil

305 Questions 180 min Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample 212-89 Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

Which of the following is an Inappropriate usage incident?

Correct Answer: C
Explanation:

An Inappropriate Usage incident refers to instances where computing resources are misused or abused, often violating organizational policies or laws. While access-control attacks, reconnaissance attacks, and denial-of-service (DoS) attacks represent different types of external threats or methods of attack, an Insider Threat is an example of inappropriate usage. Insider threats come from individuals within the organization, such as employees or contractors, who misuse their access to harm the organization's interests. This can include stealing confidential information, intentionally disrupting systems, or other malicious activities that leverage their legitimate access to the organization's resources.

Q2 MultipleChoice

SWA Cloud Services added PKI as one of their cloud security controls. What does PKI stand for?

Correct Answer: D
Explanation:

Public Key Infrastructure (PKI) is a framework used to manage digital certificates and public-key encryption. It enables secure electronic transfer of information for a range of network activities such as e-commerce, internet banking, and confidential email. PKI is fundamental to the management of encryption keys and digital certificates, ensuring the secure exchange of data over networks and verification of identity.

Q3 MultipleChoice

Raven is a part of an IH&R team and was informed by her manager to handle and lead the removal of the root cause for an incident and to close all attack vectors to prevent similar incidents in the future. Raven notifies the service providers and developers of affected resources. Which of the following steps of the incident handling and response process does Raven need to implement to remove the root cause of the incident?

Correct Answer: B
Explanation:

Eradication is the step in the incident handling and response process where the root cause of an incident is removed, and measures are taken to close all attack vectors to prevent similar incidents in the future. After an incident has been properly contained to stop it from spreading or causing further damage, the eradication phase focuses on eliminating the source of the incident. This could involve removing malware, closing vulnerabilities, or implementing stronger security measures to address the exploitation paths used by the attacker.

In the scenario with Raven, notifying service providers and developers of affected resources is part of the actions taken to address the root cause of the incident. This ensures that any vulnerabilities or issues that contributed to the incident are fixed. By working to remove the root cause and secure the system against similar attacks, Raven is effectively implementing the eradication step of the incident handling process.

Q4 MultipleChoice

Sam. an employee of a multinational company, sends emails to third-party organizations with a spoofed email address of his organization. How can you categorize this type of incident?

Correct Answer: B
Explanation:

An inappropriate usage incident involves misuse of the organization's resources or violations of its acceptable use policies. Sam's actions, where he sends emails to third-party organizations with a spoofed email address of his employer, constitute misuse of the organization's email system and misrepresentation of the organization. This behavior can harm the organization's reputation, violate policy, and potentially lead to legal consequences. Inappropriate usage incidents can range from unauthorized use of systems for personal gain to the dissemination of unapproved content.

Q5 MultipleChoice

Zoe, a security analyst, deploys a high-interaction honeypot in the DMZ that mimics critical systems and monitors logs for scans, exploit attempts, and lateral movement techniques. What is the main purpose of Zoe's activity?

Correct Answer: A
Explanation:

Explanation (aligned to threat intelligence & detection):

A high-interaction honeypot is designed to attract and engage adversaries, providing realistic services so defenders can observe tactics, techniques, and procedures (TTPs) with higher fidelity than a low-interaction decoy. The goal is not to ''stop'' attacks directly, but to detect and learn: identify scanning patterns, credential stuffing attempts, exploit chains, payload delivery methods, and post-exploitation behaviors such as enumeration and lateral movement. That intelligence is then used to improve controls---signatures, detections, segmentation, and hardening priorities.

Sandboxing (B) is typically about detonating suspicious files/URLs to observe behavior in a controlled environment; it's not what a DMZ honeypot primarily does. ACL rules and DDoS blocking (C) are traffic filtering measures, not deception telemetry. Backup/recovery testing (D) is resilience planning, unrelated to studying attacker behavior in real-time.

In incident handling terms, honeypots support the ''preparation'' and ''detection'' posture---expanding visibility, generating early warning, and enriching threat intelligence. They can also reduce risk by luring opportunistic attackers away from production assets, but their primary value is behavioral observation and evidence collection.

Get access to all 305 verified questions with detailed answers.

Unlock All 212-89 Questions

Frequently Asked Questions

The 212-89 is an EC-Council certification that validates professional competency in incident handling and response. It covers skills needed to detect, respond to, and manage security incidents effectively in an organization.

While there are no strict formal prerequisites, EC-Council recommends having basic networking and security knowledge. Some candidates pursue the CEH (Certified Ethical Hacker) certification first, though it is not mandatory for the ECIH exam.

The exam covers incident handling phases, incident response procedures, forensics, malware analysis, and compliance frameworks. It also includes topics on detection techniques, containment strategies, and post-incident activities.

The exam typically consists of 100 multiple-choice questions that must be completed within 4 hours. Candidates generally need to achieve a passing score of around 70-75% to earn the certification, though exact requirements may vary.

EC-Council certifications are typically valid for three years from the date of certification. After expiration, candidates must renew their certification through retesting or by completing continuing education requirements.
Exam Details
  • Exam Code212-89
  • VendorEccouncil
  • Total Questions305
  • Duration180 min
  • LanguageEnglish
  • Version3
  • Last UpdatedSep 1, 2026
4.9/5

Pass 212-89 First Time

Get all 305 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals