
Updated May 09, 2026 Verified 212-89 dumps Q&As - 100% Pass
New 2026 Latest Questions 212-89 Dumps - Use Updated EC-COUNCIL Exam
What Is 212-89 Exam?
The questions in the official 212-89 are presented in the form of multiple-choices. Also, there are a total of 100 questions that the applicant needs to finish within 3 hours. You require at least 70% of the score to pass such an exam. In addition, you must have a minimum of 1 year of working experience in the information security domain. To register for the final exam, the candidates have to pay $450 as an eligibility fee. In all, this test is a great way for specialists to demonstrate their skills and knowledge used for appropriate incident handling.
EC-COUNCIL 212-89 (EC Council Certified Incident Handler (ECIH v2)) Certification Exam is a highly respected certification that is recognized worldwide by employers and industry professionals. It is designed for individuals who are responsible for incident handling and response in an organization and covers a wide range of topics related to incident handling. EC Council Certified Incident Handler (ECIH v3) certification demonstrates the candidate's knowledge and skills in incident handling and response, making them a valuable asset to any organization.
NEW QUESTION # 154
A security policy will take the form of a document or a collection of documents, depending on the situation or usage. It can become a point of reference in case a violation occurs that results in dismissal or other penalty. Which of the following is NOT true for a good security policy?
- A. It must be approved by court of law after verifications of the stated terms and facts
- B. It must be enforceable with security tools where appropriate and with sanctions where actual prevention is not technically feasible
- C. It must clearly define the areas of responsibilities of the users, administrators and management
- D. It must be implemented through system administration procedures, publishing of acceptable use guide lines or other appropriate methods
Answer: A
NEW QUESTION # 155
Rachel, a first responder, finds a smartphone in an executive's office that is powered ON and actively displaying a messaging app with potentially incriminating information. She avoids locking the screen or turning off the device, photographs the current display, and collects its charging cable. She then safely packages the device and ensures it is kept charged during transport. What principle is Rachel applying in her evidence handling approach?
- A. Forcing a factory reset to preserve evidence.
- B. Extracting deleted messages from the cache.
- C. Allowing device shutdown to save battery.
- D. Preserving screen-based digital evidence.
Answer: D
Explanation:
Rachel is applying the forensic principle of preserving volatile and screen-based digital evidence, which is a core concept in the ECIH First Response and Digital Forensics modules. When a mobile device is powered on and unlocked, the data visible on the screen-such as messages, timestamps, sender details, and session states-constitutes volatile evidence that may be lost permanently if the device locks, reboots, or powers off.
ECIH guidance instructs first responders to document the live state of a device before any interaction that could alter its condition. Photographing the screen captures evidence that may not be recoverable later due to encryption or session expiration. Maintaining power ensures the device does not enter a locked or encrypted state during transport.
Option A refers to forensic analysis, not first response. Option C would destroy evidence and violates forensic principles. Option D risks loss of volatile data.
Preserving screen-based evidence ensures integrity, admissibility, and continuity of evidence, making Option B correct.
NEW QUESTION # 156
GlobalCorp, a leading software development company, recently launched a cloud-based CRM application.
However, within a week, customers reported unauthorized access incidents. On investigation, it was discovered that the vulnerability was due to improper session management, allowing session fixation attacks.
How should GlobalCorp address this vulnerability?
- A. Implement CAPTCHA on all login pages.
- B. Increase the complexity of user passwords.
- C. Store session IDs in encrypted cookies.
- D. Rotate session tokens after successful login.
Answer: D
Explanation:
Comprehensive and Detailed Explanation (ECIH-aligned):
This scenario involves a session fixation vulnerability, a well-known web application attack where an attacker forces or predicts a session identifier and then tricks a user into authenticating with that session. According to the ECIH web application security module, proper session management is essential to prevent such attacks.
Option B is correct because rotating or regenerating session tokens immediately after successful authentication ensures that any session identifier known to an attacker becomes invalid. This breaks the attack chain inherent in session fixation attacks. ECIH explicitly identifies session regeneration as a primary mitigation control.
Option A helps against automated abuse but does not address session reuse. Option C strengthens authentication but does not prevent session hijacking. Option D improves confidentiality but does not prevent fixation if the same session ID remains valid.
ECIH stresses that authentication and session management must be treated as distinct security controls. Even strong passwords cannot protect against flawed session handling. Therefore, regenerating session tokens post- login is the correct and most effective remediation.
NEW QUESTION # 157
Which of the following is not the responsibility of first responders?
- A. Packaging and transporting the electronic evidence
- B. Preserving temporary and fragile evidence and then shut down or reboot the victim's computer
- C. Protecting the crime scene
- D. Identifying the crime scene
Answer: D
Explanation:
The responsibility of first responders does not include shutting down or rebooting the victim's computer as a measure to preserve temporary and fragile evidence. In fact, such actions can potentially alter or destroy volatile data that could be crucial for the investigation. The primary responsibilities of first responders include protecting and identifying the crime scene, and ensuring the preservation of evidence in its original state as much as possible, which may involve isolating affected systems from the network but not necessarily shutting them down or rebooting them without proper forensic readiness and consideration.
NEW QUESTION # 158
What command does a Digital Forensic Examiner use to display the list of all open ports and the associated IP addresses on a victim computer to identify the established connections on it:
- A. "dd" command
- B. "netstat -an" command
- C. "ifconfig" command
- D. "arp" command
Answer: B
NEW QUESTION # 159
Bran is an incident handler who is assessing the network of the organization. He wants to detect ping sweep attempts on the network using Wireshark. Which of the following Wireshark filters would Bran use to accomplish this task?
- A. icmp.lype==8
- B. icmp.ident
- C. icmp.scq
- D. icmp.redir_gw
Answer: A
NEW QUESTION # 160
David, a certified digital first responder, arrives at the scene of a reported security breach in the HR department of a corporate office. The breach involves multiple digital endpoints, including desktop systems and mobile devices. Upon entering the scene, David observes that one desktop computer is still powered ON and logged in, showing a sensitive financial dashboard on the screen. Realizing the importance of preserving this evidence, David refrains from interacting directly with the keyboard or running applications. Instead, he takes high-resolution photographs of the screen to capture the current session details, including open applications and time-sensitive data. To avoid altering the system state, David gently moves the mouse without clicking, just enough to dismiss a screen saver without triggering any on-screen changes. He records the system's behavior, notes any visible alerts or programs running, and tags all connected cables and peripheral ports for proper documentation. What step in the evidence handling process is David demonstrating?
- A. Preserving volatile evidence from an active system
- B. Executing a shutdown script on Linux
- C. Handling a powered-off device
- D. Seizing off-site backups
Answer: A
Explanation:
Comprehensive and Detailed Explanation (ECIH-aligned):
This scenario demonstrates preservation of volatile evidence, a critical first-response principle in the ECIH forensic readiness module. Volatile evidence includes data that exists only while a system is powered on, such as active sessions, running processes, open files, and on-screen information.
Option B is correct because David documents the live system state without interacting in a way that would alter evidence. Photographing the screen, recording visible activity, and documenting connections are all recommended ECIH practices when dealing with powered-on systems.
Option A is unrelated. Option C alters system state. Option D applies only to inactive devices.
ECIH stresses that mishandling active systems can destroy crucial evidence. David's actions align precisely with first responder best practices, making Option B correct.
NEW QUESTION # 161
Sam received an alert through an email monitoring tool indicating that their company was targeted by a phishing attack. After analyzing the incident, Sam identified that most of the targets of the attack are high-profile executives of the company. What type of phishing attack is this?
- A. Whaling
- B. Pharming
- C. Puddle phishing
- D. Spear phishing
Answer: A
Explanation:
Whaling is a specific type of phishing attack that targets high-profile executives or individuals within an organization, often with the intent to steal sensitive information or gain access to their accounts for financial fraud. The term "whaling" is used because it targets the "big fish" of an organization. Given that Sam identified the targets of the attack as high-profile executives, the described scenario is indicative of a whaling attack.
References:The ECIH v3 curriculum includes a section on different types of phishing attacks, including whaling, emphasizing the strategies attackers use to target individuals based on their roles within an organization.
NEW QUESTION # 162
The state of incident response preparedness that enables an organization to maximize its potential to use digital evidence while minimizing the cost of an investigation is called:
- A. Computer Forensics
- B. Digital Forensic Analysis
- C. Forensic Readiness
- D. Digital Forensic Policy
Answer: C
NEW QUESTION # 163
Ikeo Corp, hired an incident response team to assess the enterprise security. As part of the incident handling and response process, the IR team is reviewing the current security policies implemented by the enterprise.
The IR team finds that employees of the organization do not have any restrictions on Internet access: they are allowed to visit any site, download any application, and access a computer or network from a remote location.
Considering this as the main security threat, the IR team plans to change this policy as it can be easily exploited by attackers. Which of the following security policies is the IR team planning to modify?
- A. Promiscuous policy
- B. Prudent policy
- C. Permissive policy
- D. Paranoic policy
Answer: C
Explanation:
A permissive security policy is one that allows employees broad freedoms in terms of internet access, application downloads, and remote access capabilities. In the scenario described, the incident response team identifies that the lack of restrictions is a significant security threat that could be exploited by attackers, indicating that the current policy is permissive. Modifying this policy would involve implementing more stringent controls on what sites can be visited, what applications can be downloaded, and how remote access is granted, moving towards a more controlled and secure environment. This approach contrasts with paranoic, prudent, and promiscuous policies, each of which has its own characteristics and applications in cybersecurity frameworks.References:The ECIH v3 certification materials often discuss security policies within the context of organizational security posture, emphasizing how varying degrees of restrictiveness impact security and risk.
NEW QUESTION # 164
Lack of forensic readiness may result in:
- A. System downtime
- B. All the above
- C. Data manipulation, deletion, and theft
- D. Loss of clients thereby damaging the organization's reputation
Answer: B
NEW QUESTION # 165
In which of the following types of fuzz testing strategies the new data will be generated from scratch and the amount of data to be generated are predefined based on the testing model?
- A. Log-based fuzz testing
- B. Protocol-based fuzz testing
- C. Mutation-based fuzz testing
- D. Generation-based fuzz testing
Answer: D
Explanation:
Generation-based fuzz testing is a strategy where new test data is generated from scratch based on a predefined model that specifies the structure, type, and format of the input data. This approach is systematic and relies on a deep understanding of the format and protocol of the input data to create test cases that are both valid and potentially revealing of vulnerabilities. This contrasts with mutation-based fuzz testing, where existing data samples are modified (mutated) to produce new test cases, and log-based and protocol-based fuzz testing, which use different approaches to test software robustness andsecurity.References:ECIH v3 certification materials often cover software testing techniques, including fuzz testing, to identify vulnerabilities in applications by inputting unexpected or random data.
NEW QUESTION # 166
Richard is analyzing a corporate network. After an alert in the network's IPS, he identified that all the servers are sending huge amounts of traffic to the website abc.xyz.
What type of information security attack vectors have affected the network?
- A. IOT threats
- B. Ransom ware
- C. Advanced persistent threats
- D. Botnet
Answer: D
NEW QUESTION # 167
Which of the following is host-based evidence?
- A. IDS logs
- B. Router logs
- C. The date and time of the PC
- D. Wiretaps
Answer: C
NEW QUESTION # 168
An attack on a network is BEST blocked using which of the following?
- A. IPS device inline
- B. HIPS
- C. Web proxy
- D. Load balancer
Answer: A
Explanation:
An Intrusion Prevention System (IPS) device placed inline is best suited to block attacks on a network actively. Being inline allows the IPS to analyze and take action on the traffic as it passes through the device, effectively preventing malicious traffic from reaching its target. The IPS can detect and block a wide range of attacks in real-time by using various detection methods, such as signature-based detection, anomaly detection, and policy-based detection. Unlike Host-based Intrusion Prevention Systems (HIPS), web proxies, or load balancers, an inline IPS is specifically designed to inspect and act on incoming and outgoing network traffic to prevent attacks before they reach network devices or applications.
References:The Incident Handler (ECIH v3) certification materials discuss network security controls and emphasize the role of intrusion prevention systems in protecting networks against threats.
NEW QUESTION # 169
Your manager hands you several items of digital evidence and asks you to investigate them in the order of volatility. Which of the following is the MOST volatile?
- A. Emails
- B. Disk
- C. Cache
- D. Temp files
Answer: C
Explanation:
In the context of digital evidence investigation, volatility refers to how quickly data can change or be lost when power is removed or systems are altered. Among the options provided, cache is the most volatile because it is temporary storage that is designed to speed up access to data and is frequently overwritten.
Cache data resides in RAM and includes things like memory buffers, system and network information, and process execution data, which are lost upon reboot or power loss. This contrasts with disks, emails, and temp files, which are considered less volatile because they are stored on permanent or semi-permanent media and are less likely to be immediately lost or overwritten.
References:The Incident Handler (ECIH v3) curriculum includes principles of digital evidence handling, which emphasizes the importance of collecting evidence in descending order of volatility to ensure that the most ephemeral data is preserved before it's lost.
NEW QUESTION # 170
Who is mainly responsible for providing proper network services and handling network-related incidents in all the cloud service models?
- A. Cloud consumer
- B. Cloud service provide
- C. Cloud auditor
- D. Cloud brokers
Answer: B
NEW QUESTION # 171
In which of the following phases of incident handling and response (IH&R) process the identified security incidents are analyzed, validated, categorized, and prioritized?
- A. Incident recording and assignment
- B. Incident triage
- C. Containment
- D. Notification
Answer: B
NEW QUESTION # 172
Risk is defined as the probability of the occurrence of an incident. Risk formulation generally begins with the likeliness of an event's occurrence, the harm it may cause and is usually denoted as Risk = ∑(events)X(Probability of occurrence)X?
- A. Significance
- B. Probability
- C. Consequences
- D. Magnitude
Answer: D
NEW QUESTION # 173
The process of rebuilding and restoring the computer systems affected by an incident to normal operational stage including all the processes, policies and tools is known as:
- A. Incident Handling
- B. Incident Response
- C. Incident Recovery
- D. Incident Management
Answer: C
NEW QUESTION # 174
SafeGuard Inc., a cloud storage company, identified attackers exploiting a Server-Side Request Forgery (SSRF) vulnerability, leading to internal network reconnaissance. Which measure should SafeGuard Inc.
prioritize to mitigate this vulnerability?
- A. Increase monitoring and logging of application activities.
- B. Restrict outbound traffic from the application server.
- C. Disable unused application features and services.
- D. Implement a Content Security Policy (CSP).
Answer: B
Explanation:
SSRF vulnerabilities allow attackers to coerce a server into making unauthorized internal or external requests.
The ECIH Web Application Security module states that controlling outbound traffic is the most effective mitigation against SSRF.
Option D is correct because restricting outbound traffic ensures that even if an SSRF flaw exists, the server cannot access internal resources or attacker-controlled endpoints. ECIH emphasizes network-level egress filtering as a primary defensive control for SSRF.
Option A reduces attack surface but does not stop exploitation. Option B addresses client-side risks, not server-side requests. Option C improves detection but does not prevent exploitation.
Thus, outbound traffic restriction is the priority mitigation measure.
NEW QUESTION # 175
What is the most recent NIST standard for incident response?
- A. 800-171r2
- B. 800-61r2
- C. 800-53r3
- D. 800-61r3
Answer: B
Explanation:
As of my last update, the most recent NIST standard for incident response was NIST Special Publication
800-61 Revision 2 (800-61r2), titled "Computer Security Incident Handling Guide." This document provides guidelines for establishing an effective incident response program, including preparation, detection and analysis, containment, eradication, recovery, and post-incident activity.
References:The document is a key resource in the field of incident response, frequently cited in the ECIH v3 curriculum for its comprehensive guidelines on managing and responding to cybersecurity incidents.
NEW QUESTION # 176
An organization faced an information security incident where a disgruntled employee passed sensitive access
control information to a competitor. The organization's incident response manager, upon investigation, found
that the incident must be handled within a few hours on the same day to maintain business continuity and
market competitiveness. How would you categorize such information security incident?
- A. Low level incident
- B. Ultra-High level incident
- C. Middle level incident
- D. High level incident
Answer: D
NEW QUESTION # 177
Identify Sarbanes-Oxley Act (SOX) Title, which consists of only one section, that includes measures designed to help restore investor confidence in the reporting of securities analysts.
- A. Title VIII: Corporate and Criminal Fraud Accountability
- B. Title VII: Studies and Reports
- C. Title V: Analyst Conflicts of Interest
- D. Title IX: White-Collar-Crime Penalty Enhancement
Answer: C
Explanation:
The Sarbanes-Oxley Act (SOX) Title V, titled "Analyst Conflicts of Interest," contains measures specifically designed to restore investor confidence in the reporting of securities analysts. It addresses the issue of potential conflicts of interest for securities analysts who recommend stocks and other securities by requiring disclosure of certain relationships and financial interests between analysts and the companies they cover. This part of the SOX Act aims to ensure that investors receive unbiased and accurate information from analysts, thereby helping to restore trust in financial markets. Title V consists of only one section, making it unique compared to other titles within the Act that may encompass multiple sections or provisions.References:The Incident Handler (ECIH v3) certification materials might not directly cover the specifics of the Sarbanes-Oxley Act but would underscore the importance of understanding regulatory requirements and compliance, especially in roles involving incident response and information security governance.
NEW QUESTION # 178
A malicious security-breaking code that is disguised as any useful program that installs an executable programs when a file is opened and allows others to control the victim's system is called:
- A. RootKit
- B. Virus
- C. Trojan
- D. Worm
Answer: C
NEW QUESTION # 179
......
Latest 212-89 Exam Dumps EC-COUNCIL Exam from Training: https://itexambus.passleadervce.com/ECIH-Certification/reliable-212-89-exam-learning-guide.html