Guaranteed Accomplishment with Newest Mar-2026 FREE EC-COUNCIL 212-89 [Q134-Q159]

Share

Guaranteed Accomplishment with Newest Mar-2026 FREE EC-COUNCIL 212-89

Use Valid New Free 212-89 Exam Dumps & Answers


The EC-Council Certified Incident Handler (ECIH v2) certification exam is designed to test the knowledge and skills of individuals who respond to and handle computer security incidents. 212-89 exam covers a range of topics including incident handling process, communication skills, vulnerability assessment, and threat intelligence. EC Council Certified Incident Handler (ECIH v3) certification is highly valued in the industry as it indicates that the individual has the necessary skills to handle security incidents effectively.

 

NEW QUESTION # 134
A multinational SaaS provider detects a major security breach involving unauthorized access to customer billing data in its EU and APAC servers. After triage and legal review, the IH&R team confirms data exfiltration impacting regulated regions. In response, the CISO, with legal and compliance teams, initiates a structured communication protocol-informing affected clients, notifying data protection authorities under laws such as GDPR, and preparing media responses with public affairs. All communications are securely routed, reviewed for legal accuracy, and sent only with executive approval to mitigate risk and misinformation. What type of communication is emphasized in this scenario?

  • A. External communication intended for non-organizational entities
  • B. Containment communications shared during malware removal
  • C. Automated alert forwarding using SIEM-generated rules
  • D. Technical internal update focused on root cause analysis

Answer: A

Explanation:
The EC-Council Incident Handler (ECIH) curriculum outlines structured communication protocols as a critical part of incident management, particularly when regulated data and external stakeholders are involved.
When data breaches affect customers and fall under regulatory frameworks such as GDPR, organizations are legally required to notify affected individuals and data protection authorities within defined timelines.
The scenario describes communication with clients, regulatory authorities, and media representatives. These stakeholders are external to the organization. ECIH categorizes this as external communication, which must be carefully coordinated with legal, compliance, and executive leadership to ensure accuracy and regulatory compliance.
ECIH emphasizes that external communication must be controlled, legally reviewed, approved by executive leadership, and aligned with regulatory requirements to prevent misinformation and reduce reputational damage. This differs from internal updates or automated alerts.
Option A refers to automated technical notifications. Option C focuses on internal analysis discussions.
Option D relates to operational containment communications during malware handling.
Therefore, the scenario emphasizes structured external communication intended for non-organizational entities.


NEW QUESTION # 135
Which of the following is not a best practice to eliminate the possibility of insider attacks?

  • A. Always leave business details over voicemail or email messages
  • B. Disabling users from install ng unauthorized software or accessing malicious websites using the corporate network
  • C. Implementing secure backup and disaster recovery processes for business continuity
  • D. Monitoring employee behaviors and computer systems used by employees

Answer: C


NEW QUESTION # 136
Your manager hands you several items of digital evidence and asks you to investigate them in the order of volatility. Which of the following is the MOST volatile?

  • A. Cache
  • B. Disk
  • C. Temp files
  • D. Emails

Answer: A

Explanation:
In the context of digital evidence investigation, volatility refers to how quickly data can change or be lost when power is removed or systems are altered. Among the options provided, cache is the most volatile because it is temporary storage that is designed to speed up access to data and is frequently overwritten. Cache data resides in RAM and includes things like memory buffers, system and network information, and process execution data, which are lost upon reboot or power loss. This contrasts with disks, emails, and temp files, which are considered less volatile because they are stored on permanent or semi-permanent media and are less likely to be immediately lost or overwritten.References:The Incident Handler (ECIH v3) curriculum includes principles of digital evidence handling, which emphasizes the importance of collecting evidence in descending order of volatility to ensure that the most ephemeral data is preserved before it's lost.


NEW QUESTION # 137
Raven is a part of an IH&R team and was info med by her manager to handle and lead the removal of the root cause for an incident and to close all attack vectors to prevent similar incidents in the future. Raven notifies the service providers and developers of affected resources.
Which of the following steps of the incident handling and response process does Raven need to implement to remove the root cause of the incident?

  • A. Evidence gathering and forensic analysis
  • B. Eradication
  • C. Incident triage
  • D. Containment

Answer: B


NEW QUESTION # 138
A colleague wants to minimize their security responsibility because they are in a small organization. They are evaluating a new application that is offered in different forms. Which form would result in the least amount of responsibility for the colleague?

  • A. On-prom installation
  • B. laaS
  • C. saaS
  • D. PaaS

Answer: C

Explanation:
Software as a Service (SaaS) offers the least amount of security responsibility for the end-user or organization, as the service provider manages the underlying infrastructure, software maintenance, security patching, and updates. Choosing a SaaS application means the colleague's organization would not be responsible for the physical servers, operating systems, or the application's security configurations, making it the best option for minimizing their security responsibilities.
References:In the Certified Incident Handler (ECIH v3) course materials, the various cloud service models (IaaS, PaaS, SaaS) are discussed with a focus on their implications for security responsibilities and management.


NEW QUESTION # 139
Rachel, a first responder, finds a smartphone in an executive's office that is powered ON and actively displaying a messaging app with potentially incriminating information. She avoids locking the screen or turning off the device, photographs the current display, and collects its charging cable. She then safely packages the device and ensures it is kept charged during transport. What principle is Rachel applying in her evidence handling approach?

  • A. Extracting deleted messages from the cache.
  • B. Allowing device shutdown to save battery.
  • C. Forcing a factory reset to preserve evidence.
  • D. Preserving screen-based digital evidence.

Answer: D

Explanation:
Rachel is applying the forensic principle of preserving volatile and screen-based digital evidence, which is a core concept in the ECIH First Response and Digital Forensics modules. When a mobile device is powered on and unlocked, the data visible on the screen-such as messages, timestamps, sender details, and session states-constitutes volatile evidence that may be lost permanently if the device locks, reboots, or powers off.
ECIH guidance instructs first responders to document the live state of a device before any interaction that could alter its condition. Photographing the screen captures evidence that may not be recoverable later due to encryption or session expiration. Maintaining power ensures the device does not enter a locked or encrypted state during transport.
Option A refers to forensic analysis, not first response. Option C would destroy evidence and violates forensic principles. Option D risks loss of volatile data.
Preserving screen-based evidence ensures integrity, admissibility, and continuity of evidence, making Option B correct.


NEW QUESTION # 140
The service organization that provides 24x7 computer security incident response services to any user, company, government agency, or organization is known as:

  • A. Digital Forensics Examiner
  • B. Vulnerability Assessor
  • C. Security Operations Center SOC
  • D. Computer Security Incident Response Team CSIRT

Answer: D


NEW QUESTION # 141
Introduction of malicious programs on to the device connected to the campus network (Trojan Horse, email bombs, virus, etc.) is called?

  • A. Network Access
  • B. Inappropriate Usage
  • C. Authorize Access
  • D. Un authorize Access

Answer: A


NEW QUESTION # 142
After deploying a new application on Google Cloud Platform (GCP), a security engineer discovers that an unauthorized entity has been accessing the application's backend services. Which of the following measures should the engineer take first to address this security incident?

  • A. Review IAM roles and permissions for excessive access and tighten security controls.
  • B. Use VPC Service Controls to create a secure perimeter around the affected services.
  • C. Enable Google Cloud's Security Command Center to detect future threats.
  • D. Migrate the application services to a different GCP project with stronger security settings.

Answer: A

Explanation:
Unauthorized access to backend services in a cloud environment most commonly results from overly permissive identity and access management (IAM) configurations. The ECIH cloud incident handling guidance emphasizes that identity controls are the primary security boundary in cloud platforms.
Option A is correct because reviewing and tightening IAM roles immediately reduces the attack surface and revokes excessive privileges that may be exploited. This action directly addresses the root cause of unauthorized access.
Option D is a strong additional control but should be applied after correcting IAM misconfigurations. Option B improves future detection but does not contain the current incident. Option C is disruptive and unnecessary as a first response.
Therefore, IAM review and privilege tightening is the correct first measure, consistent with ECIH best practices.


NEW QUESTION # 143
Adam is an incident handler who intends to use DBCC LOG command to analyze a database and retrieve the active transaction log files for the specified database. The syntax of DBCC LOG command is DBCC LOG(, ), where the output parameter specifies the level of information an incident handler wants to retrieve. If Adam wants to retrieve the full information on each operation along with the hex dump of a current transaction row, which of the following output parameters should Adam use?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

Explanation:
The DBCC LOG command is used in SQL Server environments to analyze the transaction log files of a database. It provides insights into the transactions that have occurred, which is crucial for forensic analysis in the event of an incident. The syntaxDBCC LOG(<database_name>, <output_level>)allows an incident handler to specify the level of detail they wish to retrieve from the log files. When an incident handler like Adam requires the full information on each operation along with the hex dump of the current transaction row, the output parameter should be set to 4. This level of output is the most verbose, providing comprehensive details about each transaction, including a hex dump which is essential for a deep forensic analysis. It helps in understanding the exact changes made by transactions, which can be pivotal in investigating incidents involving data manipulation or other unauthorized database activities.
References:EC-Council's Certified Incident Handler (ECIH v3) program emphasizes the importance of understanding and utilizing various tools and commands for forensic analysis, including how to use the DBCC LOG command for transaction log analysis in SQL Server environments.


NEW QUESTION # 144
Your company holds a large amount of customer PH. and you want to protect those data from theft or unauthorized modification. Among other actions, you classify and encrypt the dat a. In this process, which of the following OWASP security risks are you guarding against?

  • A. Insecure deserialization
  • B. Broken authentication
  • C. Sensitive data exposure
  • D. Security misconfiguration

Answer: C


NEW QUESTION # 145
SafePay, an online payment portal, recently introduced an advanced search feature. A week later, users reported unauthorized transactions. Investigation showed attackers exploited advanced search strings and a previously unidentified vulnerability. What is SafePay's best immediate action?

  • A. Disable the advanced search feature and revert to the older version.
  • B. Implement multi-factor authentication for all user accounts.
  • C. Increase the encryption level of stored user data.
  • D. Require users to re-authenticate before accessing advanced search.

Answer: A

Explanation:
This scenario describes an active exploitation of a vulnerable application feature. The ECIH Web Application Incident Handling module emphasizes that when a specific feature is being abused, immediate containment requires removing or disabling that attack surface.
Option B is correct because disabling the vulnerable advanced search feature immediately stops further exploitation while allowing the team to analyze and remediate the flaw safely. ECIH warns against leaving known-vulnerable functionality active during investigation.
Options A and C improve authentication but do not stop exploitation of backend logic. Option D protects stored data but does not prevent further abuse.
Therefore, disabling the exploited feature is the best immediate action.


NEW QUESTION # 146
Stenley is an incident handler working for Texa Corp. located in the United States. With the growing concern of increasing emails from outside the organization, Stenley was asked to take appropriate actions to keep the security of the organization intact. In the process of detecting and containing malicious emails, Stenley was asked to check the validity of the emails received by employees.
Identify the tools he can use to accomplish the given task.

  • A. PoliteMail
  • B. PointofMail
  • C. Email Dossier
  • D. EventLog Analyzer

Answer: C

Explanation:
Email Dossier is a tool designed to perform detailed investigations on email messages to verify their authenticity and trace their origin. It can analyze email headers and provide information about the route an email has taken, the servers it passed through, and potentially malicious links or origins. For an incident handler like Stenley, tasked with verifying the validity of emails and containing malicious email threats, Email Dossier serves as a practical tool for analyzing and validating emails received by employees. By using this tool, Stenley can identify fraudulent or suspicious emails, thereby helping to protect the organization from phishing attacks, malware distribution, and other email-based threats.
References:In the context of managing and mitigating the risks associated with email communications, ECIH v3 study materials outline various tools and techniques for email analysis and validation. These resources recommend the use of tools like Email Dossier for incident handlers to effectively scrutinize incoming emails for security threats.


NEW QUESTION # 147
Alexis works as an incident responder at XYZ organization. She was asked to identify and attribute the actors behind an attack that occurred recently. For this purpose, she is performing a type of threat attribution that deals with the identification of a specific person, society, or country sponsoring a well-planned and executed intrusion or attack on its target. Which of the following types of threat attributions is Alexis performing?

  • A. True attribution
  • B. Nation-state attribution
  • C. Campaign attribution
  • D. Intrusion set attribution

Answer: B


NEW QUESTION # 148
A computer Risk Policy is a set of ideas to be implemented to overcome the risk associated with computer security incidents. Identify the procedure that is NOT part of the computer risk policy?

  • A. Procedure for the ongoing training of employees authorized to access the system
  • B. Provisions for continuing support if there is an interruption in the system or if the system crashes
  • C. Procedure to identify security funds to hedge risk
  • D. Procedure to monitor the efficiency of security controls

Answer: A


NEW QUESTION # 149
Overall Likelihood rating of a Threat to Exploit a Vulnerability is driven by :

  • A. Nature of the vulnerability
  • B. All the above
  • C. Existence and effectiveness of the current controls
  • D. Threat-source motivation and capability

Answer: B


NEW QUESTION # 150
During routine checks, EduSoft, an educational software provider, identified malware within their digital examination tools. This malware not only provided answers to students but mined personal data. With a digital forensic tool and an encryption protocol tool, what's the ideal primary action?

  • A. Disable the examination tool until further notice.
  • B. Use the forensic tool to ascertain the malware's source and method of operation.
  • C. Alert educational institutions about the compromised software.
  • D. Deploy the encryption tool to safeguard students' data.

Answer: B

Explanation:
Once malware is identified, ECIH guidance requires responders to analyze before eradication to understand scope, infection vectors, persistence mechanisms, and data impact. This ensures effective removal and prevents reinfection.
Option C is correct because forensic analysis allows investigators to determine how the malware entered the system, what data was accessed, and whether additional components are compromised. Without this understanding, containment and recovery efforts may be incomplete or ineffective.
Option A is a containment step but does not address root cause. Option B is a notification step that must be supported by verified facts. Option D protects future data but does not address the active malware.
Therefore, forensic analysis is the ideal primary action following detection, as emphasized in the ECIH malware handling process.


NEW QUESTION # 151
An incident is analyzed for its nature, intensity and its effects on the network and systems. Which stage of the
incident response and handling process involves auditing the system and network log files?

  • A. Incident recording
  • B. Reporting
  • C. Containment
  • D. Identification

Answer: D


NEW QUESTION # 152
Spyware tool used to record malicious user's computer activities and keyboard stokes is called:

  • A. Rootkit
  • B. Firewall
  • C. Keylogger
  • D. adware

Answer: C


NEW QUESTION # 153
The following steps describe the key activities in forensic readiness planning:
1. Train the staff to handle the incident and preserve the evidence
2. Create a special process for documenting the procedure
3. Identify the potential evidence required for an incident
4. Determine the source of the evidence
5. Establish a legal advisory board to guide the investigation process
6. Identify if the incident requires full or formal investigation
7. Establish a policy for securely handling and storing the collected evidence
8. Define a policy that determines the pathway to legally extract electronic evidence with minimal disruption Identify the correct sequence of steps involved in forensic readiness planning.

  • A. 1-->2-->3-->4-->5-->6-->7-->8
  • B. 3-->1-->4-->5-->8-->2-->6-->7
  • C. 3-->4-->8-->7-->6-->1-->2-->5
  • D. 2-->3-->1-->4-->6-->5-->7-->8

Answer: C

Explanation:
The correct sequence of steps involved in forensic readiness planning, based on the activities described, is as follows:
* Identify the potential evidence required for an incident.
* Determine the source of the evidence.
* Define a policy that determines the pathway to legally extract electronic evidence with minimal disruption.
* Establish a policy for securely handling and storing the collected evidence.
* Identify if the incident requires full or formal investigation.
* Train the staff to handle the incident and preserve the evidence.
* Create a special process for documenting the procedure.
References:Incident Handler (ECIH v3) courses and study guides include discussions on forensic readiness planning, highlighting the importance of preparing organizations for effective legal and technical handling of incidents.


NEW QUESTION # 154
John is a professional hacker who is performing an attack on the target organization where he tries to redirect the connection between the IP address and its target server such that when the users type in the Internet address, it redirects them to a rogue website that resembles the original website. He tries this attack using cache poisoning technique. Identify the type of attack John is performing on the target organization.

  • A. Skimming
  • B. War driving
  • C. Pharming
  • D. Pretexting

Answer: C


NEW QUESTION # 155
Bit stream image copy of the digital evidence must be performed in order to:

  • A. All the above
  • B. Copy the FAT table
  • C. Prevent alteration to the original disk
  • D. Copy all disk sectors including slack space

Answer: D


NEW QUESTION # 156
A US Federal Agency network was the target of a DoS attack that prevented and impaired the normal authorized functionality of the networks. According to agency's reporting timeframe guidelines, this incident should be reported within 2 h of discovery/detection if the successful attack is still ongoing and the agency is unable to successfully mitigate the activity.
Which incident category of US Federal Agency does this incident belong to?

  • A. CAT 2
  • B. CAT 6
  • C. CAT 1
  • D. CAT 5

Answer: A

Explanation:
In the context of US Federal Agencies, incidents are categorized based on their impact on operations, assets, or individuals. A DoS attack that prevents or impairs the authorized functionality of networks and is still ongoing without successful mitigation efforts typically falls under Category 2 (CAT 2). This category is designated for incidents that have a significant impact, requiring immediate reporting and response. The reporting timeframe of within 2 hours as mentioned aligns with the urgency associated with CAT 2 incidents, emphasizing the need for swift action to address the attack and restore normal operations.References:US Federal incident response guidelines and the Incident Handler (ECIH v3) courses outline the categorization of cybersecurity incidents, detailing the response protocols for each category, including the reporting timeframes.


NEW QUESTION # 157
He must present this evidence in a clear and comprehensible manner to the members of jury so that the evidence explains the facts clearly and further helps in obtaining an expert opinion on the same to confirm the investigation process.
In the above scenario, what is the characteristic of the digital evidence Stanley tried to preserve?

  • A. Believable
  • B. Admissible
  • C. Authentic
  • D. Complete

Answer: A


NEW QUESTION # 158
You are talking to a colleague who Is deciding what information they should include in their organization's logs to help with security auditing. Which of the following items should you tell them to NOT log?

  • A. Session ID
  • B. Timestamp
  • C. Source IP eddross
  • D. userid

Answer: D


NEW QUESTION # 159
......

212-89 Braindumps PDF, EC-COUNCIL 212-89 Exam Cram: https://www.latestcram.com/212-89-exam-cram-questions.html

New 2026 212-89 Sample Questions Reliable 212-89 Test Engine: https://drive.google.com/open?id=1sAuwTum8Tau-64nAbYv3wB1zjJ0l0-kF