212-89 Certified Incident Handler (ECIH) Practice Questions
Prepare for 212-89 with more than an answer.
- Exam fee
- $250 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 10
- Introduction to Incident Handling and Response10%
- Incident Handling and Response Process15%
- First Response10%
- Handling Malware Incidents15%
- Handling Email Security Incidents10%
- Handling Network Security Incidents15%
- Handling Web Application Security Incidents10%
- Handling Cloud Security Incidents10%
- Handling Insider Threats5%
- Handling Endpoint Security Incidents10%
- 1
In the context of Incident Classification, which priority level should be assigned to an incident where 'Critical business services are down, and sensitive customer data is actively being exfiltrated'?
Show answer details
Correct answer: C
High/Critical priority is assigned when an incident affects critical infrastructure or involves significant data loss (Confidentiality and Availability impact). Active exfiltration + Service Down = Critical.
- 2
The diagram below represents the Incident Response Lifecycle. Which phase is represented by the missing block 'X'?
Preparation -> Detection & Analysis -> X -> Post-Incident Activity
Show answer details
Correct answer: B
According to the NIST SP 800-61 lifecycle, the phase following 'Detection & Analysis' and preceding 'Post-Incident Activity' is 'Containment, Eradication, and Recovery'.
flowchart LR A[Preparation] --> B[Detection & Analysis] B --> C[Containment, Eradication, Recovery] C --> D[Post-Incident Activity] D --> A - 3
A First Responder arrives at a scene where a laptop is running and clearly shows evidence of a cybercrime in progress. According to the 'Order of Volatility' (RFC 3227), which data source should be collected FIRST?
Show answer details
Correct answer: B
The Order of Volatility states that data should be collected from most volatile to least volatile. CPU Registers and Cache are the most volatile, followed by Routing Tables/RAM, then Temp Files/Swap, then Disk, then Archival Media.
- 4
When collecting digital evidence, a First Responder uses a hardware Write Blocker. What is the primary function of this device?
Show answer details
Correct answer: B
A Write Blocker ensures that the source drive is mounted in read-only mode, preventing the operating system or user from accidentally modifying metadata or files, thus preserving evidence integrity.
- 5
True or False: In a Chain of Custody document, if a gap in the timeline exists where evidence cannot be accounted for, the evidence may be ruled inadmissible in court.
Show answer details
Correct answer: A
True. The Chain of Custody must show a continuous timeline of possession. Any gap allows the defense to argue that the evidence could have been tampered with during that time.
- 6
Which command-line tool is commonly used by First Responders on a Linux system to capture the current network connections and associated processes before powering down?
Show answer details
Correct answer: A
'netstat -anp' (or 'ss -anp') displays all active connections (-a), numerically (-n), showing the PID and program name (-p). This links network activity to specific processes.
- 7
You are securing a digital crime scene involving a mobile device found in an unlocked state. What is the BEST practice to ensure the device does not lock and to prevent remote wiping?
Show answer details
Correct answer: B
Isolating the device from the network (Airplane Mode/Faraday Bag) prevents remote wipe commands. Keeping the screen active prevents encryption keys from being flushed from memory (which happens on lock/reboot).
- 8
A malware analyst is performing 'Static Analysis' on a suspicious executable. Which of the following activities falls under Static Analysis?
Show answer details
Correct answer: B
Static Analysis involves examining the file without executing it. Extracting strings, checking PE headers, and hashing are static methods. Running the file (Sandboxing) is Dynamic Analysis.
- 9
Which type of malware analysis requires an isolated, virtualized environment (Sandbox) to safely execute the code and observe its behavior, such as file system changes and network connections?
Show answer details
Correct answer: B
Dynamic Analysis involves running the malware in a controlled environment (Sandbox) to watch what it does (behavioral analysis).
- 10
You are handling a ransomware incident. The malware has encrypted the file server. What is the FIRST priority in the containment phase?
Show answer details
Correct answer: B
Ransomware spreads laterally and targets backups. The immediate priority is to isolate the infected host and protect backup integrity to ensure recovery is possible.
- 11
The very well-known free open source port, OS and service scanner and network discovery utility is called:
Show answer details
Correct answer: B
Nmap (Network Mapper) is the most well-known free and open-source network scanning tool for port scanning, OS detection, and service enumeration. It provides comprehensive network discovery and security auditing capabilities that are essential for incident handlers. Wireshark is a packet analyzer, Snort is an intrusion detection system, and SAINT is a commercial vulnerability scanner, none of which provide the broad network mapping functionality that Nmap offers.
- 12
A malware code that infects computer files, corrupts or deletes the data in them and requires a host file to propagate is called:
Show answer details
Correct answer: C
A virus is malicious code that infects computer files, corrupts or deletes data, and specifically requires a host file to propagate and spread. This host dependency is the key characteristic that distinguishes viruses from other malware types. Trojans disguise themselves as legitimate software but do not require host files, worms self-replicate across networks without needing host files, and rootkits hide malicious activity rather than requiring hosts for propagation.
