[May-2026] Free 212-89 Exam Dumps to Improve Exam Score [Q146-Q168]

Share

[May-2026] Free 212-89 Exam Dumps to Improve Exam Score

2026 Realistic 212-89 Dumps Exam Tips Test Pdf Exam Material


The ECIH certification exam covers a wide range of topics, including incident management processes, risk assessment methodologies, incident response frameworks, and more. It is designed to test the proficiency of candidates in identifying, assessing, and responding to various types of security incidents, including malware attacks, network intrusions, and data breaches. EC Council Certified Incident Handler (ECIH v3) certification is highly respected in the industry, and it is recognized by employers around the world as a mark of excellence in incident response and handling.

 

NEW QUESTION # 146
Francis received a spoof email asking for his bank information. He decided to use a tool to analyze the email headers.
Which of the following should he use?

  • A. EventLog Analyzer
  • B. Polite Mail
  • C. Email Checker
  • D. Mx Toolbox

Answer: D


NEW QUESTION # 147
Which of the following is a common tool used to help detect malicious internal or compromised actors?

  • A. User behavior analytics
  • B. Log forward ng
  • C. SOC2 compliance report
  • D. Syslog configuration

Answer: A

Explanation:
User Behavior Analytics (UBA) is a cybersecurity process or tool that utilizes machine learning, algorithms, and statistical analyses to detect potentially harmful activities within an organization's network by comparing them against established patterns of users' behavior. It is particularly effective in identifying malicious internal actors or compromised users who may be conducting activities that deviate from their normal behavior patterns, such as accessing unauthorized data or systems, excessive file downloads, or unusual login times.
UBA tools can flag these activities for further investigation, often before traditional security tools detect a breach. In contrast, SOC2 compliance reports, log forwarding, and syslog configuration are important for maintaining and auditing security standards and for infrastructure monitoring, but they are not primarily focused on detecting malicious behavior based on deviations from established user behavior patterns.References:The Incident Handler (ECIH v3) curriculum discusses various tools and methodologies for detecting and responding to security incidents, highlighting User Behavior Analytics as a key tool for identifying insider threats and compromised accounts through behavioral monitoring and analysis.


NEW QUESTION # 148
Which of the following GPG 18 and Forensic readiness planning (SPF) principles states that "organizations should adopt a scenario based Forensic Readiness Planning approach that learns from experience gained within the business"?

  • A. Principle 2
  • B. Principle 7
  • C. Principle 5
  • D. Principle 3

Answer: C


NEW QUESTION # 149
Rossi san incident manager (IM) and his team provides support to all users in the organization that are affected by the threat or attack. David, who is the organizational internal auditor, is also part of the Ross's incident response team.
Among the following duties, identify one of the responsibilities of David.

  • A. Coordinate incident containment activities with the information security officer (ISO)
  • B. Configure information security controls
  • C. Preform the necessary action required to block the network traffic from the suspected intruder
  • D. Identify and report security loopholes to management for necessary action

Answer: D


NEW QUESTION # 150
Jacob is an employee at a firm called Dolphin Investment. While he was on duty, he identified that his computer was facing some problems, and he wanted to convey the issue to the concerned authority in his organization. However, this organization currently does not have a ticketing system to address such types of issues. In the above scenario, which of the following ticketing systems can be employed by Dolphin Investment to allow Jacob to inform the concerned team about the incident?

  • A. ThreatConnect
  • B. IBM XForco Exchange
  • C. ManageEngine ServiceDesk Plus
  • D. MISP

Answer: C

Explanation:
In the scenario where Dolphin Investment needs to implement a ticketing system for employees like Jacob to report IT-related issues, ManageEngine ServiceDesk Plus is the most suitable option among the choices provided. ManageEngine ServiceDesk Plus is a comprehensive IT help desk software that facilitates issue tracking, incident management, and efficient resolution of IT-related problems and requests. It enables users to submit tickets through various channels, including email, web portal, phone, or chat, and allows IT support teams to manage these tickets through a centralized platform. This system is designed to streamline the process of reporting, tracking, and resolving IT issues and incidents, making it an ideal solution for organizations looking to establish a formalized incident reporting and resolution process. Other options like IBM X-Force Exchange, ThreatConnect, and MISP focus more on threat intelligence sharing and security incident analysis rather than functioning as an IT help desk or ticketing system.
References:Incident Handler (ECIH v3) courses and study guides often discuss the importance of having an effective incident reporting and management system in place, and ManageEngine ServiceDesk Plus is frequently cited as a practical solution for organizations seeking to implement such a system.


NEW QUESTION # 151
Mason, an incident responder, detects a large volume of traffic from an internal host to external IP addresses during non-business hours. The affected host also shows signs of elevated memory and CPU consumption.
AIDA64 Extreme logs confirm the system was under continuous strain for hours. What should Mason suspect as the primary issue?

  • A. High resource utilization due to inappropriate usage
  • B. Unauthorized hardware installation
  • C. Network misconfiguration
  • D. Improper access control policy

Answer: A

Explanation:
Comprehensive and Detailed Explanation (ECIH-aligned):
This scenario reflects inappropriate resource usage, a category of network and system misuse defined in the ECIH Network Security Incident module. Excessive outbound traffic during non-business hours combined with high CPU and memory utilization indicates unauthorized or improper use of system resources.
Option A is correct because the behavior suggests activities such as cryptomining, data exfiltration, or unauthorized processing. These activities strain system resources and often occur outside normal working hours to avoid detection.
Option B would not necessarily cause sustained resource strain. Option C focuses on physical changes.
Option D relates to permission enforcement, not usage behavior.
ECIH categorizes inappropriate usage as a security incident when system resources are misused in ways that violate policy or threaten availability, making Option A correct.


NEW QUESTION # 152
James is working as an incident responder at Cyber Sol Inc. The management instructed James to invest gate a cybersecurity incident that recently happened in the company. As a part of the investigation process, James started collecting volatile information from a system running on Windows operating system.
Which of the following commands helps James in determining all the executable files for running processes?

  • A. dos key/history
  • B. date/t&time/t
  • C. netstat-ab
  • D. top

Answer: C


NEW QUESTION # 153
Francis is an incident handler and security expert. He works at MorisonTech Solutions based in Sydney, Australia. He was assigned a task to detect phishing/spam mails for the client organization.
Which of the following tools can assist Francis to perform the required task?

  • A. Cain and Abel
  • B. Netcraft
  • C. Nessus
  • D. BTCrack

Answer: B

Explanation:
Netcraft is a tool that provides internet security services, including the detection of phishing and spam emails.
It offers a range of services that can help organizations identify fraudulent websites and phishing activities by analyzing web content and email messages for known phishing signatures and heuristics. This makes it a useful tool for incident handlers like Francis, who is tasked with detecting phishing and spam emails for client organizations. Other options listed, such as Nessus (a vulnerability scanner), BTCrack (a Bluetooth pin and link-key cracker), and Cain and Abel (a password recovery tool), do not specialize in detecting phishing or spam emails but serve different purposes in cybersecurity.
References:The Incident Handler (ECIH v3) curriculum includes discussions on tools and methodologies for detecting and mitigating various cyber threats, including phishing and spam, highlighting tools like Netcraft for their utility in these areas.


NEW QUESTION # 154
A regional airport recently upgraded its operations with smart IoT-based baggage handling and security camera systems. During a routine cyber resilience drill mimicking device disruption, operational staff experienced confusion in executing assigned duties and lacked clarity in the communication flow. There was uncertainty about who should engage with third-party vendors, how to retrieve diagnostic logs from affected systems, and which units required priority attention to maintain continuity. Which of the following would best address these preparedness gaps?

  • A. Conduct realistic simulations and clearly document responsibilities for each stakeholder
  • B. Transition critical airport infrastructure to a fallback manual mode during emergency events
  • C. Schedule periodic firmware patching for vulnerable IoT endpoints
  • D. Automate alerts for anomalous activity across the IoT network using monitoring tools

Answer: A

Explanation:
The EC-Council Incident Handler (ECIH) curriculum stresses that preparation is the most critical phase of incident response. Organizations must establish clearly defined roles, communication channels, escalation procedures, and documented response workflows before an incident occurs. The scenario highlights confusion during a resilience drill-specifically unclear stakeholder responsibilities, communication breakdowns, and uncertainty in vendor coordination and log retrieval.
ECIH emphasizes that conducting realistic simulations, tabletop exercises, and red/blue team drills strengthens organizational readiness. These exercises help validate escalation paths, clarify third-party engagement protocols, and ensure that evidence collection procedures-such as retrieving diagnostic logs- are well understood by operational teams.
Option A (automated alerts) improves detection but does not solve role ambiguity. Option B (firmware patching) addresses vulnerability management but not communication gaps. Option D (manual fallback mode) supports business continuity but does not resolve the confusion in responsibilities and escalation paths identified in the drill.
ECIH guidance clearly states that effective first response depends on documented playbooks, defined stakeholder responsibilities, vendor coordination procedures, and continuous testing of incident response plans. Simulation-based training exposes procedural weaknesses and ensures each department understands its operational and communication duties.
Therefore, conducting realistic simulations and clearly documenting responsibilities for each stakeholder is the most appropriate corrective action to close the preparedness gaps identified during the exercise.


NEW QUESTION # 155
NovoMed discovers encrypted data transfers of drug research and participant data to an unknown location and receives an extortion-like message implying the formula may be released. What is the most prudent course of action?

  • A. Engage local law enforcement and international cybercrime agencies to trace the transfer's origins.
  • B. Negotiate with the attackers discreetly to buy time and retrieve data.
  • C. Immediately recall the drug from the market.
  • D. Publicly announce the breach warning competitors and authorities.

Answer: A

Explanation:
Explanation (incident response governance):
This scenario combines data theft + extortion involving highly sensitive IP and regulated participant data.
The prudent course is to trigger formal legal/incident governance: engage law enforcement and appropriate cybercrime agencies (D), preserve evidence, and coordinate with legal counsel, regulators (if required), and cyber-insurance response processes. Law enforcement engagement can support intelligence sharing, preservation orders, and broader investigation into the infrastructure receiving the exfiltrated data.
(A) recalling the drug is not directly tied to the incident's immediate technical or legal response; it's a business decision that may be unnecessary and harmful without evidence of counterfeit risk. (B) immediate public announcement may be legally required in some jurisdictions, but it must be accurate and coordinated; doing it prematurely can worsen harm. (C) negotiation is risky and typically handled only through controlled legal and executive channels; it does not ensure data return and can incentivize further extortion.
Thus, (D) reflects best-practice escalation: treat it as a serious crime, preserve chain of custody, and coordinate response through legal and investigative authorities while technical teams contain and scope.


NEW QUESTION # 156
James is a professional hacker and is employed by an organization to exploit their cloud services. In order to achieve this, James created anonymous access to the cloud services to carry out various attacks such as password and key cracking, hosting malicious data, and DDoS attacks. Which of the following threats is he posing to the cloud platform?

  • A. Insecure interface and APIs
  • B. Data breach/loss
  • C. Insufficient duo diligence
  • D. Abuse end nefarious use of cloud services

Answer: D


NEW QUESTION # 157
In the cloud environment, an authorized security professional executes approved sanitation procedures using approved utilities to permanently remove data spilled from contaminated information systems and applications in the cloud.
This is an example of which of the following?

  • A. Cloud auditor
  • B. Cloud computing
  • C. Cloud broker
  • D. Cloud eradication

Answer: A


NEW QUESTION # 158
Employee monitoring tools are mostly used by employers to find which of the following?

  • A. Conspiracies
  • B. Malicious insider threats
  • C. Stolen credentials
  • D. Lost registry keys

Answer: B

Explanation:
Employee monitoring tools are primarily used by employers to detect and prevent malicious insider threats.
These tools can track activities such as data access, data exfiltration attempts, unauthorized actions, and other behaviors that could indicate malicious intent or pose a risk to the organization's security. While such tools may also incidentally uncover issues like lost registry keys, conspiracies, or stolen credentials, their main purpose is to safeguard against insiders who might misuse their access to harm the organization, steal data, sabotage systems, or engage in espionage.
References:ECIH v3 study materials cover various security measures and tools that organizations can use to protect against insider threats, emphasizing the role of monitoring in detecting and responding to malicious activities by insiders.


NEW QUESTION # 159
Johnson an incident handler is working on a recent web application attack faced by the organization. As part of this process, he performed data preprocessing in order to analyzing and detecting the watering hole attack. He preprocessed the outbound network traffic data collected from firewalls and proxy servers and started analyzing the user activities within a certain time period to create time-ordered domain sequences to perform further analysis on sequential patterns.
Identify the data-preprocessing step performed by Johnson.

  • A. Identifying unpopular domains
  • B. Filtering invalid host names
  • C. User-specific sessionization
  • D. Host name normalization

Answer: C


NEW QUESTION # 160
A national healthcare organization with multiple branches is facing growing cybersecurity challenges due to unmanaged systems, inconsistent configurations, and a lack of asset visibility. In response, leadership has asked the security team to implement a proactive strategy aimed at minimizing exposure across all departments. This includes identifying hardware and software in use, enforcing consistent security settings, and establishing a routine process to detect system weaknesses before they can be exploited.
The security team is seeking a well-established, practical framework that emphasizes prioritized, real-world security practices and can be implemented efficiently with available resources. Which of the following frameworks would BEST support this proactive security initiative?

  • A. Applying ITIL for restoring disrupted business services
  • B. Employing CIS Critical Security Controls for foundational defensive actions
  • C. Using COBIT for strategic enterprise governance modeling
  • D. Implementing NIST 800-61 for policy and incident lifecycle development

Answer: B

Explanation:
The EC-Council Incident Handler (ECIH) curriculum highlights the importance of proactive security controls, asset management, configuration management, and vulnerability management as foundational elements of forensic readiness and incident prevention.
The scenario describes challenges related to unmanaged systems, inconsistent configurations, and lack of asset visibility-core issues addressed by the CIS Critical Security Controls (CIS CSC). The CIS Controls provide prioritized, actionable cybersecurity best practices designed to mitigate the most common attack vectors. These include inventory and control of hardware assets, inventory and control of software assets, secure configuration of enterprise assets, continuous vulnerability management, and controlled use of administrative privileges.
ECIH emphasizes that organizations must first establish visibility into assets and enforce baseline security configurations to reduce attack surfaces. The CIS framework is specifically designed for practical implementation, making it ideal for organizations seeking efficient deployment using available resources.
Option B (NIST 800-61) focuses on incident response lifecycle management, not proactive exposure reduction. Option C (ITIL) focuses on IT service management and service restoration, not cybersecurity hardening. Option D (COBIT) provides high-level governance and enterprise control objectives but does not offer the hands-on, prioritized technical safeguards described in the scenario.
Therefore, consistent with ECIH guidance on preventive controls and security baselining, the CIS Critical Security Controls framework is the best fit for implementing proactive, real-world defensive measures.


NEW QUESTION # 161
Quantitative risk is the numerical determination of the probability of an adverse event and the extent of the
losses due to the event. Quantitative risk is calculated as:

  • A. (Loss) / (Probability of Loss)
  • B. (Probability of Loss) / (Loss)
  • C. (Probability of Loss) X (Loss)
  • D. Significant Risks X Probability of Loss X Loss

Answer: C


NEW QUESTION # 162
Adam is an incident handler who intends to use DBCCLOG command to analyze a database and retrieve the active transaction logfiles for the specified database. The syntax of DBCC LG command is DBCC LOG (<database name>, <output>), where the output parameter specifies the level of information an incident handler wants to retrieve.
If Adam wants to retrieve the full information on each operation along with the hex dump of a current transaction row, which of the following output parameters should Adam use?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A


NEW QUESTION # 163
Rose is an incident-handling person and she is responsible for detecting and eliminating any kind of scanning attempts over the network by any malicious threat actors. Rose uses Wireshark tool to sniff the network and detect any malicious activities going on.
Which of the following Wireshark filters can be used by her to detect TCP Xmas scan attempt by the attacker?

  • A. tcp.flags==0X000
  • B. tcp.dstport==7
  • C. tcp.flags==0X029
  • D. tcp.flags.reset==1

Answer: C


NEW QUESTION # 164
Eric works as a system administrator at ABC organization and previously granted several users with access privileges to the organizations systems with unlimited permissions. These privileged users could prospectively misuse their rights unintentionally, maliciously, or could be deceived by attackers that could trick them to perform malicious activities. Which of the following guidelines would help incident handlers eradicate insider attacks by privileged users?

  • A. Do not allow administrators to use unique accounts during the installation process
  • B. Do not enable default administrative accounts to ensure accountability
  • C. Do not control the access to administrator ano privileged users
  • D. Do not use encryption methods to prevent, administrators and privileged users from accessing backup tapes and sensitive information

Answer: B


NEW QUESTION # 165
Michael is a part of the computer incident response team of a company. One of his responsibilities is to handle email incidents. The company receives an email from an unknown source, and one of the steps that he needs to take is to check the validity of the email. Which of the following tools should he use?

  • A. Yesware
  • B. G Suite Toolbox
  • C. Zendio
  • D. Email Dossier

Answer: D


NEW QUESTION # 166
What command does a Digital Forensic Examiner use to display the list of all IP addresses and their associated MAC addresses on a victim computer to identify the machines that were communicating with it:

  • A. "ifconfig" command
  • B. "arp" command
  • C. "dd" command
  • D. "netstat -an" command

Answer: B


NEW QUESTION # 167
Which of the following details are included in the evidence bags?

  • A. Error messages that contain sensitive information and files containing passworos
  • B. Sensitive cirectories, personal, and organizational email adcress
  • C. Software version information and web application source code
  • D. Date and time of seizure, exhibit number, anc name of incident responder

Answer: C

Explanation:
In the practice of digital forensics and incident handling, evidence bags play a crucial role in preserving the integrity and chain of custody of physical and digital evidence. The information typically included in the documentation on evidence bags encompasses the date and time of seizure, which provides a timestamp for when the evidence was collected; the exhibit number, which is a unique identifier assigned to each piece of evidence for tracking and reference purposes; and the name of the incident responder or individual who collected the evidence, ensuring accountability and traceability. This documentation is essential for maintaining the chain of custody, a critical element in legal proceedings, as it helps establish the evidence's authenticity and integrity by detailing its handling from collection to presentation in court. Options A, B, and C describe types of digital evidence but are not directly related to the content typically documented on evidence bags.
References:Incident Handler (ECIH v3) courses and study guides emphasize the importance of accurately documenting evidence bags as part of the evidence collection and preservation process in incident handling and digital forensics.


NEW QUESTION # 168
......


EC-COUNCIL 212-89 (EC Council Certified Incident Handler (ECIH v2)) Certification Exam is recognized by many organizations and businesses worldwide, and it is a valuable certification for anyone interested in a career in information security. EC Council Certified Incident Handler (ECIH v3) certification is an excellent way to demonstrate your expertise in incident handling and response, and it can help you advance your career in the field. EC Council Certified Incident Handler (ECIH v3) certification is also an excellent way to stay up-to-date with the latest developments in incident handling and response, ensuring that you are always prepared to tackle any security challenges that may arise.

 

Powerful 212-89 PDF Dumps for 212-89 Questions: https://www.validvce.com/212-89-exam-collection.html

Authentic 212-89 Dumps - Free PDF Questions to Pass: https://drive.google.com/open?id=1dRnzJ61RCMIgfkk9ny3QgWF55zuebNJ2