Latest [Jul 06, 2025] 100% Passing Guarantee - Brilliant 212-89 Exam Questions PDF [Q34-Q56]

Share

Latest [Jul 06, 2025] 100% Passing Guarantee - Brilliant 212-89 Exam Questions PDF

212-89 Certification – Valid Exam Dumps Questions Study Guide! (Updated 170 Questions)


The EC-Council Certified Incident Handler (ECIH) 212-89 is an exam that prepares you for handling incidents in various information systems. It prepares you for security plans and policies to deal with incidents with efficiency & effectiveness in a time-constrained environment to decrease the effect of those incidents. This test leads you to the ECIH certification that will allow you to work as an Incident Handler and work in incident response frameworks. So, if you want to excel in the information security environment, the EC-Council Certified Incident Handler certification exam is a must for you. It will be the best gateway to a high-paying job and a good working environment, where you can work with other EC-Council specialists.


To prepare for the ECIH v2 certification exam, candidates can attend an official EC-Council training course, which covers all the topics included in the exam. 212-89 course provides hands-on experience with incident handling tools and techniques and includes real-world scenarios to help candidates prepare for the exam. Additionally, candidates can use practice exams and study materials to reinforce their understanding of the subject matter.


The ECIH certification exam covers a wide range of topics, including incident handling and response, computer forensics, and network security. 212-89 exam is designed to test an individual’s knowledge and skills in each of these areas, and is intended to be challenging and comprehensive. 212-89 exam consists of 50 multiple-choice questions, and candidates have 2 hours to complete the exam. In order to pass the exam, candidates must achieve a score of at least 70%.

 

NEW QUESTION # 34
Bonney's system has been compromised by a gruesome malware.
What is the primary step that is advisable to Bonney in order to contain the malware incident from spreading?

  • A. Call the legal department in the organization and inform about the incident
  • B. Leave it to the network administrators to handle
  • C. Turn off the infected machine
  • D. Complaint to police in a formal way regarding the incident

Answer: C

Explanation:
Turning off the infected machine is a common immediate response to contain a malware incident and prevent it from spreading to other systems on the network. This action halts any ongoing malicious activities by the malware, thereby limiting the potential for further damage or data exfiltration. However, it is essential to note that this step can lead to the loss of volatile data that might be useful for forensic analysis. Therefore, it is advisable only when it's critical to stop the malware immediately, and there's a strategy in place for forensic investigation that includes handling non-volatile data or when the preservation of volatile data is not possible.
References:The Incident Handler (ECIH v3) curriculum by EC-Council outlines various strategies for containing malware incidents, discussing the implications and considerations of actions such as turning off infected machines.


NEW QUESTION # 35
An active vulnerability scanner featuring high speed discovery, configuration auditing, asset profiling, sensitive data discovery, and vulnerability analysis is called:

  • A. EtherApe
  • B. Nessus
  • C. CyberCop
  • D. nmap

Answer: B


NEW QUESTION # 36
According to US-CERT; if an agency is unable to successfully mitigate a DOS attack it must be reported within:

  • A. One (1) hour of discovery/detection if the successful attack is still ongoing
  • B. Two (2) hours of discovery/detection if the successful attack is still ongoing
  • C. Four (4) hours of discovery/detection if the successful attack is still ongoing
  • D. Three (3) hours of discovery/detection if the successful attack is still ongoing

Answer: B


NEW QUESTION # 37
Which of the following is host-based evidence?

  • A. Wiretaps
  • B. Router logs
  • C. The date and time of the PC
  • D. IDS logs

Answer: C


NEW QUESTION # 38
Which of the following GPG 18 and Forensic readiness planning (SPF) principles states that "organizations should adopt a scenario based Forensic Readiness Planning approach that learns from experience gained within the business"?

  • A. Principle 2
  • B. Principle 3
  • C. Principle 5
  • D. Principle 7

Answer: C


NEW QUESTION # 39
A Host is infected by worms that propagates through a vulnerable service; the sign(s) of the presence of the
worm include:

  • A. Established connection attempts targeted at the vulnerable services
  • B. All the above
  • C. System becomes instable or crashes
  • D. Decrease in network usage

Answer: C


NEW QUESTION # 40
Bit stream image copy of the digital evidence must be performed in order to:

  • A. Copy all disk sectors including slack space
  • B. All the above
  • C. Prevent alteration to the original disk
  • D. Copy the FAT table

Answer: A


NEW QUESTION # 41
In the Control Analysis stage of the NIST's risk assessment methodology, technical and none technical control methods are classified into two categories. What are these two control categories?

  • A. Predictive and Detective controls
  • B. Preventive and predictive controls
  • C. Preventive and Detective controls
  • D. Detective and Disguised controls

Answer: C


NEW QUESTION # 42
Which of the following techniques prevent or mislead incident-handling process and may also affect the collection, preservation, and identification phases of the forensic investigation process?

  • A. Footprinting
  • B. Scanning
  • C. Enumeration
  • D. Anti-forensics

Answer: D

Explanation:
Anti-forensics techniques are designed to prevent, mislead, or interfere with the incident handling process, affecting the collection, preservation, and identification phases of the forensic investigation process. These techniques include methods to erase, encrypt, or alter information, make data recovery difficult, hide data (e.g., steganography), or otherwise obstruct forensic analysis and investigation efforts. Anti-forensics can significantly challenge the efforts of incident responders and forensic investigators in establishing the facts of a security incident or crime.References:The Incident Handler (ECIH v3) courses and study guides discuss various challenges in digital forensics, including anti-forensics methods and their impact on the effectiveness of forensic investigations.
Top of Form


NEW QUESTION # 43
Which of the following service(s) is provided by the CSIRT:

  • A. All the above
  • B. Technology watch
  • C. Development of security tools
  • D. Vulnerability handling

Answer: A


NEW QUESTION # 44
Patrick is doing a cyber forensic investigation. He is in the process of collecting physical evidence at the crime scene.
Which of the following elements he must consider while collecting physical evidence?

  • A. DNS information including domain and subdomains
  • B. Published nameservers and web application source code
  • C. Removable media, cable, and publications
  • D. Open ports, services, and operating system (OS) vulnerabilities

Answer: C


NEW QUESTION # 45
The goal of incident response is to handle the incident in a way that minimizes damage and reduces recovery time and cost. Which of the following does NOT constitute a goal of incident response?

  • A. Helping personal to recover quickly and efficiently from security incidents, minimizing loss or theft and disruption of services.
  • B. Using information gathered during incident handling to prepare for handling future incidents in a better way and to provide stronger protection for systems and data.
  • C. Dealing properly with legal issues that may arise during incidents.
  • D. Dealing with human resources department and various employee conflict behaviors.

Answer: D


NEW QUESTION # 46
Alex is an incident handler for Tech-o-Tech Inc. and is tasked to identify any possible insider threats within his organization. Which of the following insider threat detection techniques can be used by Alex to detect insider threats based on the behavior of a suspicious employee, both individually and in a group?

  • A. Physical detection
  • B. Profiling
  • C. Mole detection
  • D. behaviorial analysis

Answer: D

Explanation:
Behavioral analysis is a technique used to detect insider threats by analyzing the behavior of employees, both individually and in group settings, to identify any actions that deviate from the norm. This method relies on monitoring and analyzing data related to user activities, access patterns, and other behaviors that could indicate malicious intent or a potential security risk from within the organization. Behavioral analysis can detect unusual access to sensitive data, abnormal data transfer activities, and other indicators of insider threats. This approach is proactive and can help in identifying potential insider threats before they result in significant harm to the organization.References:The Incident Handler (ECIH v3) certification materials cover various insider threat detection techniques, including the importance of behavioral analysis as a key method for identifying potential security risks posed by insiders.


NEW QUESTION # 47
Which of the following risk mitigation strategies involves execution of controls to reduce the risk factor and brings it to an acceptable level or accepts the potential risk and continues operating the IT system?

  • A. Risk avoidance
  • B. Risk transference
  • C. Risk planning
  • D. Risk assumption

Answer: D

Explanation:
Risk assumption involves accepting the potential risk and continuing to operate the IT system while implementing controls to reduce the risk to an acceptable level. This strategy acknowledges that some level of risk is inevitable and focuses on managing it through mitigation measures rather than eliminating it entirely.
Risk avoidance would entail taking actions to avoid the risk entirely, risk planning involves preparing for potential risks, and risk transference shifts the risk to another party, typically through insurance or outsourcing.
Risk assumption is a pragmatic approach that balances the need for operational continuity with the imperative of risk management.References:The ECIH v3 certification program covers various risk mitigation strategies, emphasizing the selection of the appropriate approach based on the organization's risk tolerance and the specific context of the threat.


NEW QUESTION # 48
The open source TCP/IP network intrusion prevention and detection system (IDS/IPS), uses a rule-driven
language, performs real-time traffic analysis and packet logging is known as:

  • A. Snort
  • B. Wireshark
  • C. Nessus
  • D. SAINT

Answer: A

Explanation:
Explanation


NEW QUESTION # 49
You are a systems administrator for a company. You are accessing your file server remotely for maintenance. Suddenly, you are unable to access the server. After contacting others in your department, you find out that they cannot access the file server either. You can ping the file server but not connect to it via RDP. You check the Active Directory Server, and all is well. You check the email server and find that emails are sent and received normally. What is the most likely issue?

  • A. An e-mail service issue
  • B. An admin account issue
  • C. The file server has shut down
  • D. A denial-of-service issue

Answer: D


NEW QUESTION # 50
Installing a password cracking tool, downloading pornography material, sending emails to colleagues which irritates them and hosting unauthorized websites on the company's computer are considered:

  • A. Inappropriate usage incidents
  • B. Malware attacks
  • C. Unauthorized access attacks
  • D. Network based attacks

Answer: A


NEW QUESTION # 51
Which one of the following is the correct flow of the stages in an incident handling and response (IH&R) process?

  • A. Incident triage -> Eradication -> Containment -> Incident recording -> Preparation -> Recovery -> Post-incident activities
  • B. Incident recording -> Preparation -> Containment -> Incident triage -> Recovery > Eradication -> Post-incident activities
  • C. Preparation -> Incident recording -> Incident triage -> Containment -> Eradication -> Recovery -> Post-incident activities
  • D. Containment -> Incident recording -> Incident triage -> Preparation -> Recovery -> Eradication -> Post-incident activities

Answer: C


NEW QUESTION # 52
Incident response team must adhere to the following:

  • A. Assess the situation
  • B. Notify appropriate personnel
  • C. All the above
  • D. Stay calm and document everything

Answer: C


NEW QUESTION # 53
Which of the following might be an insider threat?

  • A. Current employee
  • B. All of these
  • C. Business partners
  • D. Disgruntled system administrators

Answer: B


NEW QUESTION # 54
Which of the following is NOT a network forensic tool?

  • A. Advancec NTFS Journaling Parser
  • B. Tcpdurnp
  • C. Wireshark
  • D. Capsa Network Analyzer

Answer: A

Explanation:
Network forensic tools are designed to capture, record, and analyze network traffic. Tools like Capsa Network Analyzer, Tcpdump, and Wireshark are specifically designed for this purpose, providing capabilities to capture live traffic, analyze packets, and understand network activities. Capsa Network Analyzer is a comprehensive network monitoring tool, Tcpdump is a powerful command-line packet analyzer, and Wireshark is a widely used network protocol analyzer that provides detailed information about network traffic.
Advanced NTFS Journaling Parser, on the other hand, is not a network forensic tool but a tool used for forensic analysis of NTFS file systems. It parses the NTFS journal ($LogFile), which contains a log of changes made to files on an NTFS volume. This tool is valuable for forensic analysts who are investigating the file system activities on a Windows system, such as file creation, modification, and deletion times, rather than analyzing network traffic. Therefore, it does not fit the category of a network forensic tool.
References:The ECIH v3 curriculum from EC-Council covers a range of tools useful for incident handlers and forensic analysts, distinguishing between network forensic tools and those used for other types of forensic analysis, such as file system investigation.


NEW QUESTION # 55
Joseph is an incident handling and response (IH&R) team lead in Toro Network Solutions Company. As a part of the IH&R process, Joseph alerted the service providers, developers, and manufacturers about the affected resources. Identify the stage of lH&R process Joseph is currently in.

  • A. Eradication
  • B. Incident triage
  • C. Recovery
  • D. Containment

Answer: D


NEW QUESTION # 56
......

212-89 are Available for Instant Access: https://www.newpassleader.com/EC-COUNCIL/212-89-exam-preparation-materials.html

212-89 Dumps 2025 - New EC-COUNCIL 212-89 Exam Questions: https://drive.google.com/open?id=1Hicd7vyvmL9w1_tY2JyCbyOKNekRJ5-M