v3 212-89 Exam with This Comprehensive Set of 200
Original Practice Questions, Each Paired with Detailed
Answer Rationales and Organized by All Ten Core
Domains for Rapid Strategic Preparation for 2026/2027
Certification Cycle.
200 Practice Questions with ☑VERIFIED
ANSWERs & Rationales
Domain 1: Introduction to Incident Handling
and Response
Q1. An incident handler receives a report from
a user who believes a nation-state actor is
attacking the organization. The handler reviews
the user's screenshots, asks a series of
validation questions, checks internal resources,
and assesses the current network condition.
,Which phase of the Incident Response (IR)
process is the handler performing?
• A. Containment
• B. Eradication
• C. Recovery
• D. Detection and Analysis
☑VERIFIED ANSWER: D
Rationale: The handler is verifying the validity
of a potential incident, assessing its nature and
scope, and determining whether a real attack is
occurring. This is the Detection and
Analysis (also called Identification) phase,
where alerts and reports are investigated to
confirm incidents. Even with a history of false
positives, each report must be treated seriously
and analyzed properly.
,Q2. An organization's information security
policy must be which of the following?
• A. Complex and highly technical
• B. Written in legal language only
• C. Approved by all employees
• D. Clear, concise, and enforceable
☑VERIFIED ANSWER: D
Rationale: An effective information security
policy must be clear, concise, and
enforceable so that all employees can
understand their responsibilities and the
organization can hold individuals accountable.
Overly complex or legalistic policies are difficult
to implement and follow.
Q3. Which of the following is NOT considered
an information security threat category?
, • A. Network threats
• B. System threats
• C. Physical threats
• D. Application threats
☑VERIFIED ANSWER: C
Rationale: While physical security is important,
the primary information security threat
categories in the context of the ECIH curriculum
typically include network threats, system
threats, and application threats. "Physical
threats" is generally treated as a separate
domain rather than an information security
threat category.
Q4. DNS and ARP poisoning are examples of
what type of information security threat?
• A. System threats