Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 209 pages
Exam (elaborations)

Master the EC-Council Certified Incident Handler (ECIH) v3 212-89 Exam with This Comprehensive Set of 200 Original Practice Questions, Each Paired with Detailed Answer Rationales and Organized by All Ten Core Domains for Rapid Strategic Preparatio

Document preview thumbnail
Preview 4 out of 209 pages

Master the EC-Council Certified Incident Handler (ECIH) v3 212-89 Exam with This Comprehensive Set of 200 Original Practice Questions, Each Paired with Detailed Answer Rationales and Organized by All Ten Core Domains for Rapid Strategic Preparation for 2026/2027 Certification Cycle

Content preview

Master the EC-Council Certified Incident Handler (ECIH)
v3 212-89 Exam with This Comprehensive Set of 200
Original Practice Questions, Each Paired with Detailed
Answer Rationales and Organized by All Ten Core
Domains for Rapid Strategic Preparation for 2026/2027
Certification Cycle.


200 Practice Questions with ☑VERIFIED
ANSWERs & Rationales


Domain 1: Introduction to Incident Handling
and Response
Q1. An incident handler receives a report from
a user who believes a nation-state actor is
attacking the organization. The handler reviews
the user's screenshots, asks a series of
validation questions, checks internal resources,
and assesses the current network condition.

,Which phase of the Incident Response (IR)
process is the handler performing?
• A. Containment
• B. Eradication
• C. Recovery
• D. Detection and Analysis
☑VERIFIED ANSWER: D
Rationale: The handler is verifying the validity
of a potential incident, assessing its nature and
scope, and determining whether a real attack is
occurring. This is the Detection and
Analysis (also called Identification) phase,
where alerts and reports are investigated to
confirm incidents. Even with a history of false
positives, each report must be treated seriously
and analyzed properly.

,Q2. An organization's information security
policy must be which of the following?
• A. Complex and highly technical
• B. Written in legal language only
• C. Approved by all employees
• D. Clear, concise, and enforceable
☑VERIFIED ANSWER: D
Rationale: An effective information security
policy must be clear, concise, and
enforceable so that all employees can
understand their responsibilities and the
organization can hold individuals accountable.
Overly complex or legalistic policies are difficult
to implement and follow.


Q3. Which of the following is NOT considered
an information security threat category?

, • A. Network threats
• B. System threats
• C. Physical threats
• D. Application threats
☑VERIFIED ANSWER: C
Rationale: While physical security is important,
the primary information security threat
categories in the context of the ECIH curriculum
typically include network threats, system
threats, and application threats. "Physical
threats" is generally treated as a separate
domain rather than an information security
threat category.


Q4. DNS and ARP poisoning are examples of
what type of information security threat?
• A. System threats

Document information

Uploaded on
August 8, 2026
Number of pages
209
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$27.29

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BestNurse01
3.0
(2)
Sold
26
Followers
2
Items
3757
Last sold
16 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions