ECIH 212-89 EXAM: 200 VERIFIED PRACTICE
QUESTIONS WITH DETAILED RATIONALES |
2026/2027 LATEST UPDATE | 100% PASS
GUARANTEE
EC-Council Certified Incident Handler (ECIH) v3
212-89 Practice Questions
Domain 1: Introduction to Incident Handling and
Response
Q1. An incident handler receives a report from a
user who believes a nation-state actor is attacking
the organization. The handler reviews the user's
screenshots, asks validation questions, checks
internal resources, and assesses the current
network condition. Which phase of the Incident
Response (IR) process is the handler performing?
• A. Containment
• B. Eradication
• C. Recovery
, • D. Detection and Analysis
Correct ☑VERIFIED ANSWER: D
Rationale: The handler is verifying the validity of a
potential incident, assessing its nature and scope,
and determining whether a real attack is occurring.
This is the Detection and Analysis (also called
Identification) phase, where alerts and reports are
investigated to confirm incidents .
Q2. Which of the following flows is the correct
sequence of stages in the Incident Response
process?
• A. Preparation → Identification → Containment
→ Eradication → Recovery → Follow-up
• B. Identification → Containment → Eradication
→ Recovery → Preparation → Follow-up
• C. Containment → Eradication → Recovery →
Follow-up → Identification → Preparation
, • D. Preparation → Containment → Identification
→ Recovery → Eradication → Follow-up
Correct ☑VERIFIED ANSWER: A
Rationale: The correct incident response lifecycle
flow is Preparation, followed
by Identification (Detection and Analysis),
then Containment, Eradication, Recovery, and
finally Post-Incident Activities (Follow-up) .
Q3. Which risk is defined as the risk remaining after
the implementation of all possible controls?
• A. Inherent risk
• B. Residual risk
• C. Quantitative risk
• D. Qualitative risk
Correct ☑VERIFIED ANSWER: B
Rationale: Residual risk is the amount of risk that
remains after an organization has implemented all
, possible security controls and countermeasures.
Inherent risk exists before any controls are applied .
Q4. Motive (Goal) + Method + Vulnerability equals
which of the following?
• A. Security policy
• B. Attacks
• C. Defense-in-depth
• D. Risk
Correct ☑VERIFIED ANSWER: B
Rationale: The formula Motive + Method +
Vulnerability = Attack describes how an attack
occurs. A threat actor has a motive (goal), uses a
method (technique or tool), and exploits a
vulnerability in the target system—resulting in an
attack .
QUESTIONS WITH DETAILED RATIONALES |
2026/2027 LATEST UPDATE | 100% PASS
GUARANTEE
EC-Council Certified Incident Handler (ECIH) v3
212-89 Practice Questions
Domain 1: Introduction to Incident Handling and
Response
Q1. An incident handler receives a report from a
user who believes a nation-state actor is attacking
the organization. The handler reviews the user's
screenshots, asks validation questions, checks
internal resources, and assesses the current
network condition. Which phase of the Incident
Response (IR) process is the handler performing?
• A. Containment
• B. Eradication
• C. Recovery
, • D. Detection and Analysis
Correct ☑VERIFIED ANSWER: D
Rationale: The handler is verifying the validity of a
potential incident, assessing its nature and scope,
and determining whether a real attack is occurring.
This is the Detection and Analysis (also called
Identification) phase, where alerts and reports are
investigated to confirm incidents .
Q2. Which of the following flows is the correct
sequence of stages in the Incident Response
process?
• A. Preparation → Identification → Containment
→ Eradication → Recovery → Follow-up
• B. Identification → Containment → Eradication
→ Recovery → Preparation → Follow-up
• C. Containment → Eradication → Recovery →
Follow-up → Identification → Preparation
, • D. Preparation → Containment → Identification
→ Recovery → Eradication → Follow-up
Correct ☑VERIFIED ANSWER: A
Rationale: The correct incident response lifecycle
flow is Preparation, followed
by Identification (Detection and Analysis),
then Containment, Eradication, Recovery, and
finally Post-Incident Activities (Follow-up) .
Q3. Which risk is defined as the risk remaining after
the implementation of all possible controls?
• A. Inherent risk
• B. Residual risk
• C. Quantitative risk
• D. Qualitative risk
Correct ☑VERIFIED ANSWER: B
Rationale: Residual risk is the amount of risk that
remains after an organization has implemented all
, possible security controls and countermeasures.
Inherent risk exists before any controls are applied .
Q4. Motive (Goal) + Method + Vulnerability equals
which of the following?
• A. Security policy
• B. Attacks
• C. Defense-in-depth
• D. Risk
Correct ☑VERIFIED ANSWER: B
Rationale: The formula Motive + Method +
Vulnerability = Attack describes how an attack
occurs. A threat actor has a motive (goal), uses a
method (technique or tool), and exploits a
vulnerability in the target system—resulting in an
attack .