Free EC-Council 212-89 ECIH v3 practice questions

10 free EC-Council 212-89 ECIH v3 practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 163 questions. Work through them, then open each answer to check your reasoning.

Question 1

Which of the following terms may be defined as "a measure of possible inability to achieve a goal, objective, or target within a defined security, cost plan and technical limitations that adversely affects the organization's operation and revenues?

  1. Risk
  2. Vulnerability
  3. Threat
  4. Incident Response
Show answer and explanation

Correct answer: A. Risk

Risk is formally defined as the measure of the possibility that an organization will fail to achieve its objectives due to threats exploiting vulnerabilities, considering security constraints, cost limitations, and technical factors. It directly impacts organizational operations and revenues. Vulnerability is a weakness that can be exploited, threat is a potential cause of harm, and incident response is the process of handling security events after they occur.

Why the other options are wrong

  • B. Vulnerability is a weakness or gap in security controls, not a measure of inability to achieve organizational goals.
  • C. Threat is a potential source or cause of harm, not the measure of consequences to the organization.
  • D. Incident response is the action taken after a security event, not a measure of possible inability to achieve objectives.

Question 2

A distributed Denial of Service (DDoS) attack is a more common type of DoS Attack, where a single system is targeted by a large number of infected machines over the Internet. In a DDoS attack, attackers first infect multiple systems which are known as:

  1. Trojans
  2. Zombies
  3. Spyware
  4. Worms
Show answer and explanation

Correct answer: B. Zombies

In a distributed denial of service attack, the infected systems that are controlled by attackers and used to launch the attack are called zombies or bot computers. These compromised machines participate in the attack without the knowledge or consent of their owners. Trojans are malware delivery mechanisms, spyware is surveillance software, and worms are self-replicating malware, but the specific term for controlled systems in a botnet is zombies.

Why the other options are wrong

  • A. Trojans are malicious programs that appear legitimate but can deliver malware; they are not the term for systems used in a DDoS attack.
  • C. Spyware is malware designed to monitor and steal information from users, not to participate in coordinated attacks.
  • D. Worms are self-propagating malware but are not the specific term used for machines controlled in a DDoS attack.

Question 3

The goal of incident response is to handle the incident in a way that minimizes damage and reduces recovery time and cost.

Which of the following does NOT constitute a goal of incident response?

  1. Dealing with human resources department and various employee conflict behaviors.
  2. Using information gathered during incident handling to prepare for handling future incidents in a better way and to provide stronger protection for systems and data.
  3. Helping personal to recover quickly and efficiently from security incidents, minimizing loss or theft and disruption of services.
  4. Dealing properly with legal issues that may arise during incidents.
Show answer and explanation

Correct answer: A. Dealing with human resources department and various employee conflict behaviors.

The primary goals of incident response are to minimize damage, reduce recovery time and costs, assist in system recovery and business continuity, learn from incidents to improve future defenses, and handle legal and compliance issues. Dealing with human resources department matters and employee conflict behaviors is a general HR function, not a specific goal of incident response. While incidents may involve employee actions, managing employee conflicts is outside the scope of incident response objectives.

Why the other options are wrong

  • B. Using gathered information to improve future incident handling and strengthen system protection is a core goal of incident response.
  • C. Helping personnel recover quickly and efficiently while minimizing loss and service disruption is a primary goal of incident response.
  • D. Properly addressing legal issues arising from incidents is an important goal of incident response.

Question 4

An organization faced an information security incident where a disgruntled employee passed sensitive access control information to a competitor.

The organization's incident response manager, upon investigation, found that the incident must be handled within a few hours on the same day to maintain business continuity and market competitiveness.

How would you categorize such information security incident?

  1. High level incident
  2. Middle level incident
  3. Ultra-High level incident
  4. Low level incident
Show answer and explanation

Correct answer: B. Middle level incident

EC-Council classifies incidents as low, mid and high level based on how quickly they must be contained. Mid-level incidents are those that must be handled the same day, typically within two to four hours, and include insider disclosure of sensitive information such as access control data to a competitor. The few-hour, same-day handling requirement stated by the incident response manager places this squarely in the middle level category.

Why the other options are wrong

  • A. High level incidents are the most damaging cases, such as widespread system compromise or loss of critical data, and demand immediate handling rather than a few hours on the same day.
  • C. There is no ultra-high level tier in the incident classification scheme, which uses only low, mid and high levels.
  • D. Low level incidents are minor events that can be handled within one working day, which is slower than the response window described here.

Question 5

Business continuity is defined as the ability of an organization to continue to function even after a disastrous event, accomplished through the deployment of redundant hardware and software, the use of fault tolerant systems, as well as a solid backup and recovery strategy.

Identify the plan which is mandatory part of a business continuity plan?

  1. Forensics Procedure Plan
  2. Business Recovery Plan
  3. Sales and Marketing plan
  4. New business strategy plan
Show answer and explanation

Correct answer: B. Business Recovery Plan

A Business Recovery Plan is a mandatory component of business continuity planning. It outlines the procedures and strategies for restoring business operations, systems, and services after a disastrous event. It works in conjunction with redundant systems, fault tolerance, and backup/recovery strategies to ensure organizational resilience. Forensics procedures relate to investigation rather than continuity, while sales and marketing plans and new business strategy plans are operational rather than continuity-focused.

Why the other options are wrong

  • A. Forensics procedure plans are focused on investigation and analysis of security incidents, not on maintaining or restoring business continuity.
  • C. Sales and marketing plans are business strategy documents unrelated to the disaster recovery and continuity aspects of business continuity planning.
  • D. New business strategy plans address future business direction rather than recovery from disastrous events.

Question 6

The flow chart gives a view of different roles played by the different personnel of CSIRT.

Identify the incident response personnel denoted by A, B, C, D, E, F and G.

Exhibit for question 6

  1. A-Incident Analyst, -ncident Coordinator, -ublic Relations, D-Administrator, -uman Resource, F-Constituency, G-Incident Manager
  2. -ncident Coordinator, B-Incident Analyst, -ublic Relations, D-Administrator, -uman Resource, F-Constituency, G-Incident Manager
  3. -ncident Coordinator, -onstituency, C-Administrator, D-Incident Manager, -uman Resource, F-Incident Analyst, G-Public relations
  4. -ncident Manager, B-Incident Analyst, -ublic Relations, D-Administrator, -uman Resource, F-Constituency, G-Incident Coordinator
Show answer and explanation

Correct answer: C. -ncident Coordinator, -onstituency, C-Administrator, D-Incident Manager, -uman Resource, F-Incident Analyst, G-Public relations

Administrator, D-Incident Manager, -uman Resource, F-Incident Analyst, -ublic relations Each box in the flow chart states the duty of the role beside it. A acts as a link between different groups, which is the Incident Coordinator; B is a stakeholder in the incident, which is the Constituency; the centre role ensures office operations return to a normal situation, which is the Administrator; D handles an incident from a management and technical point of view, which is the Incident Manager; E is responsible for the human aspects of the disaster, which is Human Resource; F eradicates and recovers from the incident, which is the Incident Analyst; and G is responsible for stakeholder communications, which is Public Relations.

Why the other options are wrong

  • A. It labels position A as the Incident Analyst and position B as the Incident Coordinator, but A is described as the link between different groups and B as a stakeholder in the incident.
  • B. It labels position B as the Incident Analyst even though that box is described as a stakeholder in the incident, which is the Constituency.
  • D. It labels position A as the Incident Manager and position G as the Incident Coordinator, yet A is the link between groups and G is responsible for stakeholder communications, which is Public Relations.

Question 7

Which of the following is an appropriate flow of the incident recovery steps?

  1. System Operation-System Restoration-System Validation-System Monitoring
  2. System Validation-System Operation-System Restoration-System Monitoring
  3. System Restoration-System Monitoring-System Validation-System Operations
  4. System Restoration-System Validation-System Operations-System Monitoring
Show answer and explanation

Correct answer: D. System Restoration-System Validation-System Operations-System Monitoring

Operations-System Monitoring The correct sequence for incident recovery steps is system restoration, system validation, system operations, and system monitoring. First, the affected systems are restored to a known good state or repaired. Second, the restored systems are validated to ensure they function correctly and securely. Third, systems are returned to normal operation. Finally, systems are continuously monitored to detect any residual issues or new threats. This logical progression ensures proper recovery and ongoing security.

Why the other options are wrong

  • A. Beginning with system operation skips the critical restoration and validation phases needed before returning to normal operation.
  • B. Starting with validation before restoration is illogical since there is nothing restored to validate yet.
  • C. Placing monitoring before operations and validation reverses the logical recovery sequence.

Question 8

A computer Risk Policy is a set of ideas to be implemented to overcome the risk associated with computer security incidents.

Identify the procedure that is NOT part of the computer risk policy?

  1. Procedure to identify security funds to hedge risk
  2. Procedure to monitor the efficiency of security controls
  3. Procedure for the ongoing training of employees authorized to access the system
  4. Provisions for continuing support if there is an interruption in the system or if the system crashes
Show answer and explanation

Correct answer: A. Procedure to identify security funds to hedge risk

A computer risk policy establishes procedures for managing security risks through control implementation, employee training, system monitoring, and continuity provisions. The procedure to identify security funds to hedge risk is a financial risk management strategy used in insurance and investment contexts, not a standard component of computer security risk policy. The other options represent core risk policy elements: monitoring control effectiveness, training authorized users, and maintaining system support during interruptions.

Why the other options are wrong

  • B. Monitoring the efficiency of security controls is a fundamental component of risk policy to ensure controls remain effective.
  • C. Ongoing training of authorized system users is essential to maintain security awareness and compliance within risk policy.
  • D. Provisions for continuing support during system interruptions or crashes are necessary for business continuity and risk mitigation.

Question 9

Identify the network security incident where intended authorized users are prevented from using system, network, or applications by flooding the network with high volume of traffic that consumes all existing network resources.

  1. URL Manipulation
  2. XSS Attack
  3. SQL Injection
  4. Denial of Service Attack
Show answer and explanation

Correct answer: D. Denial of Service Attack

A denial of service attack is a network security incident where attackers prevent authorized users from accessing systems, networks, or applications by overwhelming them with hig-olume traffic that consumes all available resources. This flooding technique exhausts bandwidth, processing power, or memory, making legitimate service unavailable. URL manipulation, XSS attacks, and SQL injection are application-layer attacks targeting specific vulnerabilities in web applications rather than network resource exhaustion.

Why the other options are wrong

  • A. URL manipulation involves tampering with URL parameters to bypass security controls or access unauthorized resources.
  • B. Cross-site scripting (XSS) is an application attack that injects malicious scripts into web pages viewed by other users.
  • C. SQL injection is a database attack that inserts malicious SQL code to manipulate or extract data from databases.

Question 10

Incident handling and response steps help you to detect, identify, respond and manage an incident.

Which of the following steps focus on limiting the scope and extent of an incident?

  1. Eradication
  2. Containment
  3. Identification
  4. Data collection
Show answer and explanation

Correct answer: B. Containment

Containment is the incident response phase focused on limiting the scope and extent of an incident by isolating affected systems, stopping the attack progression, and preventing further damage. This phase occurs after identification and before eradication, with the primary goal of stopping the spread of the incident.

Why the other options are wrong

  • A. Eradication removes the cause of the incident from systems but does not focus on limiting scope.
  • C. Identification determines what has occurred but does not take actions to limit the incident's extent.
  • D. Data collection gathers information about the incident but does not actively limit its scope.

That was 10 of 163.

The full EC-Council 212-89 ECIH v3 pack has all 163 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack