EC-COUNCIL · 212-89

EC-Council 212-89 ECIH v3 Exam Practice Questions

163 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 163 questions in this pack

Question 1

Which of the following terms may be defined as "a measure of possible inability to achieve a goal, objective, or target within a defined security, cost plan and technical limitations that adversely affects the organization's operation and revenues?

  1. Risk
  2. Vulnerability
  3. Threat
  4. Incident Response
Show answer and explanation

Correct answer: A. Risk

Risk is formally defined as the measure of the possibility that an organization will fail to achieve its objectives due to threats exploiting vulnerabilities, considering security constraints, cost limitations, and technical factors. It directly impacts organizational operations and revenues. Vulnerability is a weakness that can be exploited, threat is a potential cause of harm, and incident response is the process of handling security events after they occur.

Why the other options are wrong

  • B. Vulnerability is a weakness or gap in security controls, not a measure of inability to achieve organizational goals.
  • C. Threat is a potential source or cause of harm, not the measure of consequences to the organization.
  • D. Incident response is the action taken after a security event, not a measure of possible inability to achieve objectives.

Question 2

A distributed Denial of Service (DDoS) attack is a more common type of DoS Attack, where a single system is targeted by a large number of infected machines over the Internet. In a DDoS attack, attackers first infect multiple systems which are known as:

  1. Trojans
  2. Zombies
  3. Spyware
  4. Worms
Show answer and explanation

Correct answer: B. Zombies

In a distributed denial of service attack, the infected systems that are controlled by attackers and used to launch the attack are called zombies or bot computers. These compromised machines participate in the attack without the knowledge or consent of their owners. Trojans are malware delivery mechanisms, spyware is surveillance software, and worms are self-replicating malware, but the specific term for controlled systems in a botnet is zombies.

Why the other options are wrong

  • A. Trojans are malicious programs that appear legitimate but can deliver malware; they are not the term for systems used in a DDoS attack.
  • C. Spyware is malware designed to monitor and steal information from users, not to participate in coordinated attacks.
  • D. Worms are self-propagating malware but are not the specific term used for machines controlled in a DDoS attack.

Question 3

The goal of incident response is to handle the incident in a way that minimizes damage and reduces recovery time and cost.

Which of the following does NOT constitute a goal of incident response?

  1. Dealing with human resources department and various employee conflict behaviors.
  2. Using information gathered during incident handling to prepare for handling future incidents in a better way and to provide stronger protection for systems and data.
  3. Helping personal to recover quickly and efficiently from security incidents, minimizing loss or theft and disruption of services.
  4. Dealing properly with legal issues that may arise during incidents.
Show answer and explanation

Correct answer: A. Dealing with human resources department and various employee conflict behaviors.

various employee conflict behaviors. The primary goals of incident response are to minimize damage, reduce recovery time and costs, assist in system recovery and business continuity, learn from incidents to improve future defenses, and handle legal and compliance issues. Dealing with human resources department matters and employee conflict behaviors is a general HR function, not a specific goal of incident response. While incidents may involve employee actions, managing employee conflicts is outside the scope of incident response objectives.

Why the other options are wrong

  • B. Using gathered information to improve future incident handling and strengthen system protection is a core goal of incident response.
  • C. Helping personnel recover quickly and efficiently while minimizing loss and service disruption is a primary goal of incident response.
  • D. Properly addressing legal issues arising from incidents is an important goal of incident response.

See all 10 free questions Get the full pack, US$39

163 practice questions for EC-Council Certified Incident Handler v3 (ECIH), exam 212-89, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 163 questions mapped to the ECIH v3 exam blueprint
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A 212-89 attempt costs US$450. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 163 questions

What makes the ECIH hard

ECIH spends the entire exam on one job: running an incident from the first alert to the post-incident review. Where Security+ or CND give incident response a chapter, ECIH v3 gives it ten modules and 100 questions in three hours, and the v3 update added a dedicated endpoint module for mobile, IoT and OT incidents alongside a cloud module covering AWS, Azure and GCP.

The process questions are where most marks are won or lost. ECIH teaches a nine-step incident handling and response process from preparation through recording, triage, notification, containment, evidence gathering and forensic analysis, eradication, recovery and post-incident activities, and the exam repeatedly asks which step comes next or which action belongs in which step.

The incident-type modules then walk through malware, email, network, web application, cloud, insider threat and endpoint incidents, each with its own detection signs, containment options and eradication and recovery steps. EC-Council sets the passing score per exam form, typically 60% to 85%, so it pays to aim well above the minimum.

About the exam

212-89 (EC-Council Certified Incident Handler v3) earns the ECIH certification. It covers incident handling and response fundamentals, the incident handling and response process, forensic readiness and first response, and handling malware, email, network, web application, cloud, insider threat and endpoint incidents. There are no prerequisites with official training; self-study candidates need one year of information security experience and an eligibility application.

Exam topics (ECIH v3 modules)

  • Introduction to incident handling and response
  • Incident handling and response process
  • Forensic readiness and first response
  • Handling malware incidents
  • Handling email security incidents
  • Handling network security incidents
  • Handling web application security incidents
  • Handling cloud security incidents
  • Handling insider threats
  • Handling endpoint security incidents (mobile, IoT, OT)

100 multiple choice questions, 180 minutes, passing score set per exam form (typically 60% to 85%), US$450 per attempt, ECC Exam Center, Pearson VUE or remote proctoring, certification valid for three years with EC-Council continuing education.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the EC-Council 212-89 ECIH v3 pack?

163 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.