163 practice questions for EC-Council Certified Incident Handler v3 (ECIH), exam 212-89, with full explanations.
Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.
- 163 questions mapped to the ECIH v3 exam blueprint
- Answers and explanations for every question, including the wrong options
- A questions-only PDF for timed practice runs
- Instant delivery by email the moment you check out
- Free monthly updates for as long as the exam is live
- Pass or your money back
A 212-89 attempt costs US$450. This pack is US$39, paid once.
Try 10 questions free before you buy.
Last updated September 2026 · 163 questions
What makes the ECIH hard
ECIH spends the entire exam on one job: running an incident from the first alert to the post-incident review. Where Security+ or CND give incident response a chapter, ECIH v3 gives it ten modules and 100 questions in three hours, and the v3 update added a dedicated endpoint module for mobile, IoT and OT incidents alongside a cloud module covering AWS, Azure and GCP.
The process questions are where most marks are won or lost. ECIH teaches a nine-step incident handling and response process from preparation through recording, triage, notification, containment, evidence gathering and forensic analysis, eradication, recovery and post-incident activities, and the exam repeatedly asks which step comes next or which action belongs in which step.
The incident-type modules then walk through malware, email, network, web application, cloud, insider threat and endpoint incidents, each with its own detection signs, containment options and eradication and recovery steps. EC-Council sets the passing score per exam form, typically 60% to 85%, so it pays to aim well above the minimum.
About the exam
212-89 (EC-Council Certified Incident Handler v3) earns the ECIH certification. It covers incident handling and response fundamentals, the incident handling and response process, forensic readiness and first response, and handling malware, email, network, web application, cloud, insider threat and endpoint incidents. There are no prerequisites with official training; self-study candidates need one year of information security experience and an eligibility application.
Exam topics (ECIH v3 modules)
- Introduction to incident handling and response
- Incident handling and response process
- Forensic readiness and first response
- Handling malware incidents
- Handling email security incidents
- Handling network security incidents
- Handling web application security incidents
- Handling cloud security incidents
- Handling insider threats
- Handling endpoint security incidents (mobile, IoT, OT)
100 multiple choice questions, 180 minutes, passing score set per exam form (typically 60% to 85%), US$450 per attempt, ECC Exam Center, Pearson VUE or remote proctoring, certification valid for three years with EC-Council continuing education.









Reviews
There are no reviews yet.