EC Council Certified Incident Handler (ECIH v2) Exam (212-89) - EC Council Actual Exam Questions
Last updated on April 20, 2026
[Introduction to Incident Handling and Response] Raven is a part of an IH&R team and was informed by her manager to handle and lead the removal of the root cause for an incident and to close all attack vectors to prevent similar incidents in the future. Raven notifies the service providers and developers of affected resources. Which of the following steps of the incident handling and response process does Raven need to implement to remove the root cause of the incident?
Evidence gathering and forensic analysis
Eracicotion
Containment
Incident triage
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
[Introduction to Incident Handling and Response] Which of the following is a standard framework that provides recommendations for implementing information security controls for organizations that initiate, implement, or maintain information security management systems (ISMSs)?
ISO/IEC 27002
ISO/IEC 27035
PCI DSS
RFC 219G
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
[Introduction to Incident Handling and Response] Tibson works as an incident responder for MNC based in Singapore. He is investigating a web application security incident recently faced by the company. The attack is performed on a MS SQL Server hosted by the company. In the detection and analysis phase, he used regular expressions to analyze and detect SQL meta-characters that led to SQL injection attack. Identify the regular expression used by Tibson to detect SQL injection attack on MS SQL Server.
/exec(\s|\+)+(s|x)p\w+/ix
((\.\.\\)|(\.\.\/))
((\.|%2E)(\.|%2E)(\/|%2F|\\|%5C))
((\%3C)|<)((\%2F)|\/)*(script)((\%3E)|>)
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
[Introduction to Incident Handling and Response] Which of the following is not a countermeasure to eradicate cloud security incidents?
Patch the database vulnerabilities and improve the isolation mechanism
Remove the malware files and traces from the affected components
Check for data protection at both design and runtime
Disable security options such as two factor authentication and CAPTCHA
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
[Incident Handling and Response Process] Which of the following risk management processes identifies the risks, estimates the impact, and determines sources to recommend proper mitigation measures?
Risk assessment
Risk assumption
Risk mitigation
Risk avoidance
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Finish Practice?
Are you sure you want to finish? This will end your practice session.