Official Bank 0/342

EC Council Certified Incident Handler (ECIH v2) Exam (212-89) - EC Council Actual Exam Questions

Last updated on April 20, 2026

97% Exam Compliance
342 Total Questions
1
Question

[Introduction to Incident Handling and Response] Raven is a part of an IH&R team and was informed by her manager to handle and lead the removal of the root cause for an incident and to close all attack vectors to prevent similar incidents in the future. Raven notifies the service providers and developers of affected resources. Which of the following steps of the incident handling and response process does Raven need to implement to remove the root cause of the incident?

Options
A

Evidence gathering and forensic analysis

B

Eracicotion

C

Containment

D

Incident triage

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

[Introduction to Incident Handling and Response] Which of the following is a standard framework that provides recommendations for implementing information security controls for organizations that initiate, implement, or maintain information security management systems (ISMSs)?

Options
A

ISO/IEC 27002

B

ISO/IEC 27035

C

PCI DSS

D

RFC 219G

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

[Introduction to Incident Handling and Response] Tibson works as an incident responder for MNC based in Singapore. He is investigating a web application security incident recently faced by the company. The attack is performed on a MS SQL Server hosted by the company. In the detection and analysis phase, he used regular expressions to analyze and detect SQL meta-characters that led to SQL injection attack. Identify the regular expression used by Tibson to detect SQL injection attack on MS SQL Server.

Options
A

/exec(\s|\+)+(s|x)p\w+/ix

B

((\.\.\\)|(\.\.\/))

C

((\.|%2E)(\.|%2E)(\/|%2F|\\|%5C))

D

((\%3C)|<)((\%2F)|\/)*(script)((\%3E)|>)

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

[Introduction to Incident Handling and Response] Which of the following is not a countermeasure to eradicate cloud security incidents?

Options
A

Patch the database vulnerabilities and improve the isolation mechanism

B

Remove the malware files and traces from the affected components

C

Check for data protection at both design and runtime

D

Disable security options such as two factor authentication and CAPTCHA

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

[Incident Handling and Response Process] Which of the following risk management processes identifies the risks, estimates the impact, and determines sources to recommend proper mitigation measures?

Options
A

Risk assessment

B

Risk assumption

C

Risk mitigation

D

Risk avoidance

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.