Official Bank 0/305

EC Council Certified Incident Handler (ECIH v2) Exam (212-89) - EC-Council Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
305 Total Questions
1
Question
A large insurance enterprise recently completed an internal phishing simulation to evaluate its incident reporting workflow. Upon reviewing the ticketing system logs, the IR lead discovered that several phishing-related reports submitted by employees had been mistakenly logged as routine IT
service requests. This misrouting prevented timely review by the IH&R team, delaying appropriate
follow-up actions. The root cause was traced to frontline support staff misinterpreting subtle incident indicators as generic technical issues. Recognizing the potential risk this poses to early issue detection, the Chief Information Security Officer directed an overhaul of the alert-handling procedures. This included refining the reporting workflow, embedding clearer triage rules within the ticketing platform, and initiating refresher training to strengthen tier-one decision-making when handling ambiguous user reports. Which IR concern is being addressed through this corrective action?
Options
A Enhancing containment strategies by integrating identity management systems
B Reducing alert fatigue in SOC environments by disabling false positives
C Configuring asset lookup fields in the ticketing system to support hardware inventory tracking
D Improving accuracy in initial threat categorization and escalation
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Identify Sarbanes–Oxley Act (SOX) Title, which consists of only one section, that includes measures designed to help restore investor confidence in the reporting of securities analysts.
Options
A Title IX: White-Collar-Crime Penalty Enhancement
B Title VIII: Corporate and Criminal Fraud Accountability
C Title V: Analyst Conflicts of Interest
D Title VII: Studies and Reports
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Michael is an incident handler at CyberTech Solutions. He is performing detection and analysis of a cloud security incident. He is analyzing the file systems, slack spaces, and metadata of the storage units to find hidden malware and evidence of malice. Identify the cloud security incident handled by Michael.
Options
A Storage-related incident
B Server-related incident
C Network-related incident
D Application-related incident
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Ross is an incident manager (IM) at an organization, and his team provides support to all users in the organization who are affected by threats or attacks. David, who is the organization's internal auditor, is also part of Ross's incident response team. Which of the following is David's responsibility?
Options
A Identify and report security loopholes to the management for necessary action.
B Configure information security controls.
C Perform the- necessary action to block the network traffic from the suspectoc intruder.
D Coordinate incident containment activities with the information security officer (ISO).
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
James is working as an incident responder at CyberSol Inc. The management instructed James to investigate a cybersecurity incident that recently happened in the company. As a part of the investigation process, James started collecting volatile information from a system running on Windows operating system.

Which of the following commands helps James in determining all the executable files for running processes?
Options
A doskey/history
B cate A &. time ,/t
C netstat -ab
D top
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.