Official Bank 0/305

EC Council Certified Incident Handler (ECIH v2) Exam (212-89) - EC-Council Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
305 Total Questions
1
Question
DigitalSoft, a major software development firm, recently discovered unauthorized access to its codebase. The culprit was a disgruntled employee who had been overlooked for a promotion. The company wants to prevent such insider threats in the future. What is the most effective measure it can implement?
Options
A Conduct regular audits of user access and use behavior analytics.
B Implement a strict hierarchy where only senior employees have access to sensitive data.
C Implement mandatory password changes every 30 days.
D Use biometric authentication for accessing sensitive data.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Which of the following best describes an email issued as an attack medium, in which several messages are sent to a mailbox to cause overflow?
Options
A Masquerading
B Email-bombing
C Smurf attack
D Spoofing
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
A large insurance enterprise recently completed an internal phishing simulation to evaluate its incident reporting workflow. Upon reviewing the ticketing system logs, the IR lead discovered that several phishing-related reports submitted by employees had been mistakenly logged as routine IT
service requests. This misrouting prevented timely review by the IH&R team, delaying appropriate
follow-up actions. The root cause was traced to frontline support staff misinterpreting subtle incident indicators as generic technical issues. Recognizing the potential risk this poses to early issue detection, the Chief Information Security Officer directed an overhaul of the alert-handling procedures. This included refining the reporting workflow, embedding clearer triage rules within the ticketing platform, and initiating refresher training to strengthen tier-one decision-making when handling ambiguous user reports. Which IR concern is being addressed through this corrective action?
Options
A Enhancing containment strategies by integrating identity management systems
B Reducing alert fatigue in SOC environments by disabling false positives
C Configuring asset lookup fields in the ticketing system to support hardware inventory tracking
D Improving accuracy in initial threat categorization and escalation
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Which of the following GPG18 and Forensic readiness planning (SPF) principles states that “organizations should adopt a scenario based Forensic Readiness Planning approach that learns from experience gained within the business”?
Options
A Principle 7
B Principle 2
C Principle 3
D Principle 5
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Which of the following is an Inappropriate usage incident?
Options
A Denial-of-service attack
B Access-control attack
C Reconnaissance attack
D Insider threat
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.