Home/ec council/Free ECcouncil 212-89 Actual Exam Questions

Free ECcouncil 212-89 Actual Exam Questions

The questions for this exam were last updated on January 7, 2026

Dumps Box (DumpsBox) offers up-to-date practice exam questions for 212-89 certification exam which are developed and validated by Ec-Council subject domain experts certified in ECcouncil 212-89 . These practice questions are update regularly as we keep an eye on any recent changes in 212-89 syllabus, and when there is update our team quickly adjusts the questions. This commitment to providing the best quality exam prep material to certification aspirants is what makes DumpsBox.com the best certification exam prep website. On top of that, our strong, yet strictly moderated, community based feedback keeps the content clean and current. Each question has helpful community discussion that provides it extra perspective and introduces helpful resources for better exam preparation. This also saves students from other outdated practice questions or illicit exam dumps that can have adverse affects on career. Browse through our ECcouncil 212-89 exam questions and pass your exam on first try.

Question No. 1
[Handling and Responding to Web Application Attacks]
Clark, a professional hacker, exploited the web application of a target organization by
tampering the form and parameter values. He successfully exploited the web
application and gained access to the information assets of the organization.
Identify the vulnerability in the web application exploited by the attacker.
Select one option, then reveal solution.
Question No. 2
[Introduction to Incident Handling and Response]
Johnson an incident handler is working on a recent web application attack faced by the
organization. As part of this process, he performed data preprocessing in order to
analyzing and detecting the watering hole attack. He preprocessed the outbound
network traffic data collected from firewalls and proxy servers and started analyzing
the user activities within a certain time period to create time-ordered domain sequences
to perform further analysis on sequential patterns.
Identify the data-preprocessing step performed by Johnson.
Select one option, then reveal solution.
Question No. 3
[Introduction to Incident Handling and Response]
Investigator Ian gives you a drive image to investigate. What type of analysis are you performing?
Select one option, then reveal solution.
Question No. 4
[Introduction to Incident Handling and Response]
QualTech Solutions is a leading security services enterprise. Dickson works as an incident responder
with this firm. He is performing vulnerability assessment to identify
the security problems in the network, using automated tools to identify the hosts, services, and
vulnerabilities present in the enterprise network.
Based on the above scenario, identify the type of vulnerability assessment performed by Dickson.
Select one option, then reveal solution.
Question No. 5
[Risk Assessment and Incident Recovery]
Which of the following risk mitigation strategies involves execution of controls to
reduce the risk factor and brings it to an acceptable level or accepts the potential risk
and continues operating the IT system?
Select one option, then reveal solution.
Question No. 6
[Introduction to Incident Handling and Response]
Robert is an incident handler working for Xsecurity Inc. One day, his organization
faced a massive cyberattack and all the websites related to the organization went
offline. Robert was on duty during the incident and he was responsible to handle the
incident and maintain business continuity. He immediately restored the web application
service with the help of the existing backups.
According to the scenario, which of the following stages of incident handling and
response (IH&R) process does Robert performed?
Select one option, then reveal solution.
Question No. 7
[Introduction to Incident Handling and Response]
Bob, an incident responder at CyberTech Solutions, is investigating a cybercrime attack occurred in
the client company. He acquired the evidence data, preserved it, and started
performing analysis on acquired evidentiary data to identify the source of the crime and the culprit
behind the incident.
Identify the forensic investigation phase in which Bob is currently in.
Select one option, then reveal solution.
Question No. 8
[Handling and Responding to Malware Incidents]
Malicious Micky has moved from the delivery stage to the exploitation stage of the kill chain. This
malware wants to find and report to the command center any useful services on the system. Which
of the following recon attacks is the MOST LIKELY to provide this information?
Select one option, then reveal solution.
Question No. 9
[Introduction to Incident Handling and Response]
James has been appointed as an incident handling and response (IH&R) team lead and
he was assigned to build an IH&R plan along with his own team in the company.
Identify the IH&R process step James is currently working on.
Select one option, then reveal solution.
Question No. 10
[Incident Handling and Response Process]
Which of the following terms refers to vulnerable account management functions, including account
update, recovery of forgotten or lost passwords, and password reset, that might weaken valid
authentication schemes?
Select one option, then reveal solution.
Question No. 11
[Introduction to Incident Handling and Response]
Which of the following methods help incident responders to reduce the false-positive
alert rates and further provide benefits of focusing on topmost priority issues reducing
potential risk and corporate liabilities?
Select one option, then reveal solution.
Question No. 12
[Introduction to Incident Handling and Response]
Otis is an incident handler working in an organization called Delmont. Recently, the organization
faced several setbacks in business, whereby its revenues are decreasing. Otis was asked to take
charge and look into the matter. While auditing the enterprise security, he found traces of an attack
through which proprietary information was stolen from the enterprise network and passed onto
their competitors. Which of the following information security incidents did Delmont face?
Select one option, then reveal solution.
Question No. 13
[Introduction to Incident Handling and Response]
Which of the following GPG18 and Forensic readiness planning (SPF) principles states
that “organizations should adopt a scenario based Forensic Readiness Planning
approach that learns from experience gained within the business”?
Select one option, then reveal solution.
Question No. 14
[Handling and Responding to Malware Incidents]
An attacker traced out and found the kind of websites a target company/individual is
frequently surfing and tested those particular websites to identify any possible
vulnerabilities. When the attacker detected vulnerabilities in the website, the attacker
started injecting malicious script/code into the web application that can redirect the
webpage and download the malware onto the victim’s machine. After infecting the
vulnerable web application, the attacker waited for the victim to access the infected web
application.
Identify the type of attack performed by the attacker.
Select one option, then reveal solution.
Question No. 15
[Introduction to Incident Handling and Response]
Joseph is an incident handling and response (IH&R) team lead in Toro Network Solutions Company.
As a part of IH&R process, Joseph alerted the service providers,
developers, and manufacturers about the affected resources.
Identify the stage of IH&R process Joseph is currently in.
Select one option, then reveal solution.