[Jun-2026] 212-89 Free PDF from ITPassLeader [Q74-Q95]

Share

Jun-2026 Latest ITPassLeader 212-89 Exam Dumps with PDF and Exam Engine Free Updated Today!

Following are some new 212-89 Real Exam Questions!

NEW QUESTION # 74
James has been appointed as an incident handling and response (IH&R) team lead and he was assigned to build an IH&R plan along with his own team in the company.
Identify the IH&R process step James is currently working on.

  • A. Recovery
  • B. Notification
  • C. Eradication
  • D. Preparation

Answer: D

Explanation:
In the context of incident handling and response (IH&R), the preparation phase is the initial step where teams and resources are organized to effectively respond to potential security incidents. This phase involves building the IH&R team, developing incident response plans and policies, setting up communication channels, and ensuring that the team has the necessary tools and authority to act. James, being assigned to build an IH&R plan and organize his team, is engaging in the preparation step of the incident response process. This foundational step is crucial for ensuring a coordinated and efficient response to incidents when they occur.
References:The importance of the preparation phase in the incident response lifecycle is emphasized in various cybersecurity frameworks and guidelines, including those covered in ECIH v3 certification materials, which detail the roles, responsibilities, and planning necessary to establish an effective incident response capability.


NEW QUESTION # 75
SpaceTech Innovations, specializing in space exploration software, encountered malware that camouflaged itself within proprietary algorithms. This stealthy malware intermittently transmitted blueprints to an unknown receiver. With a state-of-the-art code analyzer and a network traffic analyzer at hand, what's the ideal first step?

  • A. Inform partners and stakeholders of potential data leaks.
  • B. Update all proprietary software hoping to overwrite the malware.
  • C. Run the code analyzer to detect and remove the hidden malware.
  • D. Use the network traffic analyzer to pinpoint and halt the blueprint transmission.

Answer: D

Explanation:
This incident involves active data exfiltration, which ECIH malware handling guidance identifies as a critical containment priority. When malware is actively transmitting sensitive data, stopping the leak takes precedence over deep analysis.
Option B is correct because using the network traffic analyzer to identify and halt outbound malicious communication immediately prevents further data loss. ECIH stresses that containment actions must first stop harm before eradication and recovery.
Option A supports eradication but does not immediately stop exfiltration. Option C is premature. Option D is unreliable and risks reinfection.
Therefore, halting malicious transmissions is the ideal first step.


NEW QUESTION # 76
The flow chart gives a view of different roles played by the different personnel of CSIRT. Identify the incident
response personnel denoted by A, B, C, D, E, F and G.

  • A. A- Incident Manager, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-
    Constituency, G-Incident Coordinator
  • B. A- Incident Coordinator, B- Constituency, C-Administrator, D-Incident Manager, E- Human Resource, F-
    Incident Analyst, G-Public relations
  • C. A- Incident Coordinator, B-Incident Analyst, C- Public Relations, D-Administrator, E- Human Resource, F-
    Constituency, G-Incident Manager
  • D. A-Incident Analyst, B- Incident Coordinator, C- Public Relations, D-Administrator, E- Human Resource, F-
    Constituency, G-Incident Manager

Answer: B


NEW QUESTION # 77
SafePay, an online payment portal, recently introduced an advanced search feature. A week later, users reported unauthorized transactions. Investigation showed attackers exploited advanced search strings and a previously unidentified vulnerability. What is SafePay's best immediate action?

  • A. Implement multi-factor authentication for all user accounts.
  • B. Require users to re-authenticate before accessing advanced search.
  • C. Increase the encryption level of stored user data.
  • D. Disable the advanced search feature and revert to the older version.

Answer: D

Explanation:
Comprehensive and Detailed Explanation (ECIH-aligned):
This scenario describes an active exploitation of a vulnerable application feature. The ECIH Web Application Incident Handling module emphasizes that when a specific feature is being abused, immediate containment requires removing or disabling that attack surface.
Option B is correct because disabling the vulnerable advanced search feature immediately stops further exploitation while allowing the team to analyze and remediate the flaw safely. ECIH warns against leaving known-vulnerable functionality active during investigation.
Options A and C improve authentication but do not stop exploitation of backend logic. Option D protects stored data but does not prevent further abuse.
Therefore, disabling the exploited feature is the best immediate action.


NEW QUESTION # 78
Nervous Nat often sends emails with screenshots of what he thinks are serious incidents, but they always turn out to be false positives. Today, he sends another screenshot, suspecting a nation-state attack. As usual, you go through your list of questions, check your resources for information to determine whether the screenshot shows a real attack, and determine the condition of your network. Which step of IR did you just perform?

  • A. Detection anc analysis (or identification)
  • B. Preparation
  • C. Remediation
  • D. Recovery

Answer: A

Explanation:
When you receive a screenshot from Nervous Nat and go through a list of questions, check resources for information to determine the nature of the screenshot, and assess the condition of your network, you are engaging in the Detection and Analysis (or Identification) phase of Incident Response (IR). This phase is about identifying potential security incidents based on reported concerns, anomalies detected by security tools, or through the analysis of security alerts. In this scenario, despite the historical context of false positives, each report is treated seriously, requiring you to collect and analyze information to determine whether a real attack is happening. This involves verifying the validity of the incident, assessing its nature, scope, and impact, and deciding on the appropriate next steps. The detection and analysis phase is critical for determining the course of the IR process, including whether escalation is needed and what response measures should be initiated.References:The ECIH v3 certification materials outline the Incident Response process, detailing steps from preparation, detection and analysis, containment, eradication, and recovery, to post-incident activities, highlighting the importance of thorough detection and analysis as the foundation for effective incident management.


NEW QUESTION # 79
Ikeo Corp.hired an incident response team to assess the enterprise security. As part of the incident handling and response process, the IR team is reviewing the current se cunty policies implemented by the enterprise. The IR team finds that employees of the organization do not have any restrictions on Internet access: they are allowed to visit any site, download any appl cation, and access a computer or network from a remote location. Considering this as the main security threat, the IR team plans to change this policy as it can be easily exploited by attackers.
Which of the following security policies is the IR team planning to modify?

  • A. Promiscuous policy
  • B. Permissive policy
  • C. Prudent policy
  • D. Paranoid policy

Answer: A


NEW QUESTION # 80
Ren is assigned to handle a security incident of an organization. He is tasked with forensics investigation to find the evidence needed by the management. Which of the following steps falls under the investigation phase of the computer forensics investigation process?

  • A. Risk assessment
  • B. Setup a computer forensics lab
  • C. Secure the evidence
  • D. Evidence assessment

Answer: D

Explanation:
Evidence assessment is a critical step in the investigation phase of the computer forensics process. This step involves evaluating the evidence collected to determine its relevance and significance to the case at hand. It includes analyzing the secured data to identify what information can be used as evidence, its integrity, and how it can be related to the security incident. This phase is pivotal as it helps in building a coherent understanding of the incident and in establishing facts that can be presented in management reports or legal proceedings.
References:The Certified Incident Handler (ECIH v3) by EC-Council includes a comprehensive discussion on the computer forensics investigation process, detailing steps from securing evidence to analyzing and assessing it within the context of an investigation.


NEW QUESTION # 81
Which of the following is an inappropriate usage incident?

  • A. Denial-of-service attack
  • B. Insider threat
  • C. Reconnaissance attack
  • D. Access-control attack

Answer: B


NEW QUESTION # 82
Which of the following encoding techniques replaces unusual ASCII characters with "%" followed by the character's two-digit ASCII code expressed in hexadecimal?

  • A. URL encoding
  • B. Base 64 encoding
  • C. Unicode encoding
  • D. HTML encoding

Answer: A


NEW QUESTION # 83
During routine monitoring, a cloud-based application hosting provider detects an anomaly suggesting an ongoing DDoS attack targeting one of its hosted applications. The provider's incident response team must quickly mitigate the attack while ensuring minimal service disruption. Which of the following strategies should they prioritize?

  • A. Immediately scale up application resources to absorb the attack impact.
  • B. Temporarily take the affected application offline to stop the attack.
  • C. Implement rate limiting and challenge-response tests to differentiate between legitimate and malicious traffic.
  • D. Enable geo-restriction to block incoming traffic from regions not serviced by the application.

Answer: C

Explanation:
The ECIH Network Security Incident Handling module emphasizes maintaining availability while mitigating denial-of-service attacks. The objective is not simply to stop traffic, but to distinguish malicious traffic from legitimate user requests.
Option D is correct because rate limiting and challenge-response mechanisms (such as CAPTCHA or SYN cookies) allow legitimate traffic to continue while throttling or blocking malicious requests. This approach minimizes service disruption while effectively containing the attack.
Option A may increase costs and still fail against large-scale DDoS attacks. Option B can unintentionally block legitimate users. Option C contradicts ECIH guidance by unnecessarily impacting availability.
ECIH stresses proportional and intelligent mitigation strategies that preserve business continuity. Therefore, implementing rate limiting and challenge-response mechanisms is the preferred strategy.


NEW QUESTION # 84
Which of the following risk mitigation strategies involves the execution of controls to reduce the risk factor and bring it to an acceptable level, or accepts the potential risk and continues operating the IT system?

  • A. Risk avoidance
  • B. Risk transference
  • C. Risk assumption
  • D. Risk planning

Answer: C


NEW QUESTION # 85
Investigator Ian gives you a drive image to investigate. What type of analysis are you performing?

  • A. Static
  • B. Real-time
  • C. Live
  • D. Dynamic

Answer: A

Explanation:
When Investigator Ian gives you a drive image to investigate, the type of analysis you are performing is static analysis. Static analysis involves examining the contents of a drive, file, or binary without executing the system or the application. It's about analyzing the data at rest. This type of analysis is crucial for forensics investigations because it allows for the examination of files, directories, and system information without altering any state or data, thereby preserving the integrity of the evidence. Static analysis is contrasted with dynamic analysis, which involves analyzing a system in operation (real-time or live) or executing the application to observe its behavior.References:Incident Handler (ECIH v3) courses and study guides highlight the importance of static analysis in digital forensics, detailing methods for examining disk images, files, and other digital artifacts to gather evidence without compromising its integrity.


NEW QUESTION # 86
Which of the following is an attack that occurs when a malicious program causes a user's browser to perform man unwanted action on a trusted site for which the user is currently authenticated?

  • A. Cross-site scripting
  • B. SQL injection
  • C. Insecure direct object references
  • D. Cross-site request forgery

Answer: D


NEW QUESTION # 87
Network Ned is the security administrator for a company. He is going to place the company's new web server into production.
Into which of the following zones should he place the server to best protect the company's network?

  • A. Honeypot
  • B. DMZ
  • C. Sandbox
  • D. Intranet

Answer: D


NEW QUESTION # 88
After a web application attack, HealthFirst traced the breach to an insecure Direct Object Reference (IDOR) vulnerability. They want to patch it and fortify the app. What should be their primary action?

  • A. Implement role-based access controls (RBAC) for data access.
  • B. Conduct regular penetration testing on the application.
  • C. Encrypt all data at rest and in transit.
  • D. Introduce a WAF with default rules.

Answer: A

Explanation:
IDOR is fundamentally an authorization flaw: the application exposes object identifiers (IDs) and fails to enforce that the requesting user is allowed to access that object. The primary remediation is to implement robust authorization checks-commonly RBAC (C) plus object-level access control-so every request verifies user identity and privileges against the requested resource.
(A) WAFs can help with certain injection patterns, but default WAF rules rarely fix logical authorization flaws like IDOR. A WAF also risks false positives and doesn't replace secure design. (B) pen testing is important for assurance, but it's not the primary patch; it helps validate the fix later. (D) encryption protects confidentiality in transit/at rest, but it does not prevent an authenticated user from accessing another user's records if authorization checks are missing.
Therefore (C) is the correct first-line fix: enforce authorization server-side, avoid predictable identifiers, and ensure access control is consistently applied across all endpoints (including APIs).


NEW QUESTION # 89
Your company sells SaaS, and your company itself is hosted in the cloud (using it as a PaaS). In case of a malware incident in your customer's database, who is responsible for eradicating the malicious software?

  • A. The customer
  • B. Your company
  • C. The PaaS provider
  • D. Building management

Answer: B

Explanation:
In the scenario where your company sells Software as a Service (SaaS) and is hosted on the cloud using it as a Platform as a Service (PaaS), your company is responsible for eradicating malware in your customer's database. This is because, as the SaaS provider, your company manages the software and is responsible for its security and maintenance, including the databases that store customer data. While the PaaS provider is responsible for the underlying infrastructure, platform, and possibly some middleware security aspects, the application layer security, including data and application management, falls to the SaaS provider. Building management would not be involved in digital security matters, and while customers are responsible for their data, the actual software maintenance and security in a SaaS model are the provider's responsibility.
References:Incident Handler (ECIH v3) certification materials often discuss cloud service models (IaaS, PaaS, SaaS) and their associated security responsibilities, highlighting the importance of understanding who is responsible for what in cloud environments.


NEW QUESTION # 90
A computer Risk Policy is a set of ideas to be implemented to overcome the risk associated with computer security incidents. Identify the procedure that is NOT part of the computer risk policy?

  • A. Procedure for the ongoing training of employees authorized to access the system
  • B. Provisions for continuing support if there is an interruption in the system or if the system crashes
  • C. Procedure to monitor the efficiency of security controls
  • D. Procedure to identify security funds to hedge risk

Answer: A


NEW QUESTION # 91
The program that helps to train people to be better prepared to respond to emergency situations in their communities is known as:

  • A. All the above
  • B. Incident Response Team (IRT)
  • C. Security Incident Response Team (SIRT)
  • D. Community Emergency Response Team (CERT)

Answer: D


NEW QUESTION # 92
Which of the following is a common tool used to help detect malicious internal or compromised actors?

  • A. User behavior analytics
  • B. SOC2 compliance report
  • C. Log forward ng
  • D. Syslog configuration

Answer: A

Explanation:
User Behavior Analytics (UBA) is a cybersecurity process or tool that utilizes machine learning, algorithms, and statistical analyses to detect potentially harmful activities within an organization's network by comparing them against established patterns of users' behavior. It is particularly effective in identifying malicious internal actors or compromised users who may be conducting activities that deviate from their normal behavior patterns, such as accessing unauthorized data or systems, excessive file downloads, or unusual login times. UBA tools can flag these activities for further investigation, often before traditional security tools detect a breach. In contrast, SOC2 compliance reports, log forwarding, and syslog configuration are important for maintaining and auditing security standards and for infrastructure monitoring, but they are not primarily focused on detecting malicious behavior based on deviations from established user behavior patterns.
References:The Incident Handler (ECIH v3) curriculum discusses various tools and methodologies for detecting and responding to security incidents, highlighting User Behavior Analytics as a key tool for identifying insider threats and compromised accounts through behavioral monitoring and analysis.


NEW QUESTION # 93
Darwin is an attacker residing within the organization and is performing network sniffing by running his system in promiscuous mode. He is capturing and viewing all the network packets transmitted within the organization. Edwin is an incident handler in the same organization.
In the above situation, which of the following Nmap commands Edwin must use to detect Darwin's system that is running in promiscuous mode?

  • A. nmap --script hostmap
  • B. nmap --script=sniffer-detect [Target IP Address/Range of IP addresses]
  • C. nmap -sU -p 500
  • D. nmap -sV -T4 -O -F -version-light

Answer: B


NEW QUESTION # 94
Which of the following terms refers to the personnel that the incident handling and response (IH&R) team must contact to report the incident and obtain the necessary permissions?

  • A. Ticketing
  • B. Civil litigation
  • C. Criminal referral
  • D. Point of contact

Answer: D

Explanation:
In the context of incident handling and response (IH&R), the term "Point of contact" refers to individuals or departments within an organization that are designated to be contacted by the IH&R team in case of an incident. These personnel are crucial for the reporting process and for obtaining the necessary permissions to proceed with incident response activities. They serve as the liaison between the incident response team and other parts of the organization, external agencies, or partners involved in the incident response process. The point of contact is responsible for facilitating communication, coordinating actions, and ensuring that the appropriate stakeholders are engaged in the response to an incident. This role is pivotal in ensuring a swift and effective response to security incidents, minimizing damage, and restoring operations.
References:Incident Handler (ECIH v3) courses and study guides typically emphasize the importance of clearly defined roles and responsibilities within the incident response process, including the designation of points of contact.


NEW QUESTION # 95
......


Resources From:

  1. 2026 Latest ITPassLeader 212-89 Exam Dumps (PDF & Exam Engine) Free Share: https://exam-labs.itpassleader.com/EC-COUNCIL/212-89-dumps-pass-exam.html

Free Resources from ITPassLeader, We Devoted to Helping You 100% Pass All Exams!

0
0
0
0