Practice 212-89 Incident Handling Process questions with full explanations on every answer.
Start practicing
Incident Handling Process — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
During a suspected data breach, you must collect volatile memory. Which tool and command is the industry-standard starting point for capturing an image of RAM in a Windows-based incident?
2Which role in the Incident Response Team is primarily responsible for ensuring that the incident handling activities remain aligned with organizational legal and privacy requirements?
3You are managing chain of custody for a physical server seized during an investigation. What is the most critical action to ensure the evidence remains admissible in court?
4You are performing a post-incident review. Which action is the most important to ensure that the 'Lessons Learned' process effectively improves future response capabilities?
5You are setting up a secure communication channel for the IR team during a major incident. Why is it recommended to use an out-of-band communication method?
6You are establishing an Incident Response Plan (IRP). Which document should prioritize the technical steps for restoring services after a ransomware attack?
7You suspect an incident involves an insider threat. Which step should be taken FIRST to preserve the integrity of the potential evidence while minimizing system downtime?
8A department head demands to know the names of the employees involved in an internal data leak. Which policy document defines your obligation to disclose or withhold this information?
9You have identified a potential Advanced Persistent Threat (APT) in your network. Which evidence preservation strategy is required to maintain the validity of the logs found in a SIEM?
10You are documenting a post-incident review. Which of the following should be included in the 'Timeline of Events' section?
11During the identification phase, you notice a high volume of traffic from an unknown IP to your web server. What is the most appropriate action to take first?
12When classifying the severity of an incident, which factor should carry the most weight in your decision-making process?
13You are dealing with a legal hold request for data related to an investigation. How should you handle the data retention policy for this specific case?
14An incident handler is reviewing an alert from the Endpoint Detection and Response (EDR) system. What is the main goal of the 'Containment' phase?
15Which of the following activities is best suited for the 'Recovery' phase of the incident handling process?
16What is the primary function of an Incident Response (IR) policy?
17Which team should be notified first in the event of a confirmed external data breach involving customer PII?
18When dealing with digital evidence in a remote investigation, what is the standard procedure to ensure evidence integrity during network transfer?
19You are using a SIEM to correlate events during an investigation. What is the primary advantage of correlation in incident analysis?
20You are preparing a final report for an incident. Which element is mandatory for ensuring the report serves as a valid document for future insurance or legal claims?
21You are assessing the effectiveness of a containment strategy for a worm spreading through the network. What is the most effective metric to use?
22During an incident, why is it important to keep the 'Incident Log' updated in real-time?
23During an investigation, you need to verify the integrity of a system configuration file. You have the original known-good hash. What does it mean if the hash of the current file matches the known-good hash?
24You are choosing a destination for forensic image storage. What is the most critical characteristic of this storage?
25What is the primary purpose of the 'Preparation' phase in the incident response lifecycle?
26When conducting an interview with a potential witness during an investigation, what is the best practice to follow?
27Which TWO of the following are primary objectives of the 'Lessons Learned' phase?
28Which TWO of the following are essential components of an effective Incident Response (IR) plan?
29You are configuring a SIEM for long-term storage of investigation logs. Which feature is most important to prevent evidence tampering?
30Which THREE of the following should be included in an incident communication plan?
31Which THREE of the following are critical requirements for maintaining a valid Chain of Custody?
32Which TWO of the following are common indicators that an incident should be declared?
33Which TWO of the following actions are standard steps in the 'Analysis' phase of an incident?
34Which THREE of the following roles are typically included in an IR team?
35Which TWO of the following are recommended when creating a forensic copy of a hard drive?
36Which TWO of the following are common sources for incident identification?
37Which THREE of the following are legal considerations when handling an incident?
38You are utilizing NIST SP 800-61 Rev. 2 to structure your incident response team. During a critical ransomware outbreak, you need to assign a lead who coordinates with legal, PR, and executive leadership. Which role should you designate to ensure organizational communication is handled per the policy?
39While investigating a server compromise, you need to ensure the digital evidence collected from the RAID array is admissible in court. What is the most critical requirement for the chain of custody?
40During the lessons learned phase of a P1 incident, you notice that the incident handling policy failed to define clear 'Rules of Engagement' for containment, leading to accidental service disruption. Which document should be updated to address this deficiency?
41You are reviewing a failed incident case management report. The team failed to capture the 'Time of Detection' vs. 'Time of Occurrence'. Which metric is directly impacted by this lack of documentation?
42You are performing an incident investigation involving a suspected insider threat. Under GDPR compliance, you must ensure that your data collection methods adhere to the 'data minimization' principle. Which action best aligns with this requirement?
43An organization is establishing an Incident Response (IR) team. According to NIST, which team structure is most suitable for a large, globally distributed organization that requires localized response capability with centralized oversight?
44Which TWO of the following are essential components of an effective Incident Communication Plan?
45When managing the 'Lessons Learned' phase of the incident response lifecycle, which THREE activities should be conducted to ensure continuous improvement?
46Which TWO of the following are considered 'Legal Considerations' during the Incident Handling process that must be integrated into the response plan?
The Incident Handling Process domain covers the key concepts tested in this area of the 212-89 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 212-89 domains — no account required.
The Courseiva 212-89 question bank contains 46 questions in the Incident Handling Process domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Incident Handling Process domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included