Practice 212-89 Network Incidents questions with full explanations on every answer.
Start practicing
Network Incidents — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An incident responder is using NetFlow to identify a data exfiltration event. What specific field in a NetFlow v9 record provides the best indication of the total volume of data moved between two internal hosts?
2You suspect a DNS tunneling attack for data exfiltration. In your DNS server logs, which characteristic is the strongest indicator of a tunnel rather than standard recursive lookups?
3You are performing log correlation in a SIEM. You want to match Windows Event ID 4624 (Logon) with network traffic. Which field is the primary 'join key' to correlate the event with a specific network flow?
4During an investigation into lateral movement, you notice an unusual RDP connection from a workstation to a domain controller. Which Wireshark filter would be most effective in isolating only the RDP traffic associated with that specific source IP to identify potential credential dumping activity?
5You are investigating a compromised Linux host. Using 'tcpdump' to capture traffic on interface eth0 to analyze C2 communication on port 443, which command is most efficient for saving the output to a file for later analysis in Wireshark?
6When segmenting a network to contain an incident, what is the best practice for a 'Jump Server' in a DMZ to limit the attack surface?
7A security analyst is investigating lateral movement using PowerShell Remoting (WinRM). Which Windows Event Log should be prioritized to confirm the execution of remote commands?
8You are analyzing a PCAP file to detect 'Pass-the-Hash' activity. Which SMB message type should you specifically look for in the NTLM authentication exchange?
9Which technique should an incident responder use to prevent an infected host from spreading ransomware via SMB to other segments in the network?
10You are identifying a compromised host by checking for beaconing behavior. Which network metric is most indicative of heartbeat-style beaconing?
11Which syslog facility would typically be configured on a network device to send audit logs to a central server?
12An attacker is using ICMP tunneling to exfiltrate data. What field in an ICMP echo request packet would contain the unauthorized data?
13During network forensics, you need to reconstruct an HTTP file transfer from a PCAP. Which Wireshark feature allows you to extract the file object directly from the stream?
14When reviewing firewall logs, you see many 'deny' events from an internal host to an external IP. What is the most likely cause?
15You are using NetFlow to identify lateral movement. You see a high volume of connections from a web server to an internal database server on port 3306. What is the most appropriate next step in the investigation?
16What is the purpose of 'Network Segmentation' during an active network incident?
17Which TWO of the following indicators are primary artifacts to look for when investigating potential lateral movement on a Windows network?
18Which THREE of the following are effective network forensics techniques for identifying an attacker's C2 server infrastructure?
19Which TWO of the following are common network-based indicators of a compromised host attempting to perform network discovery?
20Which THREE of the following represent critical log sources that should be correlated when investigating a potential network-based exfiltration incident?
21Which TWO of the following are common signs of a compromised switch in a local area network?
22Which THREE of the following are key components of a network-based containment strategy?
23Which THREE of the following characterize potential lateral movement using RDP in a domain environment?
24Which TWO of the following steps are considered best practices when performing network forensics on a live environment?
25Which TWO of the following techniques would an attacker likely use to hide lateral movement traffic within a network?
26You are using an IDS/IPS to detect lateral movement. You notice that your NIDS is not alerting on SSH brute force attempts. Which configuration check is most important to perform?
The Network Incidents domain covers the key concepts tested in this area of the 212-89 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 212-89 domains — no account required.
The Courseiva 212-89 question bank contains 26 questions in the Network Incidents domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Network Incidents domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included