Sample questions
Certified Incident Handler (212-89) practice questions
Which TWO of the following are safe practices when analyzing a suspicious email?
What is the primary risk associated with 'Executive Spoofing' or BEC (Business Email Compromise)?
While analyzing an email header, you observe an SPF 'softfail'. What does this imply?
Which THREE of the following email security technologies should be configured to prevent domain spoofing?
Which THREE of the following are appropriate communication channels to keep users informed during an email phishing incident?
An email header contains 'X-Forefront-Antispam-Report'. What can an analyst determine from this?
Which TWO of the following describe the role of an email gateway in incident response?
Which TWO types of evidence are considered 'volatile'?
Which TWO of the following are valid methods to identify a malicious attachment?
Which THREE of the following items should be included in an email incident report?
Which of the following is a symptom of an 'Email Forwarding Rule' attack?
During an incident, a responder needs to capture the ARP cache to identify potential local spoofing. Which tool provides this information?
An employee receives a suspicious email asking to verify account details by clicking a link. What is the most effective user behavior to mitigate this?
What is the 'First Responder Toolkit' used for during an incident?
Which THREE categories of stakeholders should be considered for notification in a major data breach?
Which TWO criteria must a first responder satisfy when choosing a tool for a toolkit?
In the context of the NIST Incident Response Life Cycle, which phase immediately follows the 'Detection and Analysis' phase, specifically focusing on limiting the scope of the comp…
You are managing chain of custody for a physical server seized during an investigation. What is the most critical action to ensure the evidence remains admissible in court?
When classifying the severity of an incident, which factor should carry the most weight in your decision-making process?
A first responder is using a 'Live Response' toolkit. What is the main characteristic of these tools?
You are performing an investigation on a compromised mobile device. What is the primary risk of connecting the device to a standard workstation without a write blocker?
You are handling a ransomware incident. Which step should be taken before attempting any file recovery?
You are performing a post-incident review. Which action is the most important to ensure that the 'Lessons Learned' process effectively improves future response capabilities?
Which TWO actions are recommended for evidence preservation in a digital incident?