212-89 · domain
First Response
Practise Certified Incident Handler (212-89) First Response practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice First Response questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about First Response
First Response questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common First Response exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All First Response questions (41)
Click any question to see the full explanation, or start a practice session above.
When identifying stakeholders to notify during an incident, which group should be notified first?
Easy2During initial triage, you identify that a system's time is significantly out of sync with the NTP server. Why is this critical to record during the first response?
Easy3Which TWO types of evidence are considered 'volatile'?
Easy4You have identified an active C2 beacon on a corporate server. You are instructed to implement 'Containment' via network segmentation. Which configuration change on a Cisco ASA firewall provides the most effective containment while still allowing for remote forensic forensic analysis?
Hard5When investigating an incident on a virtualized platform (VMware), what is the first step to capture the state of the VM for analysis?
Hard6What is the 'First Responder Toolkit' used for during an incident?
Easy7Which THREE pieces of information should be recorded on a Chain of Custody (CoC) form when collecting a device?
Medium8Which TWO items should be part of a first responder's physical toolkit?
Medium9You are investigating a Linux server breach. You need to capture the current state of network connections without altering the evidence. Which command-line tool is preferred by first responders?
Hard10You are responding to a web-based attack. Which log source is most critical for identifying the origin of a SQL injection attempt?
Medium11You are performing an investigation on a compromised mobile device. What is the primary risk of connecting the device to a standard workstation without a write blocker?
Medium12You are investigating a suspected rootkit. Which area of the operating system should you examine for unauthorized boot-time execution?
Hard13You are documenting an incident and need to record the time of the event. Why is accurate time synchronization critical?
Medium14When documenting the chain of custody for a seized laptop, which information is mandatory?
Easy15Which TWO criteria must a first responder satisfy when choosing a tool for a toolkit?
Hard16A user reports a 'missing' file that was present earlier. What is the first thing you should check in a forensic triage?
Medium17Which THREE categories of stakeholders should be considered for notification in a major data breach?
Easy18You are handling a ransomware incident. Which step should be taken before attempting any file recovery?
Medium19Which of the following is an example of a non-volatile data source?
Easy20You are performing initial containment on a cloud-based AWS EC2 instance. The instance is under a DDoS attack. What is the most effective way to isolate this specific resource?
Medium21You are performing a triage on a server and see unauthorized outbound connections to a foreign IP. What is the best way to determine which process initiated the connection?
Hard22You are assembling a 'First Responder Toolkit' for a remote incident team. Which THREE items are essential for collecting volatile data and ensuring legal defensibility on a Windows system?
Medium23You discover a suspicious scheduled task on a server. Which Windows tool allows you to export this task for analysis without relying on the GUI?
Medium24When documenting evidence for a forensic investigation, you are required to establish a chain of custody. Which information is considered mandatory for each entry in the chain of custody log to satisfy legal requirements?
Medium25During an incident, a responder needs to capture the ARP cache to identify potential local spoofing. Which tool provides this information?
Hard26During the triage of a Linux server, you suspect a rootkit is intercepting system calls. Which THREE actions are appropriate for the first responder to perform to gather evidence of the rootkit?
Medium27As a first responder, you arrive at a compromised workstation showing signs of active malware beaconing. Which action should be performed first according to the Order of Volatility?
Easy28You need to capture forensic data from a Windows machine using a remote agent. What is the risk of using built-in administrative tools like PowerShell for this?
Medium29You are analyzing an incident where a user account is being used to exfiltrate data. What is the most immediate action to contain the account?
Medium30Which TWO actions are recommended for evidence preservation in a digital incident?
Medium31Which THREE pieces of information should be included in an incident triage report?
Medium32During a suspected ransomware incident, you are using EnCase Endpoint to perform remote triage. You need to collect volatile data without triggering the ransomware's anti-forensic triggers. Which action should you take first to ensure the integrity of evidence?
Medium33What is the primary purpose of a write blocker in a forensic investigation?
Easy34Which THREE actions should be avoided during the initial response phase to ensure evidence integrity?
Hard35Which documentation is required when transferring physical evidence from a responder to a forensic lab?
Easy36In the context of the NIST Incident Response Life Cycle, which phase immediately follows the 'Detection and Analysis' phase, specifically focusing on limiting the scope of the compromise?
Easy37A first responder is using a 'Live Response' toolkit. What is the main characteristic of these tools?
Easy38While investigating a breach, you need to verify the integrity of a system file. Which process is correct to ensure the file has not been altered?
Hard39When notifying stakeholders during a major data breach, which TWO of the following groups must be informed according to standard incident communication plans to satisfy regulatory and operational needs?
Hard40A stakeholder asks you to prioritize the recovery of a compromised system. According to incident response best practices, what is your first responsibility?
Easy41Which TWO actions are recommended for secure evidence storage?
EasyOther domains
All 212-89 exam domains
Frequently asked questions
- What does the First Response domain cover on the 212-89 exam?
- First Response questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 41 First Response questions in the 212-89 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only First Response questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.