Courseiva
Back to Certified Incident Handler (212-89) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified Incident Handler (212-89) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
212-89
exam code
EC-Council
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related 212-89 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymulti select
Full question →

Which TWO of the following are safe practices when analyzing a suspicious email?

Question 2hardmulti select
Full question →

Which THREE of the following email security technologies should be configured to prevent domain spoofing?

Question 3easymulti select
Full question →

Which THREE of the following are appropriate communication channels to keep users informed during an email phishing incident?

Question 4mediummulti select
Full question →

Which TWO of the following describe the role of an email gateway in incident response?

Question 5easymulti select
Full question →

Which TWO types of evidence are considered 'volatile'?

Question 6hardmulti select
Full question →

Which TWO of the following are valid methods to identify a malicious attachment?

Question 7mediummulti select
Full question →

Which THREE of the following items should be included in an email incident report?

Question 8easymulti select
Full question →

Which THREE categories of stakeholders should be considered for notification in a major data breach?

Question 9hardmulti select
Full question →

Which TWO criteria must a first responder satisfy when choosing a tool for a toolkit?

Question 10mediummulti select
Full question →

Which TWO actions are recommended for evidence preservation in a digital incident?

Question 11mediummulti select
Full question →

Which THREE pieces of information should be recorded on a Chain of Custody (CoC) form when collecting a device?

Question 12mediummulti select
Full question →

Which TWO of the following are recommended when creating a forensic copy of a hard drive?

Question 13mediummulti select
Full question →

Which TWO of the following are essential components of an effective Incident Communication Plan?

Question 14hardmulti select
Full question →

Which THREE of the following are legal considerations when handling an incident?

Question 15mediummulti select
Full question →

Which TWO of the following are considered 'Legal Considerations' during the Incident Handling process that must be integrated into the response plan?

Question 16hardmulti select
Full question →

Which THREE of the following tools would be most effective for performing live memory forensics on a compromised Windows workstation?

Question 17easymulti select
Full question →

Which TWO of the following are common signs of a compromised switch in a local area network?

Question 18hardmulti select
Full question →

Which THREE of the following represent critical log sources that should be correlated when investigating a potential network-based exfiltration incident?

Question 19mediummulti select
Full question →

Which THREE of the following indicators are found in email-based malware delivery?

Question 20mediummulti select
Full question →

During a malware analysis, which TWO of the following indicators are typically used to identify persistence mechanisms in the Windows registry?

These 212-89 practice questions are part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style 212-89 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.