Courseiva

212-89 · topic practice

Network Incidents practice questions

Practise Certified Incident Handler (212-89) Network Incidents practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Network Incidents

What the exam tests

What to know about Network Incidents

Network Incidents questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Network Incidents exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Network Incidents questions

20 questions · select your answer, then reveal the explanation

When analyzing logs from a Palo Alto Networks firewall, which specific threat log field is most useful for identifying the 'User-Agent' string used by a beaconing malware to blend in with legitimate web traffic?

You are configuring a Cisco ASA firewall to perform deep packet inspection to mitigate lateral movement via SMB exploits. Which feature must be enabled in the modular policy framework to drop packets containing known exploit patterns?

Question 3easymultiple choice
Open the full VLAN trunking answer →

During a network incident, you need to isolate a compromised workstation by updating the switch port configuration. Which command would you use on a Cisco Catalyst switch to move a port to a restricted VLAN?

An attacker uses 'ARP Spoofing' to perform a Man-in-the-Middle attack. Which command on a Cisco switch would prevent this by mapping MAC addresses to specific ports?

An incident responder is using NetFlow to identify a data exfiltration event. What specific field in a NetFlow v9 record provides the best indication of the total volume of data moved between two internal hosts?

Question 6hardmultiple choice
Read the full DNS explanation →

You suspect a DNS tunneling attack for data exfiltration. In your DNS server logs, which characteristic is the strongest indicator of a tunnel rather than standard recursive lookups?

You are performing log correlation in a SIEM. You want to match Windows Event ID 4624 (Logon) with network traffic. Which field is the primary 'join key' to correlate the event with a specific network flow?

During an investigation into lateral movement, you notice an unusual RDP connection from a workstation to a domain controller. Which Wireshark filter would be most effective in isolating only the RDP traffic associated with that specific source IP to identify potential credential dumping activity?

You are investigating a compromised Linux host. Using 'tcpdump' to capture traffic on interface eth0 to analyze C2 communication on port 443, which command is most efficient for saving the output to a file for later analysis in Wireshark?

When segmenting a network to contain an incident, what is the best practice for a 'Jump Server' in a DMZ to limit the attack surface?

Question 11mediummultiple choice
Read the full Network Incidents explanation →

A security analyst is investigating lateral movement using PowerShell Remoting (WinRM). Which Windows Event Log should be prioritized to confirm the execution of remote commands?

You are analyzing a PCAP file to detect 'Pass-the-Hash' activity. Which SMB message type should you specifically look for in the NTLM authentication exchange?

Question 13mediummultiple choice
Read the full Network Incidents explanation →

Which technique should an incident responder use to prevent an infected host from spreading ransomware via SMB to other segments in the network?

You are identifying a compromised host by checking for beaconing behavior. Which network metric is most indicative of heartbeat-style beaconing?

Which syslog facility would typically be configured on a network device to send audit logs to a central server?

Question 16mediummultiple choice
Read the full Network Incidents explanation →

An attacker is using ICMP tunneling to exfiltrate data. What field in an ICMP echo request packet would contain the unauthorized data?

During network forensics, you need to reconstruct an HTTP file transfer from a PCAP. Which Wireshark feature allows you to extract the file object directly from the stream?

Question 18mediummultiple choice
Read the full Network Incidents explanation →

When reviewing firewall logs, you see many 'deny' events from an internal host to an external IP. What is the most likely cause?

You are using NetFlow to identify lateral movement. You see a high volume of connections from a web server to an internal database server on port 3306. What is the most appropriate next step in the investigation?

What is the purpose of 'Network Segmentation' during an active network incident?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Network Incidents sessions

Start a Network Incidents only practice session

Every question in these sessions is drawn from the Network Incidents domain — nothing else.

Related practice questions

Related 212-89 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 212-89 exam test about Network Incidents?
Network Incidents questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Network Incidents questions in a focused session?
Yes — the session launcher on this page draws every question from the Network Incidents domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 212-89 topics?
Use the topic links above to move to related areas, or go back to the 212-89 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 212-89 exam covers. They are not copied from any real exam or dump site.