Courseiva

212-89 · domain

Email Incidents

Practise Certified Incident Handler (212-89) Email Incidents practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

30 questions9 easy12 medium9 hard

Focused practice

Practice Email Incidents questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Email Incidents

Email Incidents questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Email Incidents exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Email Incidents questions (30)

Click any question to see the full explanation, or start a practice session above.

1

What is the primary risk associated with 'Executive Spoofing' or BEC (Business Email Compromise)?

Easy
2

Which action should be taken after an email incident is contained and the indicators are identified?

Easy
3

Which protocol is used in conjunction with SPF and DKIM to provide instructions to the receiver on how to handle emails that fail authentication?

Medium
4

When DKIM signature verification fails, what is the most likely technical cause?

Hard
5

While analyzing an email header, you observe an SPF 'softfail'. What does this imply?

Hard
6

You are reviewing a suspicious macro in a Word document attachment. Which tool is best suited for static analysis of the macro code?

Hard
7

Which TWO of the following steps are required when performing a post-mortem analysis of an email incident?

Medium
8

Which THREE of the following email security technologies should be configured to prevent domain spoofing?

Hard
9

An organization uses Microsoft 365. Which feature should an admin use to globally remove a malicious phishing email from all user mailboxes?

Medium
10

If a phishing email bypassed the perimeter email gateway, what is the next logical step in the incident response process?

Medium
11

An attacker uses a 'Homograph Attack' to spoof a domain. How does the analyst detect this?

Hard
12

Which TWO of the following describe the role of an email gateway in incident response?

Medium
13

An employee receives a suspicious email asking to verify account details by clicking a link. What is the most effective user behavior to mitigate this?

Easy
14

Which THREE of the following are common indicators of a phishing email?

Medium
15

You are analyzing an email with a suspicious attachment. You notice the file name is 'invoice.pdf.exe'. What does this indicate?

Medium
16

When performing manual phishing triage, which action should an analyst perform first after identifying a suspicious URL in an email body?

Easy
17

An analyst is drafting an email to a user who reported a phishing attempt. What is the most important tone to maintain?

Easy
18

Which of the following is a symptom of an 'Email Forwarding Rule' attack?

Medium
19

An analyst identifies that an email originated from an unauthorized IP address despite passing SPF. What is the most likely cause?

Hard
20

Which THREE of the following could be considered 'indicators of compromise' (IOCs) for an email incident?

Hard
21

Which THREE of the following are appropriate communication channels to keep users informed during an email phishing incident?

Easy
22

An email header contains 'X-Forefront-Antispam-Report'. What can an analyst determine from this?

Hard
23

When an email incident is resolved, why is it necessary to update the organization's blocklist?

Easy
24

Which TWO of the following are safe practices when analyzing a suspicious email?

Easy
25

You are analyzing an email and the URL redirects through multiple shortened link services. What is the recommended way to find the final landing page?

Medium
26

What is the purpose of 'Sandboxing' in email security?

Medium
27

An analyst receives a report of a phishing email. Which email header field is most reliable for verifying the path taken by the email through intermediate mail transfer agents?

Easy
28

Which THREE of the following items should be included in an email incident report?

Medium
29

If a user receives an email with an attachment that is a 'compressed password-protected file', why is this a red flag?

Medium
30

Which TWO of the following are valid methods to identify a malicious attachment?

Hard

Frequently asked questions

What does the Email Incidents domain cover on the 212-89 exam?
Email Incidents questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 30 Email Incidents questions in the 212-89 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Email Incidents questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
eccouncil-ecih ECCOUNCIL-ECIH email incidents Practice Questions