212-89 · domain
Email Incidents
Practise Certified Incident Handler (212-89) Email Incidents practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Email Incidents questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Email Incidents
Email Incidents questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Email Incidents exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Email Incidents questions (30)
Click any question to see the full explanation, or start a practice session above.
What is the primary risk associated with 'Executive Spoofing' or BEC (Business Email Compromise)?
Easy2Which action should be taken after an email incident is contained and the indicators are identified?
Easy3Which protocol is used in conjunction with SPF and DKIM to provide instructions to the receiver on how to handle emails that fail authentication?
Medium4When DKIM signature verification fails, what is the most likely technical cause?
Hard5While analyzing an email header, you observe an SPF 'softfail'. What does this imply?
Hard6You are reviewing a suspicious macro in a Word document attachment. Which tool is best suited for static analysis of the macro code?
Hard7Which TWO of the following steps are required when performing a post-mortem analysis of an email incident?
Medium8Which THREE of the following email security technologies should be configured to prevent domain spoofing?
Hard9An organization uses Microsoft 365. Which feature should an admin use to globally remove a malicious phishing email from all user mailboxes?
Medium10If a phishing email bypassed the perimeter email gateway, what is the next logical step in the incident response process?
Medium11An attacker uses a 'Homograph Attack' to spoof a domain. How does the analyst detect this?
Hard12Which TWO of the following describe the role of an email gateway in incident response?
Medium13An employee receives a suspicious email asking to verify account details by clicking a link. What is the most effective user behavior to mitigate this?
Easy14Which THREE of the following are common indicators of a phishing email?
Medium15You are analyzing an email with a suspicious attachment. You notice the file name is 'invoice.pdf.exe'. What does this indicate?
Medium16When performing manual phishing triage, which action should an analyst perform first after identifying a suspicious URL in an email body?
Easy17An analyst is drafting an email to a user who reported a phishing attempt. What is the most important tone to maintain?
Easy18Which of the following is a symptom of an 'Email Forwarding Rule' attack?
Medium19An analyst identifies that an email originated from an unauthorized IP address despite passing SPF. What is the most likely cause?
Hard20Which THREE of the following could be considered 'indicators of compromise' (IOCs) for an email incident?
Hard21Which THREE of the following are appropriate communication channels to keep users informed during an email phishing incident?
Easy22An email header contains 'X-Forefront-Antispam-Report'. What can an analyst determine from this?
Hard23When an email incident is resolved, why is it necessary to update the organization's blocklist?
Easy24Which TWO of the following are safe practices when analyzing a suspicious email?
Easy25You are analyzing an email and the URL redirects through multiple shortened link services. What is the recommended way to find the final landing page?
Medium26What is the purpose of 'Sandboxing' in email security?
Medium27An analyst receives a report of a phishing email. Which email header field is most reliable for verifying the path taken by the email through intermediate mail transfer agents?
Easy28Which THREE of the following items should be included in an email incident report?
Medium29If a user receives an email with an attachment that is a 'compressed password-protected file', why is this a red flag?
Medium30Which TWO of the following are valid methods to identify a malicious attachment?
HardOther domains
All 212-89 exam domains
Frequently asked questions
- What does the Email Incidents domain cover on the 212-89 exam?
- Email Incidents questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 30 Email Incidents questions in the 212-89 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Email Incidents questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.