Courseiva

212-89 · domain

First Response

Practise Certified Incident Handler (212-89) First Response practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

41 questions14 easy17 medium10 hard

Focused practice

Practice First Response questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about First Response

First Response questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common First Response exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All First Response questions (41)

Click any question to see the full explanation, or start a practice session above.

1

When identifying stakeholders to notify during an incident, which group should be notified first?

Easy
2

During initial triage, you identify that a system's time is significantly out of sync with the NTP server. Why is this critical to record during the first response?

Easy
3

Which TWO types of evidence are considered 'volatile'?

Easy
4

You have identified an active C2 beacon on a corporate server. You are instructed to implement 'Containment' via network segmentation. Which configuration change on a Cisco ASA firewall provides the most effective containment while still allowing for remote forensic forensic analysis?

Hard
5

When investigating an incident on a virtualized platform (VMware), what is the first step to capture the state of the VM for analysis?

Hard
6

What is the 'First Responder Toolkit' used for during an incident?

Easy
7

Which THREE pieces of information should be recorded on a Chain of Custody (CoC) form when collecting a device?

Medium
8

Which TWO items should be part of a first responder's physical toolkit?

Medium
9

You are investigating a Linux server breach. You need to capture the current state of network connections without altering the evidence. Which command-line tool is preferred by first responders?

Hard
10

You are responding to a web-based attack. Which log source is most critical for identifying the origin of a SQL injection attempt?

Medium
11

You are performing an investigation on a compromised mobile device. What is the primary risk of connecting the device to a standard workstation without a write blocker?

Medium
12

You are investigating a suspected rootkit. Which area of the operating system should you examine for unauthorized boot-time execution?

Hard
13

You are documenting an incident and need to record the time of the event. Why is accurate time synchronization critical?

Medium
14

When documenting the chain of custody for a seized laptop, which information is mandatory?

Easy
15

Which TWO criteria must a first responder satisfy when choosing a tool for a toolkit?

Hard
16

A user reports a 'missing' file that was present earlier. What is the first thing you should check in a forensic triage?

Medium
17

Which THREE categories of stakeholders should be considered for notification in a major data breach?

Easy
18

You are handling a ransomware incident. Which step should be taken before attempting any file recovery?

Medium
19

Which of the following is an example of a non-volatile data source?

Easy
20

You are performing initial containment on a cloud-based AWS EC2 instance. The instance is under a DDoS attack. What is the most effective way to isolate this specific resource?

Medium
21

You are performing a triage on a server and see unauthorized outbound connections to a foreign IP. What is the best way to determine which process initiated the connection?

Hard
22

You are assembling a 'First Responder Toolkit' for a remote incident team. Which THREE items are essential for collecting volatile data and ensuring legal defensibility on a Windows system?

Medium
23

You discover a suspicious scheduled task on a server. Which Windows tool allows you to export this task for analysis without relying on the GUI?

Medium
24

When documenting evidence for a forensic investigation, you are required to establish a chain of custody. Which information is considered mandatory for each entry in the chain of custody log to satisfy legal requirements?

Medium
25

During an incident, a responder needs to capture the ARP cache to identify potential local spoofing. Which tool provides this information?

Hard
26

During the triage of a Linux server, you suspect a rootkit is intercepting system calls. Which THREE actions are appropriate for the first responder to perform to gather evidence of the rootkit?

Medium
27

As a first responder, you arrive at a compromised workstation showing signs of active malware beaconing. Which action should be performed first according to the Order of Volatility?

Easy
28

You need to capture forensic data from a Windows machine using a remote agent. What is the risk of using built-in administrative tools like PowerShell for this?

Medium
29

You are analyzing an incident where a user account is being used to exfiltrate data. What is the most immediate action to contain the account?

Medium
30

Which TWO actions are recommended for evidence preservation in a digital incident?

Medium
31

Which THREE pieces of information should be included in an incident triage report?

Medium
32

During a suspected ransomware incident, you are using EnCase Endpoint to perform remote triage. You need to collect volatile data without triggering the ransomware's anti-forensic triggers. Which action should you take first to ensure the integrity of evidence?

Medium
33

What is the primary purpose of a write blocker in a forensic investigation?

Easy
34

Which THREE actions should be avoided during the initial response phase to ensure evidence integrity?

Hard
35

Which documentation is required when transferring physical evidence from a responder to a forensic lab?

Easy
36

In the context of the NIST Incident Response Life Cycle, which phase immediately follows the 'Detection and Analysis' phase, specifically focusing on limiting the scope of the compromise?

Easy
37

A first responder is using a 'Live Response' toolkit. What is the main characteristic of these tools?

Easy
38

While investigating a breach, you need to verify the integrity of a system file. Which process is correct to ensure the file has not been altered?

Hard
39

When notifying stakeholders during a major data breach, which TWO of the following groups must be informed according to standard incident communication plans to satisfy regulatory and operational needs?

Hard
40

A stakeholder asks you to prioritize the recovery of a compromised system. According to incident response best practices, what is your first responsibility?

Easy
41

Which TWO actions are recommended for secure evidence storage?

Easy

Frequently asked questions

What does the First Response domain cover on the 212-89 exam?
First Response questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 41 First Response questions in the 212-89 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only First Response questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
eccouncil-ecih ECCOUNCIL-ECIH first response Practice Questions