Courseiva

212-89 · domain

Incident Handling Process

Practise Certified Incident Handler (212-89) Incident Handling Process practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

46 questions13 easy20 medium13 hard

Focused practice

Practice Incident Handling Process questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Incident Handling Process

Incident Handling Process questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Incident Handling Process exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Incident Handling Process questions (46)

Click any question to see the full explanation, or start a practice session above.

1

During the lessons learned phase of a P1 incident, you notice that the incident handling policy failed to define clear 'Rules of Engagement' for containment, leading to accidental service disruption. Which document should be updated to address this deficiency?

Medium
2

During an investigation, you need to verify the integrity of a system configuration file. You have the original known-good hash. What does it mean if the hash of the current file matches the known-good hash?

Hard
3

Which role in the Incident Response Team is primarily responsible for ensuring that the incident handling activities remain aligned with organizational legal and privacy requirements?

Easy
4

You are setting up a secure communication channel for the IR team during a major incident. Why is it recommended to use an out-of-band communication method?

Medium
5

During the identification phase, you notice a high volume of traffic from an unknown IP to your web server. What is the most appropriate action to take first?

Easy
6

What is the primary function of an Incident Response (IR) policy?

Easy
7

What is the primary purpose of the 'Preparation' phase in the incident response lifecycle?

Easy
8

Which TWO of the following actions are standard steps in the 'Analysis' phase of an incident?

Hard
9

When conducting an interview with a potential witness during an investigation, what is the best practice to follow?

Medium
10

Which of the following activities is best suited for the 'Recovery' phase of the incident handling process?

Medium
11

Which THREE of the following should be included in an incident communication plan?

Medium
12

When managing the 'Lessons Learned' phase of the incident response lifecycle, which THREE activities should be conducted to ensure continuous improvement?

Hard
13

You are utilizing NIST SP 800-61 Rev. 2 to structure your incident response team. During a critical ransomware outbreak, you need to assign a lead who coordinates with legal, PR, and executive leadership. Which role should you designate to ensure organizational communication is handled per the policy?

Medium
14

Which TWO of the following are considered 'Legal Considerations' during the Incident Handling process that must be integrated into the response plan?

Medium
15

Which TWO of the following are essential components of an effective Incident Response (IR) plan?

Easy
16

You are preparing a final report for an incident. Which element is mandatory for ensuring the report serves as a valid document for future insurance or legal claims?

Hard
17

An organization is establishing an Incident Response (IR) team. According to NIST, which team structure is most suitable for a large, globally distributed organization that requires localized response capability with centralized oversight?

Easy
18

You are dealing with a legal hold request for data related to an investigation. How should you handle the data retention policy for this specific case?

Hard
19

Which THREE of the following are critical requirements for maintaining a valid Chain of Custody?

Hard
20

Which TWO of the following are common indicators that an incident should be declared?

Easy
21

Which TWO of the following are common sources for incident identification?

Medium
22

You are managing chain of custody for a physical server seized during an investigation. What is the most critical action to ensure the evidence remains admissible in court?

Hard
23

You suspect an incident involves an insider threat. Which step should be taken FIRST to preserve the integrity of the potential evidence while minimizing system downtime?

Hard
24

You are using a SIEM to correlate events during an investigation. What is the primary advantage of correlation in incident analysis?

Medium
25

You are choosing a destination for forensic image storage. What is the most critical characteristic of this storage?

Medium
26

Which TWO of the following are primary objectives of the 'Lessons Learned' phase?

Medium
27

During an incident, why is it important to keep the 'Incident Log' updated in real-time?

Easy
28

You are assessing the effectiveness of a containment strategy for a worm spreading through the network. What is the most effective metric to use?

Medium
29

You are performing an incident investigation involving a suspected insider threat. Under GDPR compliance, you must ensure that your data collection methods adhere to the 'data minimization' principle. Which action best aligns with this requirement?

Hard
30

During a suspected data breach, you must collect volatile memory. Which tool and command is the industry-standard starting point for capturing an image of RAM in a Windows-based incident?

Medium
31

Which team should be notified first in the event of a confirmed external data breach involving customer PII?

Easy
32

While investigating a server compromise, you need to ensure the digital evidence collected from the RAID array is admissible in court. What is the most critical requirement for the chain of custody?

Easy
33

Which TWO of the following are recommended when creating a forensic copy of a hard drive?

Medium
34

An incident handler is reviewing an alert from the Endpoint Detection and Response (EDR) system. What is the main goal of the 'Containment' phase?

Easy
35

A department head demands to know the names of the employees involved in an internal data leak. Which policy document defines your obligation to disclose or withhold this information?

Medium
36

You are documenting a post-incident review. Which of the following should be included in the 'Timeline of Events' section?

Medium
37

You are performing a post-incident review. Which action is the most important to ensure that the 'Lessons Learned' process effectively improves future response capabilities?

Medium
38

Which THREE of the following are legal considerations when handling an incident?

Hard
39

You have identified a potential Advanced Persistent Threat (APT) in your network. Which evidence preservation strategy is required to maintain the validity of the logs found in a SIEM?

Hard
40

You are configuring a SIEM for long-term storage of investigation logs. Which feature is most important to prevent evidence tampering?

Hard
41

When classifying the severity of an incident, which factor should carry the most weight in your decision-making process?

Medium
42

When dealing with digital evidence in a remote investigation, what is the standard procedure to ensure evidence integrity during network transfer?

Hard
43

Which TWO of the following are essential components of an effective Incident Communication Plan?

Medium
44

Which THREE of the following roles are typically included in an IR team?

Easy
45

You are establishing an Incident Response Plan (IRP). Which document should prioritize the technical steps for restoring services after a ransomware attack?

Easy
46

You are reviewing a failed incident case management report. The team failed to capture the 'Time of Detection' vs. 'Time of Occurrence'. Which metric is directly impacted by this lack of documentation?

Medium

Frequently asked questions

What does the Incident Handling Process domain cover on the 212-89 exam?
Incident Handling Process questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 46 Incident Handling Process questions in the 212-89 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Incident Handling Process questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
eccouncil-ecih ECCOUNCIL-ECIH incident handling process Practice Questions