212-89 · domain
Incident Handling Process
Practise Certified Incident Handler (212-89) Incident Handling Process practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Incident Handling Process questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Incident Handling Process
Incident Handling Process questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Incident Handling Process exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Incident Handling Process questions (46)
Click any question to see the full explanation, or start a practice session above.
During the lessons learned phase of a P1 incident, you notice that the incident handling policy failed to define clear 'Rules of Engagement' for containment, leading to accidental service disruption. Which document should be updated to address this deficiency?
Medium2During an investigation, you need to verify the integrity of a system configuration file. You have the original known-good hash. What does it mean if the hash of the current file matches the known-good hash?
Hard3Which role in the Incident Response Team is primarily responsible for ensuring that the incident handling activities remain aligned with organizational legal and privacy requirements?
Easy4You are setting up a secure communication channel for the IR team during a major incident. Why is it recommended to use an out-of-band communication method?
Medium5During the identification phase, you notice a high volume of traffic from an unknown IP to your web server. What is the most appropriate action to take first?
Easy6What is the primary function of an Incident Response (IR) policy?
Easy7What is the primary purpose of the 'Preparation' phase in the incident response lifecycle?
Easy8Which TWO of the following actions are standard steps in the 'Analysis' phase of an incident?
Hard9When conducting an interview with a potential witness during an investigation, what is the best practice to follow?
Medium10Which of the following activities is best suited for the 'Recovery' phase of the incident handling process?
Medium11Which THREE of the following should be included in an incident communication plan?
Medium12When managing the 'Lessons Learned' phase of the incident response lifecycle, which THREE activities should be conducted to ensure continuous improvement?
Hard13You are utilizing NIST SP 800-61 Rev. 2 to structure your incident response team. During a critical ransomware outbreak, you need to assign a lead who coordinates with legal, PR, and executive leadership. Which role should you designate to ensure organizational communication is handled per the policy?
Medium14Which TWO of the following are considered 'Legal Considerations' during the Incident Handling process that must be integrated into the response plan?
Medium15Which TWO of the following are essential components of an effective Incident Response (IR) plan?
Easy16You are preparing a final report for an incident. Which element is mandatory for ensuring the report serves as a valid document for future insurance or legal claims?
Hard17An organization is establishing an Incident Response (IR) team. According to NIST, which team structure is most suitable for a large, globally distributed organization that requires localized response capability with centralized oversight?
Easy18You are dealing with a legal hold request for data related to an investigation. How should you handle the data retention policy for this specific case?
Hard19Which THREE of the following are critical requirements for maintaining a valid Chain of Custody?
Hard20Which TWO of the following are common indicators that an incident should be declared?
Easy21Which TWO of the following are common sources for incident identification?
Medium22You are managing chain of custody for a physical server seized during an investigation. What is the most critical action to ensure the evidence remains admissible in court?
Hard23You suspect an incident involves an insider threat. Which step should be taken FIRST to preserve the integrity of the potential evidence while minimizing system downtime?
Hard24You are using a SIEM to correlate events during an investigation. What is the primary advantage of correlation in incident analysis?
Medium25You are choosing a destination for forensic image storage. What is the most critical characteristic of this storage?
Medium26Which TWO of the following are primary objectives of the 'Lessons Learned' phase?
Medium27During an incident, why is it important to keep the 'Incident Log' updated in real-time?
Easy28You are assessing the effectiveness of a containment strategy for a worm spreading through the network. What is the most effective metric to use?
Medium29You are performing an incident investigation involving a suspected insider threat. Under GDPR compliance, you must ensure that your data collection methods adhere to the 'data minimization' principle. Which action best aligns with this requirement?
Hard30During a suspected data breach, you must collect volatile memory. Which tool and command is the industry-standard starting point for capturing an image of RAM in a Windows-based incident?
Medium31Which team should be notified first in the event of a confirmed external data breach involving customer PII?
Easy32While investigating a server compromise, you need to ensure the digital evidence collected from the RAID array is admissible in court. What is the most critical requirement for the chain of custody?
Easy33Which TWO of the following are recommended when creating a forensic copy of a hard drive?
Medium34An incident handler is reviewing an alert from the Endpoint Detection and Response (EDR) system. What is the main goal of the 'Containment' phase?
Easy35A department head demands to know the names of the employees involved in an internal data leak. Which policy document defines your obligation to disclose or withhold this information?
Medium36You are documenting a post-incident review. Which of the following should be included in the 'Timeline of Events' section?
Medium37You are performing a post-incident review. Which action is the most important to ensure that the 'Lessons Learned' process effectively improves future response capabilities?
Medium38Which THREE of the following are legal considerations when handling an incident?
Hard39You have identified a potential Advanced Persistent Threat (APT) in your network. Which evidence preservation strategy is required to maintain the validity of the logs found in a SIEM?
Hard40You are configuring a SIEM for long-term storage of investigation logs. Which feature is most important to prevent evidence tampering?
Hard41When classifying the severity of an incident, which factor should carry the most weight in your decision-making process?
Medium42When dealing with digital evidence in a remote investigation, what is the standard procedure to ensure evidence integrity during network transfer?
Hard43Which TWO of the following are essential components of an effective Incident Communication Plan?
Medium44Which THREE of the following roles are typically included in an IR team?
Easy45You are establishing an Incident Response Plan (IRP). Which document should prioritize the technical steps for restoring services after a ransomware attack?
Easy46You are reviewing a failed incident case management report. The team failed to capture the 'Time of Detection' vs. 'Time of Occurrence'. Which metric is directly impacted by this lack of documentation?
MediumOther domains
All 212-89 exam domains
Frequently asked questions
- What does the Incident Handling Process domain cover on the 212-89 exam?
- Incident Handling Process questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 46 Incident Handling Process questions in the 212-89 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Incident Handling Process questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.