212-89 · domain
Network Incidents
Practise Certified Incident Handler (212-89) Network Incidents practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Network Incidents questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Network Incidents
Network Incidents questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Network Incidents exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Network Incidents questions (26)
Click any question to see the full explanation, or start a practice session above.
During network forensics, you need to reconstruct an HTTP file transfer from a PCAP. Which Wireshark feature allows you to extract the file object directly from the stream?
Hard2When segmenting a network to contain an incident, what is the best practice for a 'Jump Server' in a DMZ to limit the attack surface?
Easy3You are using NetFlow to identify lateral movement. You see a high volume of connections from a web server to an internal database server on port 3306. What is the most appropriate next step in the investigation?
Hard4An incident responder is using NetFlow to identify a data exfiltration event. What specific field in a NetFlow v9 record provides the best indication of the total volume of data moved between two internal hosts?
Easy5Which THREE of the following characterize potential lateral movement using RDP in a domain environment?
Hard6You are analyzing a PCAP file to detect 'Pass-the-Hash' activity. Which SMB message type should you specifically look for in the NTLM authentication exchange?
Hard7What is the purpose of 'Network Segmentation' during an active network incident?
Easy8You are using an IDS/IPS to detect lateral movement. You notice that your NIDS is not alerting on SSH brute force attempts. Which configuration check is most important to perform?
Hard9When reviewing firewall logs, you see many 'deny' events from an internal host to an external IP. What is the most likely cause?
Medium10You are identifying a compromised host by checking for beaconing behavior. Which network metric is most indicative of heartbeat-style beaconing?
Easy11An attacker is using ICMP tunneling to exfiltrate data. What field in an ICMP echo request packet would contain the unauthorized data?
Medium12Which technique should an incident responder use to prevent an infected host from spreading ransomware via SMB to other segments in the network?
Medium13Which TWO of the following techniques would an attacker likely use to hide lateral movement traffic within a network?
Hard14Which TWO of the following are common signs of a compromised switch in a local area network?
Easy15Which THREE of the following are key components of a network-based containment strategy?
Medium16A security analyst is investigating lateral movement using PowerShell Remoting (WinRM). Which Windows Event Log should be prioritized to confirm the execution of remote commands?
Medium17During an investigation into lateral movement, you notice an unusual RDP connection from a workstation to a domain controller. Which Wireshark filter would be most effective in isolating only the RDP traffic associated with that specific source IP to identify potential credential dumping activity?
Medium18Which TWO of the following are common network-based indicators of a compromised host attempting to perform network discovery?
Medium19You suspect a DNS tunneling attack for data exfiltration. In your DNS server logs, which characteristic is the strongest indicator of a tunnel rather than standard recursive lookups?
Hard20You are performing log correlation in a SIEM. You want to match Windows Event ID 4624 (Logon) with network traffic. Which field is the primary 'join key' to correlate the event with a specific network flow?
Medium21You are investigating a compromised Linux host. Using 'tcpdump' to capture traffic on interface eth0 to analyze C2 communication on port 443, which command is most efficient for saving the output to a file for later analysis in Wireshark?
Medium22Which THREE of the following represent critical log sources that should be correlated when investigating a potential network-based exfiltration incident?
Hard23Which TWO of the following indicators are primary artifacts to look for when investigating potential lateral movement on a Windows network?
Medium24Which syslog facility would typically be configured on a network device to send audit logs to a central server?
Easy25Which TWO of the following steps are considered best practices when performing network forensics on a live environment?
Medium26Which THREE of the following are effective network forensics techniques for identifying an attacker's C2 server infrastructure?
HardOther domains
All 212-89 exam domains
Frequently asked questions
- What does the Network Incidents domain cover on the 212-89 exam?
- Network Incidents questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 26 Network Incidents questions in the 212-89 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Network Incidents questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.