Courseiva

212-89 · domain

Network Incidents

Practise Certified Incident Handler (212-89) Network Incidents practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

26 questions6 easy11 medium9 hard

Focused practice

Practice Network Incidents questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Network Incidents

Network Incidents questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Network Incidents exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Network Incidents questions (26)

Click any question to see the full explanation, or start a practice session above.

1

During network forensics, you need to reconstruct an HTTP file transfer from a PCAP. Which Wireshark feature allows you to extract the file object directly from the stream?

Hard
2

When segmenting a network to contain an incident, what is the best practice for a 'Jump Server' in a DMZ to limit the attack surface?

Easy
3

You are using NetFlow to identify lateral movement. You see a high volume of connections from a web server to an internal database server on port 3306. What is the most appropriate next step in the investigation?

Hard
4

An incident responder is using NetFlow to identify a data exfiltration event. What specific field in a NetFlow v9 record provides the best indication of the total volume of data moved between two internal hosts?

Easy
5

Which THREE of the following characterize potential lateral movement using RDP in a domain environment?

Hard
6

You are analyzing a PCAP file to detect 'Pass-the-Hash' activity. Which SMB message type should you specifically look for in the NTLM authentication exchange?

Hard
7

What is the purpose of 'Network Segmentation' during an active network incident?

Easy
8

You are using an IDS/IPS to detect lateral movement. You notice that your NIDS is not alerting on SSH brute force attempts. Which configuration check is most important to perform?

Hard
9

When reviewing firewall logs, you see many 'deny' events from an internal host to an external IP. What is the most likely cause?

Medium
10

You are identifying a compromised host by checking for beaconing behavior. Which network metric is most indicative of heartbeat-style beaconing?

Easy
11

An attacker is using ICMP tunneling to exfiltrate data. What field in an ICMP echo request packet would contain the unauthorized data?

Medium
12

Which technique should an incident responder use to prevent an infected host from spreading ransomware via SMB to other segments in the network?

Medium
13

Which TWO of the following techniques would an attacker likely use to hide lateral movement traffic within a network?

Hard
14

Which TWO of the following are common signs of a compromised switch in a local area network?

Easy
15

Which THREE of the following are key components of a network-based containment strategy?

Medium
16

A security analyst is investigating lateral movement using PowerShell Remoting (WinRM). Which Windows Event Log should be prioritized to confirm the execution of remote commands?

Medium
17

During an investigation into lateral movement, you notice an unusual RDP connection from a workstation to a domain controller. Which Wireshark filter would be most effective in isolating only the RDP traffic associated with that specific source IP to identify potential credential dumping activity?

Medium
18

Which TWO of the following are common network-based indicators of a compromised host attempting to perform network discovery?

Medium
19

You suspect a DNS tunneling attack for data exfiltration. In your DNS server logs, which characteristic is the strongest indicator of a tunnel rather than standard recursive lookups?

Hard
20

You are performing log correlation in a SIEM. You want to match Windows Event ID 4624 (Logon) with network traffic. Which field is the primary 'join key' to correlate the event with a specific network flow?

Medium
21

You are investigating a compromised Linux host. Using 'tcpdump' to capture traffic on interface eth0 to analyze C2 communication on port 443, which command is most efficient for saving the output to a file for later analysis in Wireshark?

Medium
22

Which THREE of the following represent critical log sources that should be correlated when investigating a potential network-based exfiltration incident?

Hard
23

Which TWO of the following indicators are primary artifacts to look for when investigating potential lateral movement on a Windows network?

Medium
24

Which syslog facility would typically be configured on a network device to send audit logs to a central server?

Easy
25

Which TWO of the following steps are considered best practices when performing network forensics on a live environment?

Medium
26

Which THREE of the following are effective network forensics techniques for identifying an attacker's C2 server infrastructure?

Hard

Frequently asked questions

What does the Network Incidents domain cover on the 212-89 exam?
Network Incidents questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 26 Network Incidents questions in the 212-89 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Network Incidents questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
Certified Incident Handler (212-89) Network Incidents Practice Questions