Free 212-89 Practice Test Questions and Answers (2026)
Last Update Check
Q: 1
[Incident Handling and Response Process]
Alice is a disgruntled employee. She decided to acquire critical information from her organization for
financial benefit. To acccomplish this, Alice started running a virtual machine on the same physical
host as her victim's virtual machine and took advantage of shared physical resources (processor
cache) to steal data (cryptographic key/plain text secrets) from the victim machine. Identify the type
of attack Alice is performing in the above scenario.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
[Introduction to Incident Handling and Response]
Which of the following GPG18 and Forensic readiness planning (SPF) principles states
that “organizations should adopt a scenario based Forensic Readiness Planning
approach that learns from experience gained within the business”?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
[Introduction to Incident Handling and Response]
ZYX company experienced a DoS/DDoS attack on their network. Upon investigating the incident, they
concluded that the attack is an application-layer attack. Which of the following attacks did the
attacker use?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
[Introduction to Incident Handling and Response]
An insider threat response plan helps an organization minimize the damage caused by malicious
insiders. One of the approaches to mitigate these threats is setting up controls from the human
resources department. Which of the following guidelines can the human resources department use?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
[Introduction to Incident Handling and Response]
Which of the following is the BEST method to prevent email incidents?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
[Introduction to Incident Handling and Response]
Which of the following techniques prevent or mislead incident-handling process and may also affect
the collection, preservation, and identification phases of the forensic
investigation process?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
[Handling and Responding to Web Application Attacks]
Oscar receives an email from an unknown source containing his domain name oscar.com. Upon
checking the link, he found that it contains a malicious URL that redirects to the website evilsite.org.
What type of vulnerability is this?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
[Introduction to Incident Handling and Response]
Darwin is an attacker residing within the organization and is performing network
sniffing by running his system in promiscuous mode. He is capturing and viewing all
the network packets transmitted within the organization. Edwin is an incident handler
in the same organization.
In the above situation, which of the following Nmap commands Edwin must use to
detect Darwin’s system that is running in promiscuous mode?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
[Handling and Responding to Email Security Incidents]
Francis received a spoof email asking for his bank information. He decided to use a tool to analyze
the email headers. Which of the following should he use?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
[Introduction to Incident Handling and Response]
Farheen is an incident responder at reputed IT Firm based in Florid
a. Farheen was asked to investigate a recent cybercrime faced by the organization. As part of this
process, she collected static data from a victim system. She used DD tool command to perform
forensic duplication to obtain an NTFS image of the original disk. She created a sector-by-sector
mirror imaging of the disk and saved the output image file as image.dd.
Identify the static data collection process step performed by Farheen while collecting static data.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
[Introduction to Incident Handling and Response]
A malicious, security-breaking program is disguised as a useful program. Such executable programs,
which are installed when a file is opened, allow others to control a user's system. What is this type of
program called?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
[Incident Handling and Response Process]
Your company holds a large amount of customer PH. and you want to protect those data from theft
or unauthorized modification. Among other actions, you classify and encrypt the dat
a. In this process, which of the following OWASP security risks are you guarding against?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
[Introduction to Incident Handling and Response]
Matt is an incident handler working for one of the largest social network companies, which was
affected by malware. According to the company’s reporting timeframe guidelines, a malware
incident should be reported within 1 h of discovery/detection after its spread across the company.
Which category does this incident belong to?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
[Introduction to Incident Handling and Response]
Zaimasoft, a prominent IT organization, was attacked by perpetrators who directly targeted the
hardware and caused irreversible damage to the hardware. In result, replacing or reinstalling the
hardware was the only solution.
Identify the type of denial-of-service attack performed on Zaimasoft.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
[Handling and Responding to Malware Incidents]
An attacker traced out and found the kind of websites a target company/individual is
frequently surfing and tested those particular websites to identify any possible
vulnerabilities. When the attacker detected vulnerabilities in the website, the attacker
started injecting malicious script/code into the web application that can redirect the
webpage and download the malware onto the victim’s machine. After infecting the
vulnerable web application, the attacker waited for the victim to access the infected web
application.
Identify the type of attack performed by the attacker.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
[Introduction to Incident Handling and Response]
Eve’s is an incident handler in ABC organization. One day, she got a complaint about email hacking
incident from one of the employees of the organization. As a part of
incident handling and response process, she must follow many recovery steps in order to recover
from incident impact to maintain business continuity.
What is the first step that she must do to secure employee account?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
[Introduction to Incident Handling and Response]
A user downloaded what appears to be genuine software. Unknown to her, when she installed the
application, it executed code that provided an unauthorized remote attacker access to her computer.
What type of malicious threat displays this characteristic?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
[Introduction to Incident Handling and Response]
The following steps describe the key activities in forensic readiness planning:
1. Train the staff to handle the incident and preserve the evidence
2. Create a special process for documenting the procedure
3. Identify the potential evidence required for an incident
4. Determine the source of the evidence
5. Establish a legal advisory board to guide the investigation process
6. Identify if the incident requires full or formal investigation
7. Establish a policy for securely handling and storing the collected evidence
8. Define a policy that determines the pathway to legally extract electronic evidence
with minimal disruption
Identify the correct sequence of steps involved in forensic readiness planning.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
[Introduction to Incident Handling and Response]
If the browser does not expire the session when the user fails to logout properly, which of the
following OWASP Top 10 web vulnerabilities is caused?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
[Introduction to Incident Handling and Response]
Which one of the following is Inappropriate Usage Incidents?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20