EC-Council · ECIH
Incident handling and response practice for ECIH v3 exam 212-89, covering the full response lifecycle and seven major incident categories.
Practice Questions
590
≈ 4 practice exams
Duration
180 minutes
Passing Score
60-78% (exam form dependent)
Difficulty
AssociateLast Updated
Oct 2026
ECIH v3 follows incident response from preparation and triage through containment, evidence handling, eradication, recovery, and post-incident activity. Its 10 modules apply that process to malware, email, network, web application, cloud, insider-threat, and endpoint incidents rather than testing isolated security definitions.
Exam 212-89 contains 100 multiple-choice questions and allows three hours through the EC-Council Exam Portal. EC-Council does not use one universal pass percentage: its official iClass page says the cut score varies by exam form from 60% to 78%. Candidates qualify through official training or, with at least one year of relevant experience, through EC-Council's eligibility application process.
Use this 590-question bank to rehearse the response sequence and the reason for each action. Pair question practice with evidence preservation, log and traffic analysis, incident documentation, and playbook exercises; ECIH remains valid for three years and renewal requires 120 ECE credits during that cycle.
EC-Council Certified Incident Handler v3 is a method-driven incident response credential. Its curriculum moves from incident-response foundations, preparation, triage, notification, containment, evidence gathering, eradication, recovery, and lessons learned into response procedures for malware, email, network, web application, cloud, insider-threat, and endpoint incidents.
The program is aimed at incident handlers and responders, SOC staff, forensic investigators, cyber-threat and vulnerability analysts, penetration testers, and security operations professionals who participate in detecting, analysing, containing, or recovering from incidents.
Candidates qualify by completing official ECIH training or by applying to challenge the exam with at least one year of relevant work experience. EC-Council lists a $100 eligibility application fee for the experience route; it is included with official training.
Exam 212-89 contains 100 multiple-choice questions and allows three hours through the EC-Council Exam Portal. EC-Council uses multiple forms and states that the cut score varies from 60% to 78% depending on the form. The credential is valid for three years and requires 120 ECE credits to renew.
ECIH provides structured evidence of incident-response knowledge for SOC, CSIRT, forensics, cyber-defence, and security-operations roles. It is most useful when paired with hands-on evidence collection, investigation, containment, and recovery experience.
5 sample questions with answers and explanations. The full bank has 590 questions, enough for 4 full-length practice exams.
Preview — answers shown1. An incident handler images a suspect hard drive and calculates the hash value. The hash output is 64 hexadecimal characters long. Which hash algorithm was used? (Select one!)
Explanation
SHA-256 produces a 256-bit hash value represented as 64 hexadecimal characters. MD5 produces 128 bits or 32 hex characters. SHA-1 produces 160 bits or 40 hex characters. SHA-512 produces 512 bits or 128 hex characters. SHA-256 is the current recommended standard for forensic evidence integrity verification and is widely supported by forensic tools including FTK Imager, dcfldd, and EnCase.
2. A company implements the NIST Cybersecurity Framework 2.0 for incident response planning. Which function was newly added in version 2.0 that was not present in version 1.1? (Select one!)
Explanation
GOVERN is the new function added in NIST Cybersecurity Framework 2.0 to emphasize governance, risk management, and organizational context. The framework now includes six functions: GOVERN (new), IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER. The GOVERN function addresses cybersecurity strategy, expectations, and policies at the organizational level. PROTECT, DETECT, and RESPOND were all present in version 1.1 and remain in version 2.0 with updated guidance.
3. An organization implements ISO 27035 for information security incident management. How many phases does the ISO 27035 incident management framework define? (Select one!)
Explanation
ISO 27035 defines five phases for information security incident management: Plan and Prepare, Detection and Reporting, Assessment and Decision, Responses, and Lessons Learned. This differs from NIST SP 800-61 which has four phases and SANS PICERL which has six phases. The ISO framework emphasizes the Assessment and Decision phase as a distinct step between detection and response, recognizing that not all detected events require the same response actions. Organizations often choose between these frameworks based on regulatory requirements, organizational culture, and industry standards.
4. A CSIRT implements the NIST Cybersecurity Framework 2.0 for organizational security governance. Which function was newly added in version 2.0 that was not present in version 1.1? (Select one!)
Explanation
GOVERN is the new function added in NIST Cybersecurity Framework 2.0, emphasizing cybersecurity governance, risk management strategy, and organizational context. This function addresses the need for executive-level oversight and integration of cybersecurity into enterprise risk management. IDENTIFY, PROTECT, and RESPOND were all core functions in the original CSF 1.0 and remained in version 1.1 and 2.0. The six functions in CSF 2.0 are GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER.
5. An organization implements NIST Cybersecurity Framework 2.0 for incident response program development. Which new function was added in version 2.0 that did not exist in version 1.1? (Select one!)
Explanation
GOVERN is the new function added in NIST Cybersecurity Framework 2.0 that emphasizes cybersecurity governance, risk management strategy, and organizational context. This function addresses leadership and culture aspects that were previously embedded within other functions. The six functions in version 2.0 are GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER. RESPOND, DETECT, and RECOVER were all part of the original five functions in NIST CSF 1.0 and 1.1 (which had IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER).
The EC-Council Certified Incident Handler v3 exam code is 212-89.
ECIH has 100 multiple-choice questions and a three-hour time limit through the EC-Council Exam Portal.
There is no single fixed cut score. EC-Council says it varies by exam form from 60% to 78%.
Yes, if EC-Council approves an eligibility application based on at least one year of relevant experience. Its brochure lists a $100 application fee for this route.
The 10 modules cover the response process plus malware, email, network, web application, cloud, insider-threat, and endpoint incidents.
The credential is valid for three years. EC-Council requires 120 ECE credits during the cycle to renew it.
Digital Forensics Essentials (DFE)
DFE · 626 questions
EC-Council Certified Disaster Recovery Professional (EDRP)
EDRP · 623 questions
Certified Application Security Engineer .NET (CASE-.NET)
CASE-.NET · 625 questions
EC-Council Certified Encryption Specialist (ECES)
ECES · 627 questions
Ethical Hacking Essentials (EHE)
EHE · 627 questions
ICS/SCADA Cybersecurity
ICS-SCADA · 627 questions
$17.99
One-time access to this exam