212-89 Verified 2026 Edition

Certified Incident Handler (ECIH)Practice Test

Master the Certified Incident Handler (ECIH) with the official PlanetCert Practice Test. Access real exam questions, professional-grade detailed explanations, and our advanced adaptive simulator. Pass your certification exam on the first attempt.

350 Total Questions
1 Included Version Get all versions for the price of one
English Edition
All-In-One Bundle
$79.99
$75.99
  • Interactive Simulator & AI
  • Detailed Explanations
  • Study, Timed & Flashcard Mode
  • Lifetime Access & Updates

Instant lifetime access • Secure checkout

Why Study with PlanetCert?

The Latest Questions

Practice questions and exam topics aligned with the current exam objectives.

Detailed Explanations

Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI

AI-Powered Insights

Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.

Exam Information

Official specifications published by EC-Council

Exam Format

180 min
100
70%
Professional

Registration

$250 USD
Pearson VUE, ECC Exam Center, or online proctoring

Validity

3 years
Earn 120 ECE (EC-Council Continuing Education) credits over 3 years; Submit 40 ECE credits annually; Pay annual membership fee of $80 USD

212-89 Exam Topics and Domains

212-89 is organized into 10 weighted domains. Expect to work with DLP Solutions, EDR Solutions, Identity Management, Network Access Control, and more.

1

Introduction to Incident Handling and Response

10%

Information Security Threats and Attack Vectors

Threat Landscape OverviewDefense Frameworks
  • Understand various information security threats and attack vectors
  • Apply defense frameworks to incident handling scenarios
  • Recognize the role of cybersecurity frameworks in incident response

Incident Management Processes

Automation and OrchestrationBest Practices and Standards
  • Implement automation and orchestration in incident response
  • Comply with industry standards and legal requirements
  • Apply best practices for incident management
2

Incident Handling and Response Process

15%

IH&R Workflow Stages

Preparation PhaseDetection and RecordingTriage and Notification
  • Execute all phases of the incident handling workflow
  • Properly document incidents from detection through resolution
  • Manage stakeholder communication and escalation

Containment and Evidence Gathering

Containment StrategiesForensic Evidence Collection
  • Implement appropriate containment strategies
  • Collect and preserve forensic evidence properly
  • Maintain chain of custody throughout the process

Eradication, Recovery, and Post-Incident Activities

Eradication ProceduresRecovery and RestorationPost-Incident Review
  • Eradicate threats completely from affected systems
  • Restore systems and services to normal operations
  • Conduct effective post-incident reviews and reporting

Information Sharing Activities

Threat Intelligence Sharing
  • Share threat intelligence appropriately with stakeholders
  • Use standard protocols for information exchange
  • Participate in collaborative defense efforts
3

First Response

10%

Securing and Documenting the Crime Scene

Crime Scene Management
  • Secure incident scenes properly to preserve evidence
  • Document initial conditions and observations
  • Control access to affected systems and locations

Evidence Collection Procedures

Volatile Data Collection
  • Collect volatile evidence following proper order
  • Use appropriate tools for evidence collection
  • Maintain evidence integrity during collection

Preserving, Packaging, and Transporting Evidence

Evidence Handling
  • Preserve evidence integrity through proper handling
  • Package and transport evidence securely
  • Maintain complete chain of custody documentation
4

Handling Malware Incidents

15%

Malware Incident Lifecycle

Preparation for Malware IncidentsDetection and ContainmentAnalysis and EradicationRecovery and Prevention
  • Handle malware incidents through complete lifecycle
  • Analyze malware using static and dynamic techniques
  • Implement preventive measures to reduce future incidents
5

Handling Email Security Incidents

10%

Email Security Incident Handling

Email Threat DetectionContainment and AnalysisEradication and Recovery
  • Detect and analyze email-based threats
  • Contain email security incidents effectively
  • Remediate compromised email accounts and systems
6

Handling Network Security Incidents

15%

Unauthorized Access Incidents

Detecting and Responding to Unauthorized Access
  • Detect unauthorized network access attempts
  • Investigate and contain access incidents
  • Remove attacker persistence mechanisms

Inappropriate Usage Incidents

Policy Violation Detection and Response
  • Monitor and detect inappropriate network usage
  • Enforce acceptable use policies
  • Handle policy violation incidents appropriately

Denial-of-Service Incidents

DDoS Detection and Mitigation
  • Identify and classify denial-of-service attacks
  • Implement effective DDoS mitigation strategies
  • Restore services after DDoS incidents

Wireless Network Security Incidents

Wireless Threat Response
  • Detect wireless security threats
  • Respond to wireless network incidents
  • Implement wireless security controls
7

Handling Web Application Security Incidents

10%

Web Application Incident Handling

Web Attack Detection and ResponseSecuring Web Applications
  • Detect and respond to web application attacks
  • Analyze web application security incidents
  • Implement security controls for web applications
8

Handling Cloud Security Incidents

10%

Cloud Platform Incident Handling

AWS Security IncidentsAzure Security IncidentsGoogle Cloud Security Incidents
  • Handle security incidents in AWS, Azure, and GCP environments
  • Analyze cloud platform logs and alerts
  • Implement cloud security best practices
9

Handling Insider Threats

5%

Insider Threat Management

Detection and InvestigationContainment and Mitigation
  • Detect and investigate insider threat incidents
  • Coordinate with HR and legal teams appropriately
  • Mitigate insider threat risks
10

Handling Endpoint Security Incidents

10%

Endpoint Incident Handling

Desktop and Laptop Security IncidentsMobile Device Security IncidentsIoT and OT Security Incidents
  • Handle endpoint security incidents across device types
  • Use EDR tools effectively for investigation and response
  • Secure IoT and OT environments

How do I earn this certification?

Passing 212-89 earns the EC-Council Certified Incident Handler (ECIH) certification. It sits in the Incident Response and Forensics track.

Next Level Options
  • 312-49 - Computer Hacking Forensic Investigator (CHFI) Advanced digital forensics specialization, natural progression from incident handling
  • 412-79 - EC-Council Certified Security Analyst (ECSA) Advanced penetration testing and vulnerability assessment skills
  • CCISO - Certified Chief Information Security Officer Executive-level certification for C-suite cybersecurity leadership
Alternative Paths

Practice with Precision

The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.

Launch Simulator

How to study for this exam?

The most effective way to prepare for 212-89 is by using the PlanetCert Simulator to practice questions and review detailed explanations.

What's changed on this exam?

Current Status
  • ACTIVE
  • Last content update: 2024-01-10
  • Announcement date: 2024-01-10
Updates
  • SOAR Platforms Latest AI-enhanced versions Increasing emphasis on automation and orchestration in ECIH exam • Release date: 2025-2026
  • Cloud Security Tools AWS GuardDuty ML, Azure Sentinel AI Cloud incident handling now core exam domain with 10% weighting • Release date: 2024-2025
  • EDR Solutions XDR Evolution Endpoint security incidents domain emphasizes EDR/XDR capabilities • Release date: 2024-2025

Who should take this exam?

  • Minimum 1 year of experience in cybersecurity domain
  • Fundamental understanding of cybersecurity concepts
  • Practical experience in incident handling (preferred)
  • Without official EC-Council training: 2 years of work experience in Information Security domain

Your Complete Exam Solution

Best-In-Class Practice Tests

Authentic, regularly updated questions that mirror the real exam. Verified, current material — not recycled dumps.

Topical Breakdown

Study by domain, pinpoint weak areas, and focus your time where it matters most. Every topic mapped to the official syllabus.

Flashcard Mode

Rapid-fire review to reinforce key concepts. Flip through questions and answers at your own pace before exam day.

See How You Compare Against Yourself

✕
✕
✕

Other Exam Prep

  • Outdated question dumpsRecycled, often inaccurate material
  • No explanationsMemorize answers without understanding
  • Static PDF filesNo interactive practice or feedback
  • Subscription feesRecurring charges, access expires
✓
✓
✓

PlanetCert

  • Verified, current questionsUpdated weekly to match live exam objectives
  • Expert-written rationalesUnderstand every concept, not just the answer
  • Session tracking & exam progressTrack every attempt, see your growth over time
  • Lifetime access, one pricePay once — updates included forever
CERTIFIED212-89

Study Naturally, Study Responsibly

Join thousands of certified professionals who trusted PlanetCert to pass on the first attempt.

Try Free Demo
Secure Checkout Lifetime Access Money-back Guarantee