Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 212-89 Exam Questions

Exam Name: Eccouncil EC-Council Certified Incident Handler v3 Exam
Exam Code: 212-89
Related Certification(s): Eccouncil Certified Incident Handler ECIH Certification
Certification Provider: Eccouncil
Actual Exam Duration: 180 Minutes
Number of 212-89 practice questions in our database: 305 (updated: Jul. 08, 2026)
Expected 212-89 Exam Topics, as suggested by Eccouncil :
  • Topic 1: Introduction to Incident Handling and Response: This section of the exam measures the competency of Cybersecurity Analysts in understanding the core concepts of information security threats, vulnerabilities, and various attack and defense frameworks. It covers foundational knowledge of incidents, their classification, and the incident management lifecycle. Candidates are expected to be familiar with automation and orchestration in response efforts, industry standards, security best practices, and legal compliance frameworks relevant to incident handling.
  • Topic 2: Incident Handling and Response Process: This part evaluates IT Security Operations Managers on their understanding of the structured incident handling and response process. It includes the recording, assignment, and triage of incidents, as well as the procedures for notifying stakeholders and containing threats. The module also examines capabilities in forensic evidence gathering, eradication and recovery strategies, post-incident review activities, and the significance of inter-organizational information sharing.
  • Topic 3: First Response: This section of the exam assesses Cybersecurity Analysts in their ability to carry out effective first response procedures. It includes securing and documenting crime scenes, evidence collection methodologies, and guidelines for preserving, packaging, and transporting digital and physical evidence in a way that maintains chain of custody and forensic integrity.
  • Topic 4: Handling and Responding to Malware Incidents:In this domain, IT Security Operations Managers are tested on their capacity to respond to malware incidents effectively. The focus lies on planning, detecting, containing, and analyzing malware threats. It also includes strategies for eradication and recovery, alongside evaluating real-world malware case studies and identifying applicable best practices to avoid recurrence.
  • Topic 5: Handling and Responding to Email Security Incidents: This part evaluates Cybersecurity Analysts on their ability to detect and mitigate email-based threats. It explores preparation, analysis, and containment measures in response to email-related incidents, as well as post-incident recovery steps. Candidates must interpret case studies and apply best practices for protecting enterprise email systems.
  • Topic 6: Handling and Responding to Network Security Incidents: This module assesses IT Security Operations Managers in their expertise to manage network-level security breaches. It includes the detection of unauthorized access, misuse, denial-of-service attacks, and wireless network threats. Practical case studies and preventive strategies are included to ensure operational security across distributed environments.
  • Topic 7: Handling and Responding to Web Application Security Incidents: This section measures Cybersecurity Analysts' proficiency in managing web application vulnerabilities and incidents. It covers the preparation, detection, containment, and resolution of threats within web-based platforms. Candidates are expected to understand analytical approaches, case-based examples, and protective techniques for securing application infrastructure.
  • Topic 8: Handling and Responding to Cloud Security Incidents: Here, IT Security Operations Managers are examined on their familiarity with cloud-specific threats across platforms like Azure, AWS, and Google Cloud. The focus is on recognizing incident types, handling and monitoring procedures, and recovery methods. The use of real-world scenarios helps to demonstrate effective response tactics and reinforce best practices in cloud environments.
  • Topic 9: Handling and Responding to Insider Threats: This module evaluates Cybersecurity Analysts on how well they understand and manage internal security risks. It includes detection and containment of insider threats, analysis and eradication procedures, and recovery from internal breaches. A case-study approach is used to test comprehension of best practices and response strategies that align with organizational policy.
  • Topic 10: Handling and Responding to Endpoint Security Incidents: This section measures the abilities of IT Security Operations Managers to protect various endpoint devices, including mobile, IoT, and operational technologies. It addresses the identification and mitigation of endpoint threats, with applied case examples to evaluate readiness and response capacity in complex technical environments.
Disscuss Eccouncil 212-89 Topics, Questions or Ask Anything Related
0/2000 characters

Justin Cook

5 days ago
Cloud Security Incidents often include tracing suspicious API calls or misconfigured IAM permissions and ask which cloud-native logs to collect or how to isolate a compromised instance. Know CloudTrail/Stackdriver/Azure Monitor equivalents, the shared responsibility model, and snapshotting volatile data, a teammate focused on those differences and earned the certification.
upvoted 0 times
...

Heather Wright

22 days ago
I spent extra time on first response decisions and chain of custody because the questions were picky about what to do next in the moment, and that focus helped me pass ECIH v3 without surprises.
upvoted 0 times
...

Steven Parker

1 month ago
Malware Incidents questions commonly present a compromised host and ask you to prioritize triage steps or interpret a memory or network capture to identify persistence and C2 behavior. Study static versus dynamic analysis basics, common indicators of compromise, and containment choices, a friend used Pass4Success question sets and cleared the exam quickly thanks to the concentrated practice.
upvoted 0 times
...

Edward Miller

2 months ago
The 212-89 ECIH v3 exam leaned heavily on process flow, so mapping each phase of incident handling to clear actions and evidence types is what finally made it click for me, and I passed on the first attempt.
upvoted 0 times
...

Donna Miller

2 months ago
Application Level Incidents often show up as scenario questions where you must parse web server logs or code snippets to determine if an SQL injection, XSS, or broken authentication was exploited. Focus on OWASP Top Ten, log correlation, and how input validation failures manifest in requests and errors, and a colleague who drilled those areas passed the exam.
upvoted 0 times
...

Ryan Rodriguez

3 months ago
The malware incidents section threw me with sandbox-evasion indicators and telling true hits from false positives was tricky. I focused on IOCs, dynamic analysis basics, and practice scenarios which helped.
upvoted 0 times

Sharon Stewart

3 months ago
For time management on Eccouncil 212-89 I flagged long scenario questions and came back to them after finishing quicker knowledge-based items.
upvoted 0 times

Maria Taylor

2 months ago
Interestingly, the network-level section used traffic-baseline questions that made you think in ranges instead of absolute yes/no answers.
upvoted 0 times

Dorothy Roberts

2 months ago
Another useful approach was to memorize the incident handling process steps so you could apply them quickly across malware, cloud, and email scenarios.
upvoted 0 times
...
...
...

Adam Cook

3 months ago
Meanwhile I had a hard time with questions that blended insider threat indicators and endpoint telemetry because they expected you to prioritize containment first.
upvoted 0 times
...

Jason Williams

3 months ago
Honestly, I found distinguishing between benign anomalous behavior and actual IOC signatures required stepping back and looking for multiple corroborating signs.
upvoted 0 times
...
...

Curtis

3 months ago
Confident I passed the ECIH v3 exam because of Pass4Success practice exams. Tip: Familiarize yourself with the exam format and question types.
upvoted 0 times
...

Page

4 months ago
Relieved to have passed the ECIH v3 exam with the support of Pass4Success practice tests. Tip: Don't underestimate the importance of hands-on experience.
upvoted 0 times
...

Aileen

4 months ago
Be ready for questions on Incident Response Planning. Understand the key components of an IR plan.
upvoted 0 times
...

Shalon

4 months ago
Aced the ECIH v3 exam! Pass4Success's practice tests were key to my success.
upvoted 0 times
...

Frankie

4 months ago
EC-Council Certified Incident Handler v3 - done and dusted! Pass4Success, you're a lifesaver!
upvoted 0 times
...

Julianna

5 months ago
I was worried about the exam's breadth, but Pass4Success offered focused reviews and hands-on labs that made the material click—stay motivated and finish strong!
upvoted 0 times
...

Luisa

5 months ago
Cleared ECIH v3 in record time. Pass4Success's questions were incredibly helpful. Grateful!
upvoted 0 times
...

Elza

5 months ago
The beginning was overwhelming with so many details, but Pass4Success helped me organize my study through concise guides and labs, and you can rise to the challenge too!
upvoted 0 times
...

Chau

5 months ago
Log correlation and evidence collection under time pressure got brutal. The practice tests by pass4success trained me to spot decoy data and pick the smallest viable evidence set.
upvoted 0 times
...

Elly

6 months ago
Pass4Success materials helped with questions on Incident Communication. Know how to effectively communicate with stakeholders during an incident.
upvoted 0 times
...

Sanjuana

6 months ago
ECIH v3 certification achieved! Pass4Success made prep a breeze with their relevant exam material.
upvoted 0 times
...

Janna

6 months ago
I felt jittery about incident containment under pressure, but the Pass4Success mock exams mirrored real scenarios and calmed my nerves—keep practicing, you'll prevail!
upvoted 0 times
...

Martina

6 months ago
My nerves kicked in during the first practice tests, yet pass4success provided clear explanations and practical labs, boosting my confidence—you've got this, stay persistent!
upvoted 0 times
...

Sabra

7 months ago
Aced the ECIH v3 exam thanks to Pass4Success. Tip: Revise the exam objectives thoroughly and practice with realistic questions.
upvoted 0 times
...

Huey

7 months ago
Initially anxious about timing and memory, Pass4Success drills built my pace and recall, and now I know I can handle tough questions—stay focused and believe in your preparation!
upvoted 0 times
...

Argelia

7 months ago
I successfully passed the EC-Council Certified Incident Handler v3 exam, thanks to the Pass4Success practice questions. A difficult question I faced was about endpoint security incidents, asking which endpoint detection and response (EDR) tools are most effective. I wasn't entirely sure, but I managed to pass.
upvoted 0 times
...

Edelmira

7 months ago
Network Security Monitoring questions were prevalent. Understand different monitoring techniques and tools.
upvoted 0 times
...

Mariann

8 months ago
Passed the EC-Council Certified Incident Handler v3 exam! The Pass4Success practice questions were incredibly helpful. One question that stumped me was about first response, specifically which actions should be taken first to secure a compromised system. I had to think hard, but I passed the exam.
upvoted 0 times
...

Lindsey

8 months ago
I struggled with threat hunting concepts and how to map attacker kill chains to containment steps. Pass4Success questions pinned down the exact sequence and helped me choose the right containment option.
upvoted 0 times
...

Emiko

8 months ago
Just passed the EC-Council Certified Incident Handler v3 exam! Thanks Pass4Success for the spot-on practice questions.
upvoted 0 times
...

Daron

8 months ago
Just got my EC-Council Certified Incident Handler v3 certification! Pass4Success made my short preparation time incredibly effective.
upvoted 0 times
...

Katy

9 months ago
The hardest part for me was incident response playbooks and reconstructing timelines from logs—the tricky questions around containment vs. eradication. Pass4Success practice exams helped me spot subtle wording that changes the recommended action.
upvoted 0 times
...

Viva

9 months ago
ECIH v3 exam was a breeze with Pass4Success practice exams. Tip: Focus on understanding the concepts, not just memorizing.
upvoted 0 times
...

Cherry

9 months ago
Passed the EC-Council ECIH v3 exam with the help of Pass4Success practice tests. Tip: Manage your time wisely and don't get stuck on a single question.
upvoted 0 times
...

Karan

9 months ago
The exam included scenarios on Incident Recovery. Study business continuity and disaster recovery plans.
upvoted 0 times
...

Francisca

10 months ago
I was nervous at the start, doubting if I'd remember the incident response steps, but Pass4Success structured practice and real-world scenarios gave me confidence, and you can do this too—keep pushing forward!
upvoted 0 times
...

Georgiann

10 months ago
I am happy to report that I passed the EC-Council Certified Incident Handler v3 exam. The practice questions from Pass4Success were very helpful. One challenging question was about insider threats, asking which monitoring tools are most effective for detecting suspicious employee behavior. I wasn't sure, but I still passed.
upvoted 0 times
...

Tula

10 months ago
Thanks to Pass4Success, I was ready for questions on Security Information and Event Management (SIEM). Know its key functions and benefits.
upvoted 0 times
...

Chauncey

10 months ago
ECIH v3 exam conquered! Pass4Success provided the most relevant practice questions. Saved me so much time!
upvoted 0 times
...

Lajuana

10 months ago
Just passed the EC-Council Certified Incident Handler v3 exam! The Pass4Success practice questions were a great resource. There was a tough question about malware incidents, asking which indicators are most reliable for identifying a ransomware infection. I wasn't completely confident, but I passed the exam.
upvoted 0 times
...

Percy

1 year ago
EC-Council ECIH v3 certified! Pass4Success practice tests were invaluable. Exam was challenging but I felt ready.
upvoted 0 times
...

Elmira

1 year ago
Be prepared for questions on Incident Containment strategies. Understand both short-term and long-term containment methods.
upvoted 0 times
...

jalolag

1 year ago
Community emergency response teams are an example of local-level preparedness, but I’m still not clear on how they fit into broader incident response frameworks covered in the 212-89 exam.
upvoted 1 times
...

Mari

1 year ago
Passed ECIH v3 exam with flying colors! Pass4Success materials were a game-changer for my quick prep.
upvoted 0 times
...

Jaime

1 year ago
Just became EC-Council Certified Incident Handler! Pass4Success questions were spot-on. Couldn't have done it without them.
upvoted 0 times
...

Beckie

1 year ago
The exam covered Social Engineering attacks. Study various techniques and prevention strategies.
upvoted 0 times
...

Curtis

1 year ago
Pass4Success prep was spot-on for Incident Triage questions. Practice prioritizing and categorizing incidents.
upvoted 0 times
...

Dorothy

1 year ago
ECIH v3 certification in the bag! Thanks Pass4Success for the relevant practice questions. Saved me weeks of studying!
upvoted 0 times
...

Desirae

1 year ago
Questions on Vulnerability Assessment were challenging. Familiarize yourself with common tools and methodologies.
upvoted 0 times
...

Andree

1 year ago
The ECIH v3 exam tests your understanding of CSIRT roles and responsibilities. Review team structures and functions.
upvoted 0 times
...

Rosio

1 year ago
EC-Council Certified Incident Handler v3 done! Pass4Success materials made all the difference in my short preparation time.
upvoted 0 times
...

Arletta

1 year ago
Be ready for questions on Incident Reporting and Documentation. Know the key components of an incident report.
upvoted 0 times
...

Teri

1 year ago
I passed the EC-Council Certified Incident Handler v3 exam, and the Pass4Success practice questions were very useful. One question that threw me off was about cloud security incidents, asking how to detect unauthorized access to cloud resources. I wasn't sure of the best answer, but I managed to pass.
upvoted 0 times
...

Augustine

2 years ago
Pass4Success materials helped me tackle questions on Threat Intelligence. Study different types of threat intel and their applications.
upvoted 0 times
...

Quiana

2 years ago
Passed my ECIH v3 exam today! Pass4Success practice tests were crucial for my success. Highly recommended!
upvoted 0 times
...

Tori

2 years ago
The exam included questions on Digital Forensics. Understand the basics of evidence collection and preservation.
upvoted 0 times
...

Kallie

2 years ago
Thrilled to have passed the EC-Council Certified Incident Handler v3 exam! The practice questions from Pass4Success were essential. One tricky question was about the incident response and handling process, specifically the steps involved in the containment phase. I had to guess, but I still passed the exam.
upvoted 0 times
...

Alise

2 years ago
Incident Handling procedures were a significant part of the exam. Review ISO 27035 and NIST SP 800-61 guidelines.
upvoted 0 times
...

Mike

2 years ago
ECIH v3 certification achieved! Pass4Success helped me prepare efficiently. Their questions matched the exam perfectly.
upvoted 0 times
...

Staci

2 years ago
I successfully passed the EC-Council Certified Incident Handler v3 exam, and the Pass4Success practice questions were a big help. A difficult question I encountered was about application level incidents, asking which logs are most critical for identifying a SQL injection attack. I wasn't entirely sure, but I managed to pass.
upvoted 0 times
...

Julio

2 years ago
Thanks to Pass4Success, I was well-prepared for questions on Incident Response Tools. Make sure you're familiar with popular IR software.
upvoted 0 times
...

Annice

2 years ago
Excited to announce that I passed the EC-Council Certified Incident Handler v3 exam! The Pass4Success practice questions were really helpful. One question that puzzled me was about email security incidents, specifically how to identify phishing emails based on header analysis. I wasn't sure of the exact answer, but I still passed.
upvoted 0 times
...

Annabelle

2 years ago
ECIH v3 exam tests your knowledge of Malware Analysis techniques. Study static and dynamic analysis methods thoroughly.
upvoted 0 times
...

Elli

2 years ago
Aced the EC-Council Certified Incident Handler exam! Pass4Success questions were incredibly similar to the real thing.
upvoted 0 times
...

Carisa

2 years ago
I passed the EC-Council Certified Incident Handler v3 exam, thanks to the practice questions from Pass4Success. There was a question about network level incidents that asked how to differentiate between a DDoS attack and a sudden spike in legitimate traffic. It was tough, but I made it through the exam.
upvoted 0 times
...

Eugene

2 years ago
Be prepared for scenario-based questions on Network Traffic Analysis. Practice interpreting packet captures and identifying anomalies.
upvoted 0 times
...

Adelina

2 years ago
Happy to share that I passed the EC-Council Certified Incident Handler v3 exam. The Pass4Success practice questions were spot on. One challenging question was about endpoint security incidents, asking which tools are most effective for detecting unauthorized access on a workstation. I wasn't completely confident in my answer, but I still managed to pass.
upvoted 0 times
...

Reed

2 years ago
ECIH v3 certified! Pass4Success materials were a lifesaver. Exam was tough, but I felt well-prepared.
upvoted 0 times
...

Cecil

2 years ago
Grateful to Pass4Success for their exam prep materials. Cyber Kill Chain questions were challenging but manageable with their resources.
upvoted 0 times
...

Peggie

2 years ago
Just cleared the EC-Council Certified Incident Handler v3 exam! The practice questions from Pass4Success were invaluable. There was a tricky question about the first response steps when encountering a potential security breach. Specifically, it asked which action should be prioritized to preserve evidence. I had to think hard about it, but I got through the exam successfully.
upvoted 0 times
...

Mi

2 years ago
Just passed the EC-Council Certified Incident Handler v3 exam! Incident Response Lifecycle questions were prominent. Focus on understanding each phase thoroughly.
upvoted 0 times
...

Lashonda

2 years ago
I recently passed the EC-Council Certified Incident Handler v3 exam, and the Pass4Success practice questions were a great help. One question that stumped me was about identifying the key indicators of an insider threat. It asked about the most common behavioral signs that might suggest an insider is planning malicious activity. I wasn't entirely sure of the answer, but I managed to pass the exam.
upvoted 0 times
...

Cletus

2 years ago
Just passed the EC-Council ECIH v3 exam! Thanks Pass4Success for the spot-on practice questions. Saved me tons of prep time!
upvoted 0 times
...

Charlesetta

2 years ago
Passing the Eccouncil EC-Council Certified Incident Handler v3 exam was a great accomplishment for me. The exam covered important topics like Incident Handling and Response Process. One question that I recall was about the key components of a comprehensive incident response plan. Despite feeling uncertain about my answer, I was able to pass the exam with flying colors, thanks to the help of Pass4Success practice questions.
upvoted 0 times
...

Lanie

2 years ago
Successfully completed the ECIH v3 certification! Focus on malware analysis techniques and tools. Be prepared to identify different types of malware based on behavior. Pass4Success really came through with relevant exam questions, making my prep time efficient and effective.
upvoted 0 times
...

Amos

2 years ago
My experience taking the Eccouncil EC-Council Certified Incident Handler v3 exam was challenging yet rewarding. With the assistance of Pass4Success practice questions, I was able to successfully navigate topics such as Handling and Responding to Cloud Security Incidents. One question that I remember from the exam was about the steps involved in responding to a security incident in a cloud environment. Although I had some doubts about my answer, I managed to pass the exam.
upvoted 0 times
...

Wilford

2 years ago
Aced the ECIH v3 exam! Expect scenario-based questions on network traffic analysis. Know how to interpret packet captures and identify anomalies. Pass4Success practice tests were crucial for my success, covering all the right topics.
upvoted 0 times
...

Beckie

2 years ago
Just passed the EC-Council Certified Incident Handler v3 exam! Be prepared for questions on incident response phases, especially containment strategies. Study the NIST SP 800-61 framework thoroughly. Grateful to Pass4Success for their spot-on practice questions that helped me prepare efficiently in a short time. Good luck to future test-takers!
upvoted 0 times
...

Aleta

2 years ago
I recently passed the Eccouncil EC-Council Certified Incident Handler v3 exam with the help of Pass4Success practice questions. The exam covered topics such as Handling and Responding to Insider Threats and Forensic Readiness. One question that stood out to me was related to identifying indicators of insider threats within an organization. Despite being unsure of the answer, I was able to pass the exam.
upvoted 0 times
...

Daniel

2 years ago
Just passed the EC-Council Certified Incident Handler v3 exam! Be ready for questions on incident response phases and their order. Understand the difference between containment and eradication. Thanks to Pass4Success for the spot-on practice questions that helped me prepare quickly!
upvoted 0 times
...

Free Eccouncil 212-89 Exam Actual Questions

Note: Premium Questions for 212-89 were last updated On Jul. 08, 2026 (see below)

Question #1

Bob, an incident responder at CyberTech Solutions, is investigating a cybercrime attack occurred in the client company. He acquired the evidence data, preserved it, and started

performing analysis on acquired evidentiary data to identify the source of the crime and the culprit behind the incident.

Identify the forensic investigation phase in which Bob is currently in.

Reveal Solution Hide Solution
Correct Answer: D

Bob is in the Investigation phase of the forensic investigation process. This phase involves the detailed examination and analysis of the collected evidence to identify the source of the crime and the perpetrator behind the incident. It is a crucial step that follows the acquisition and preservation of evidence, where the incident responder applies various techniques and methodologies to analyze the evidentiary data. This analysis aims to uncover how the cybercrime was committed, trace the activities of the culprit, and gather actionable intelligence to support legal actions and prevent future incidents.


Question #2

Identify Sarbanes--Oxley Act (SOX) Title, which consists of only one section, that includes measures designed to help restore investor confidence in the reporting of

securities analysts.

Reveal Solution Hide Solution
Correct Answer: B

The Sarbanes--Oxley Act (SOX) Title V, titled 'Analyst Conflicts of Interest,' contains measures specifically designed to restore investor confidence in the reporting of securities analysts. It addresses the issue of potential conflicts of interest for securities analysts who recommend stocks and other securities by requiring disclosure of certain relationships and financial interests between analysts and the companies they cover. This part of the SOX Act aims to ensure that investors receive unbiased and accurate information from analysts, thereby helping to restore trust in financial markets. Title V consists of only one section, making it unique compared to other titles within the Act that may encompass multiple sections or provisions.


Question #3

Logan, an incident handler, ensures the chain of custody is documented while handling backup media post-attack. The goal is to preserve evidence integrity while restoring critical systems. Which recovery principle is Logan adhering to?

Reveal Solution Hide Solution
Correct Answer: A

The EC-Council Incident Handler (ECIH) curriculum stresses the importance of maintaining evidence integrity during recovery operations. Documenting the chain of custody ensures that evidence remains admissible in legal proceedings and maintains forensic validity.

Chain of custody documentation tracks who handled the evidence, when it was accessed, how it was stored, and what actions were performed. This aligns directly with forensic compliance principles, which require proper evidence preservation, documentation, and controlled handling procedures.

While restoring systems, responders must ensure that backup media and affected systems are handled in a way that does not compromise evidence. ECIH emphasizes that recovery should not destroy or contaminate forensic artifacts that may be required for legal, regulatory, or disciplinary action.

Option B (Network segmentation) relates to containment strategies. Option C (Immutable infrastructure) refers to architectural resilience models. Option D (Enhanced authentication) concerns access control, not evidence handling.

Therefore, Logan is adhering to forensic compliance principles during recovery.


Question #4

Dash wants to perform a DoS attack over 256 target URLs simultaneously.

Which of the following tools can Dash employ to achieve his objective?

Reveal Solution Hide Solution
Correct Answer: A

High Orbit Ion Cannon (HOIC) is a tool designed to perform stress testing on networks or servers. It can launch a Distributed Denial of Service (DDoS) attack by enabling an attacker to overwhelm a target with HTTP POST and GET requests. HOIC's distinctive feature is its ability to attack multiple targets (up to 256 URLs simultaneously) with configurable HTTP flood attacks. This capability makes it a preferred choice for attackers aiming to disrupt services on a large scale. Unlike tools designed for debugging or vulnerability scanning (e.g., IDA Pro, Ollydbg, OpenVAS), HOIC is specifically crafted for launching DoS/DDoS attacks, making it the correct answer for Dash's objective.


Question #5

John is a professional hacker who is performing an attack on the target organization where he tries to redirect the connection between the IP address and its target server such that when the users type in the Internet address, it redirects them to a rogue website that resembles the original website. He tries this attack using cache poisoning technique. Identify the type of attack John is performing on the target organization.

Reveal Solution Hide Solution
Correct Answer: B

Pharming is a cyber attack intended to redirect a website's traffic to another, bogus website. By poisoning a DNS server's cache, attackers can redirect users from the site they intended to visit to one that is malicious, without the user's knowledge or any action on their part, such as clicking a deceptive link. This technique is particularly insidious because it can affect well-intentioned users who type the correct URL into their browsers but are still redirected. War driving involves searching for wireless networks from a moving vehicle, skimming refers to stealing credit card information using a device placed on ATMs or point-of-sale terminals, and pretexting is a form of social engineering where the attacker lies to obtain privileged data.



Unlock Premium 212-89 Exam Questions with Advanced Practice Test Features:
  • Select Question Types you want
  • Set your Desired Pass Percentage
  • Allocate Time (Hours : Minutes)
  • Create Multiple Practice tests with Limited Questions
  • Customer Support
Get Full Access Now

Save Cancel