
GIAC Critical Controls Certification
Domain 7Objective 1
Incident Response Management GCCC Practice Questions (Page 5)
Part of the Incident Response and Testing domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 21–25
- 21
What is the primary benefit of conducting incident response simulations?
Select an answer first - 22
After a malware infection was contained and eradicated, the incident response team is conducting a post-incident review. The team identifies that the malware entered through an unpatched vulnerability in a public-facing application. Which action should the team take to prevent a similar incident?
Select an answer first - 23
During a major security incident, the incident response team is activated. The team includes a technical lead, a communications lead, a legal representative, and a forensic analyst. The incident involves a potential data breach that may affect customers. Who is responsible for communicating with external stakeholders, such as customers and regulators?
Select an answer first - 24
A mid-sized company has an incident response plan but has never tested it. The security manager wants to validate the plan's effectiveness and identify gaps without causing disruption to production systems. Which type of exercise should the security manager choose?
Select an answer first - 25
Why is timely reporting of an incident important?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.