Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Critical Controls Certification

Domain 7Objective 1

Incident Response Management GCCC Practice Questions (Page 9)

Part of the Incident Response and Testing domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 41–45

  1. 41expert · hard

    An organization is planning to test its incident response plan. The organization has a mature security team but has never conducted a coordinated exercise. The goal is to test the team's ability to respond to a phishing attack that leads to credential compromise. The organization wants to minimize the risk of disrupting production. Which exercise type is most appropriate?

    Select an answer first
  2. 42application · medium

    An organization is planning to test its incident response capabilities. The team wants to evaluate decision-making and communication without affecting production systems. Which type of exercise should they conduct?

    Select an answer first
  3. 43application · medium

    A manufacturing company's IT team discovers that a ransomware attack has encrypted files on several file servers. The attack appears to have started from a single workstation. The company has backups that are verified to be clean. The incident response team is considering how to recover. Which approach should they take?

    Select an answer first
  4. 44application · medium

    A company's incident response team has contained a malware infection and eradicated the malware from all affected systems. The team is now ready to recover. What should the team do during the recovery phase?

    Select an answer first
  5. 45application · medium

    After a significant security incident, the incident response team has completed containment, eradication, and recovery. The team lead wants to ensure that the organization learns from the incident and improves its security posture. Which activity should the team lead prioritize?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.