Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Enterprise Defender

Domain 2Objective 1

Incident Response Concepts and Application GCED Practice Questions (Page 1)

Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
9concepts

Questions 1–5

  1. 1foundation · easy

    Which incident type is typically classified as having the highest severity?

    Select an answer first
  2. 2expert · hard

    A company discovers that an attacker has compromised a domain controller and used it to move laterally to several file servers. The attacker's activity appears to be ongoing. The company's priority is to stop the attacker while preserving evidence for a criminal investigation. Which containment strategy is most appropriate?

    Select an answer first
  3. 3foundation · easy

    Which type of forensic analysis would be most useful for determining what actions a user performed on a system at a specific time?

    Select an answer first
  4. 4foundation · easy

    Which benefit do standardized incident response procedures provide?

    Select an answer first
  5. 5foundation · easy

    What is the primary purpose of maintaining a chain of custody for digital evidence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.