
GIAC Certified Enterprise Defender
Domain 2Objective 1
Incident Response Concepts and Application GCED Practice Questions (Page 10)
Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
9concepts
Questions 46–50
- 46
A company's incident response playbook for phishing incidents specifies that upon confirmation of a phishing email, the team should quarantine the email, block the sender, and reset the credentials of any user who clicked the link. A user reports a suspicious email, and the analyst confirms it is a known phishing campaign. Which action should the analyst take?
Select an answer first - 47
During a significant security incident, the incident commander asks the communications lead to provide a status update to executive leadership. The communications lead has detailed technical findings from the lead analyst. What should the communications lead include in the update?
Select an answer first - 48
After a security incident, the incident response team has completed the recovery phase and all systems are back to normal. The team is now meeting to discuss what went well and what could be improved. Which phase of the incident response lifecycle are they in?
Select an answer first - 49
An incident responder in the European Union is handling a data breach that involves personal data of EU citizens. The responder needs to collect evidence from a cloud service provider whose servers are located in the United States. What legal consideration is most important before transferring the evidence?
Select an answer first - 50
A mid-sized company has a playbook for phishing incidents. During a real phishing attack, the incident commander notices that the playbook's containment step assumes the email gateway can block the sender, but the gateway is misconfigured. What should the incident commander do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.