
GIAC Certified Enterprise Defender
Domain 2Objective 1
Incident Response Concepts and Application GCED Practice Questions (Page 3)
Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
9concepts
Questions 11–15
- 11
What is the primary goal of the containment phase in incident response?
Select an answer first - 12
During an investigation, an analyst finds a suspicious process running on a compromised server. The analyst needs to determine what the process was doing at the time of the incident. Which forensic technique would provide the most direct evidence?
Select an answer first - 13
A forensic analyst is investigating a suspected data exfiltration incident. The analyst has a memory dump from the compromised system and needs to determine if any data was sent to an external IP address. Which forensic analysis technique would be most effective?
Select an answer first - 14
Which forensic analysis technique is used to examine the contents of a computer's RAM to find running processes and network connections?
Select an answer first - 15
In the incident response lifecycle, which phase focuses on removing the root cause of an incident from the environment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.