
GIAC Certified Enterprise Defender
Domain 2Objective 1
Incident Response Concepts and Application GCED Practice Questions (Page 5)
Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
9concepts
Questions 21–25
- 21
An incident responder is collecting evidence from a compromised server that is also a critical production system. The server cannot be taken offline without causing significant business disruption. The responder needs to preserve evidence for potential legal action. Which approach best balances the need for evidence preservation with business continuity?
Select an answer first - 22
A large organization is responding to a multi-system breach. The incident commander is coordinating the response, but the lead analyst is unavailable due to illness. Which action best maintains the effectiveness of the incident response team?
Select an answer first - 23
What is the primary purpose of an incident response report?
Select an answer first - 24
Which stakeholder group should receive regular incident status updates during an active incident?
Select an answer first - 25
Which factor is most important when prioritizing incident response actions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.