Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 1Objective 1

Enterprise Environment Incident Response GCFA Practice Questions (Page 1)

Part of the Incident Response Fundamentals domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 8–14 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
9concepts

Questions 1–5

  1. 1application · medium

    A company's EDR solution has flagged a suspicious process on several endpoints. The IR team needs to determine if the process is malicious and whether it has spread. Which combination of tools would provide the most comprehensive view?

    Select an answer first
  2. 2foundation · easy

    What is the primary purpose of an after-action report (AAR) in enterprise incident response?

    Select an answer first
  3. 3foundation · easy

    What is the primary role of the business continuity plan (BCP) during an enterprise incident response?

    Select an answer first
  4. 4foundation · easy

    Which type of tool is most commonly used to investigate a compromised endpoint by examining running processes, memory, and file system artifacts?

    Select an answer first
  5. 5application · medium

    A company is updating its incident response policy. The policy must define the criteria for declaring an incident and the escalation path. Which component is most essential to include in the policy to ensure consistent and effective response?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.