Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 1Objective 1

Enterprise Environment Incident Response GCFA Practice Questions (Page 10)

Part of the Incident Response Fundamentals domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 8–14 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
9concepts

Questions 46–50

  1. 46application · medium

    A ransomware incident has been confirmed on a segment of the corporate network. The incident commander needs to notify stakeholders without causing panic or leaking sensitive details. Which communication approach is most appropriate during the initial containment phase?

    Select an answer first
  2. 47application · medium

    After a phishing incident, the CISO wants to evaluate the effectiveness of the incident response team. Which metric would best measure the team's ability to limit the impact of the incident?

    Select an answer first
  3. 48application · medium

    An IR team wants to report to executive management on the effectiveness of the incident response process after a major incident. Which metric would be most useful for executives to understand the business impact?

    Select an answer first
  4. 49expert · hard

    A large enterprise has a decentralized IR structure where each business unit has its own IR team. A cross-business-unit incident is detected, and the teams are not coordinating effectively, leading to duplicated efforts and missed containment actions. The enterprise IR policy is being revised. Which change would most improve coordination across business units?

    Select an answer first
  5. 50application · medium

    A company's SIEM generates a high volume of alerts, many of which are false positives. The IR team is overwhelmed and missing real incidents. Which approach would most effectively improve the team's ability to detect and respond to genuine threats?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.