
GIAC Certified Incident Handler
Domain 1Objective 1
Incident Response and Cyber Investigation GCIH Practice Questions (Page 2)
Part of the Incident Response and Investigation domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 6–10
- 6
During an investigation of a suspected insider threat, an incident handler needs to collect a copy of an employee's local user profile from a Windows workstation. The company is in a jurisdiction with strict data protection laws. Which method best preserves the integrity of the evidence while respecting legal requirements?
Select an answer first - 7
A company's incident response team discovers that an employee's personal cloud storage account was used to exfiltrate corporate data. The employee is in a country with strict privacy laws. The incident handler needs to preserve evidence. Which action is most appropriate?
Select an answer first - 8
Which of the following is a primary responsibility of an incident handler during the response process?
Select an answer first - 9
During an incident, an incident handler needs to collect network traffic logs from a firewall. Which action is most important to ensure the logs are admissible as evidence?
Select an answer first - 10
A small company has just experienced a phishing attack that compromised one employee's email account. The incident handler is new and asks what the primary goal of incident response is in this situation. What is the best answer?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.