
GIAC Certified Incident Handler
Domain 1Objective 1
Incident Response and Cyber Investigation GCIH Practice Questions (Page 3)
Part of the Incident Response and Investigation domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 11–15
- 11
An incident handler is investigating a data breach that involves customer personal information. The company's legal counsel has asked the handler to preserve all relevant evidence. Which action is most appropriate?
Select an answer first - 12
A small company has no dedicated incident response team. An employee discovers a potential data breach. According to incident response fundamentals, what is the first step the employee should take?
Select an answer first - 13
An incident handler is investigating a suspected data exfiltration by an employee. The employee's personal smartphone is found on the company premises. The company's policy allows monitoring of company-owned devices but not personal devices. What should the incident handler do?
Select an answer first - 14
After a security incident, the incident response team is in the recovery phase. Which action is most appropriate during this phase?
Select an answer first - 15
An incident handler is responding to a malware outbreak on several workstations. The team has isolated the affected systems. What should be done next in the incident response process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.