
GIAC Certified Incident Handler
Domain 1Objective 2
Network and Log Investigations GCIH Practice Questions (Page 3)
Part of the Incident Response and Investigation domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
7concepts
Questions 11–15
- 11
You need to collect firewall logs as evidence for a legal case. Which action is most important to maintain the admissibility of the evidence?
Select an answer first - 12
You are collecting evidence from a compromised Linux server. You need to preserve the current state of network connections and running processes for later analysis while maintaining chain of custody. Which action should you take first?
Select an answer first - 13
You have completed the analysis of a network intrusion. You need to write a section of the incident report that describes the sequence of events from initial compromise to data exfiltration. What is the most appropriate way to present this information?
Select an answer first - 14
When collecting network packet captures as evidence, which practice best supports chain of custody?
Select an answer first - 15
An incident responder is building a timeline of an attack. Which type of information is most useful for establishing the sequence of events?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.