
GIAC Certified Incident Handler
Domain 1Objective 2
Network and Log Investigations GCIH Practice Questions (Page 7)
Part of the Incident Response and Investigation domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
7concepts
Questions 31–35
- 31
After completing a network investigation, you must write a report for both technical staff and executive management. Which approach best meets the needs of both audiences?
Select an answer first - 32
You are the incident handler for a company that is about to enter litigation. You need to collect network logs from a firewall that is still in production. The logs are critical to the case. What is the most appropriate approach to preserve the evidence while minimizing operational impact?
Select an answer first - 33
When writing an incident report, what is the most important characteristic of the language used?
Select an answer first - 34
You are correlating logs from a web server, a database server, and an authentication server. The web server log shows a SQL injection attempt at 10:00. The database server log shows a query that returned a large result set at 10:01. The authentication server log shows a new admin account created at 10:05. What is the most likely attack chain?
Select an answer first - 35
Which tool is specifically designed to aggregate and correlate logs from multiple sources for security analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.