
GIAC Cyber Incident Leader
Domain 1Objective 3
Email Attacks GCIL Practice Questions (Page 8)
Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 36–40
- 36
Which of the following is an indicator that an email may be spoofed?
Select an answer first - 37
Why is user awareness and training important in defending against email attacks?
Select an answer first - 38
A company wants to reduce the success of BEC and phishing attacks. They have implemented DMARC and email filtering, but users still occasionally fall for well-crafted lures. Which additional control would be most effective in reducing the impact of a user clicking a malicious link?
Select an answer first - 39
An organization's security team notices that attackers are sending emails that appear to come from the company's own domain (e.g., @company.com) to employees. The emails pass SPF and DKIM checks. Which additional control would most directly help prevent these spoofed emails from reaching employees?
Select an answer first - 40
A company has a mature security awareness program, but employees still occasionally fall for phishing emails that use urgent language and impersonate executives. The security team wants to reduce the success rate further. Which approach would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.