
GIAC Cyber Incident Leader
Domain 3Objective 1
Incident Assessment GCIL Practice Questions (Page 7)
Part of the Incident Assessment and Tracking domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
7concepts
Questions 31–35
- 31
During a malware investigation, an analyst discovers that the malware deleted several log files on a compromised server. The analyst wants to document this finding for the incident report. What is the most appropriate way to record this information?
Select an answer first - 32
A security operations center is triaging multiple alerts. One alert indicates a possible malware infection on a server that is not critical to business operations. Another alert indicates a phishing email that was opened by a user in the finance department, but no credentials were submitted. Which alert should be prioritized?
Select an answer first - 33
A company's incident response team has confirmed a ransomware attack that has encrypted critical files. The team is preparing to communicate with stakeholders. Which communication is most appropriate for the IT help desk?
Select an answer first - 34
Which activity is a core component of incident assessment?
Select an answer first - 35
An incident response team has just contained a malware outbreak that affected several servers. The team is preparing to document the incident. Which documentation practice is most important for supporting the post-incident review?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.