
GIAC Cyber Incident Leader
Domain 3Objective 1
Incident Assessment GCIL Practice Questions (Page 8)
Part of the Incident Assessment and Tracking domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
7concepts
Questions 36–40
- 36
What is the primary reason for preserving evidence in its original state during an incident?
Select an answer first - 37
A company is responding to a ransomware attack that has encrypted files on several servers. The incident response team is preparing to communicate with the board of directors. Which information is most important to include in the initial communication?
Select an answer first - 38
A hospital's IT team detects unusual outbound traffic from a medical device to an unknown IP address. The device is not critical to patient care at the moment. The team must classify the incident to determine the appropriate response path. Which classification is most appropriate?
Select an answer first - 39
What should be included in incident documentation to support tracking?
Select an answer first - 40
A university's IT department detects that a student has been using the campus network to launch port scans against external systems. The activity is not causing damage but violates the university's acceptable use policy. How should this incident be classified?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.