
GIAC Cyber Incident Leader
Domain 3Objective 1
Incident Assessment GCIL Practice Questions (Page 9)
Part of the Incident Assessment and Tracking domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
7concepts
Questions 41–45
- 41
A regional bank's security operations center receives an alert about a phishing email that bypassed the gateway and was opened by three employees in the finance department. The email contains a link to a credential-harvesting page that is still active. The SOC lead must determine the initial priority. Which action should the SOC lead take first?
Select an answer first - 42
What is a key consideration when communicating assessment findings to stakeholders?
Select an answer first - 43
A multinational corporation experiences a data breach involving customer data from its European and US operations. The breach affects different data types and jurisdictions. The incident response team must classify the incident for reporting. What is the most appropriate classification approach?
Select an answer first - 44
In the incident management lifecycle, what is the primary purpose of incident assessment?
Select an answer first - 45
During an incident investigation, a security analyst discovers that an attacker modified a configuration file on a Linux web server. The analyst needs to preserve evidence for potential legal action. Which action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.