
GIAC Cyber Incident Leader
Domain 2Objective 2
Incident Management Team Preparation GCIL Practice Questions (Page 9)
Part of the Incident Preparation and Prevention domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
Questions 41–45
- 41
What is the purpose of conducting regular training for incident management team members?
Select an answer first - 42
After a major incident, the incident management team conducts a lessons-learned review. The team identifies that the documentation was incomplete because team members were too busy with operational tasks to update logs. The team also notes that the incident commander was not aware of several key decisions made by the technical lead. Which improvement is most likely to address both issues?
Select an answer first - 43
What is the primary role of the public relations (PR) team during an incident?
Select an answer first - 44
Who typically holds the authority to make critical decisions during an incident, such as whether to shut down a critical system?
Select an answer first - 45
During a ransomware incident, the incident commander (IC) is off-site and unreachable. The deputy IC has been delegated authority to make operational decisions. A critical decision to isolate a core business system arises, which will cause significant downtime. The deputy IC is uncertain whether to proceed without the IC's approval. What should the deputy IC do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.