
GIAC Cyber Incident Leader
Domain 2Objective 1
Incident Preparation GCIL Practice Questions (Page 10)
Part of the Incident Preparation and Prevention domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
7concepts
Questions 46–50
- 46
An organization's incident response team has a documented toolkit that includes a network analyzer, a forensic workstation, and a malware analysis sandbox. The team recently discovered that the forensic workstation's software is outdated and cannot analyze the latest disk formats. What should the incident leader do to ensure tool readiness?
Select an answer first - 47
A company's incident response team is selecting a new endpoint detection and response (EDR) tool. The team needs to ensure the tool can be deployed quickly during an incident and that analysts can access it remotely. The budget is limited, and the team wants to avoid long procurement cycles. Which approach best meets these needs?
Select an answer first - 48
An organization's incident response plan was last updated three years ago. Since then, the company has migrated to a cloud-based infrastructure and adopted a DevOps model. The incident leader is reviewing the plan for continuous improvement. What is the most important factor to consider when updating the plan?
Select an answer first - 49
After a significant data breach, an organization's incident response team conducted a thorough post-incident review. The review identified that the response plan did not include a clear communication strategy for notifying external stakeholders, and that several team members were unfamiliar with the plan's escalation procedures. What should the incident leader do to ensure continuous improvement of preparation?
Select an answer first - 50
A multinational organization maintains a single incident response plan that designates the global CISO as the sole incident commander for all incidents. After a regional ransomware event, the European response team waited over four hours for approval to contain the infection because the CISO was in a different time zone. The plan is now being revised. Which change best addresses the identified deficiency while preserving centralized governance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.