
GIAC Cyber Incident Leader
Domain 2Objective 1
Incident Preparation GCIL Practice Questions (Page 8)
Part of the Incident Preparation and Prevention domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
7concepts
Questions 36–40
- 36
An organization's incident response plan has not been updated in two years. During a recent incident, the team discovered that the plan referenced outdated contact information and did not include a newly adopted cloud service. What is the best way to maintain the plan going forward?
Select an answer first - 37
A newly formed incident response team is developing its first incident response plan. The team has limited experience and is unsure about the scope of the plan. The CISO wants the plan to be comprehensive but also practical and maintainable. Which approach is most appropriate for developing the plan?
Select an answer first - 38
A hospital's incident response team is being restructured. The team currently has a single incident commander who is also the IT director. During a recent ransomware attack, the IT director was overwhelmed trying to manage both the technical response and the communication with hospital leadership. The incident leader is tasked with improving the team structure. Which change is most effective?
Select an answer first - 39
An organization's incident response plan includes a detailed communication tree that lists specific individuals by name. Several of these individuals have left the company, and the plan has not been updated. During a recent incident, responders wasted time trying to contact former employees. What is the most effective way to prevent this in the future?
Select an answer first - 40
A company is updating its incident response plan. The plan currently defines the incident response team as a single group with no clear sub-teams. The company has grown and now has a dedicated security operations center (SOC), a threat intelligence team, and a communications team. The CISO wants to integrate these teams into the incident response plan. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.