
GIAC Cyber Incident Leader
Domain 4Objective 1
Incident Remediation and Closure GCIL Practice Questions (Page 10)
Part of the Incident Response and Remediation domain, which makes up ~6% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~3–5 in this domain), expect 3–5 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
Questions 46–48
- 46
A company has been responding to a data breach that involved exfiltration of customer data. The incident response team has contained the breach, eradicated the attacker's access, and restored systems. However, the forensic investigation is still ongoing, and the team is unsure if all exfiltration channels have been identified. The business wants to close the incident to reduce legal exposure. What is the most appropriate action?
Select an answer first - 47
During the post-incident review, the team identifies that the incident response plan lacked a clear escalation path for after-hours security alerts. What is the most effective way to capture this finding for improvement?
Select an answer first - 48
Which remediation strategy is primarily focused on restoring affected systems to a known-good state after the threat has been removed?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCIL
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.