
GIAC Cyber Incident Leader
Domain 4Objective 1
Incident Remediation and Closure GCIL Practice Questions (Page 7)
Part of the Incident Response and Remediation domain, which makes up ~6% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~3–5 in this domain), expect 3–5 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
Questions 31–35
- 31
Which element should be included in post-incident documentation?
Select an answer first - 32
A company's file server is infected with a worm that spreads through SMB. The server is needed for business operations, but the worm is actively infecting other systems. What is the best remediation strategy?
Select an answer first - 33
After a major incident, the incident commander must produce a final report that will be shared with senior management and potentially regulators. The report must be accurate but also protect sensitive information. What is the best approach?
Select an answer first - 34
Which containment measure is designed to provide a more permanent control while the organization develops a full remediation plan?
Select an answer first - 35
During the lessons-learned meeting, the team discusses that the intrusion detection system generated too many false positives, causing analysts to miss the real alert. What is the most appropriate improvement to recommend?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.