
GIAC Cyber Incident Leader
Domain 4Objective 1
Incident Remediation and Closure GCIL Practice Questions (Page 8)
Part of the Incident Response and Remediation domain, which makes up ~6% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~3–5 in this domain), expect 3–5 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
Questions 36–40
- 36
After a malware infection on a file server, the incident response team has removed the malware and restored the server from a clean backup. However, the team is unsure if the malware persists in the backup itself. What is the most appropriate next step?
Select an answer first - 37
Which activity is part of the recovery phase after an incident has been eradicated?
Select an answer first - 38
Which containment measure is typically implemented first to quickly limit the spread of an active attack?
Select an answer first - 39
A company is responding to a supply-chain attack where a software update from a trusted vendor contained malware. The malware has been detected on several systems, but the vendor has not yet released a patched version. The company needs to continue using the software for critical business operations. What is the most appropriate remediation strategy?
Select an answer first - 40
An incident response team has completed eradication and recovery, but the incident commander is concerned that the closure criteria were not fully defined at the start of the incident. What should the team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.