
GIAC Cyber Incident Leader
Domain 4Objective 1
Incident Remediation and Closure GCIL Practice Questions (Page 9)
Part of the Incident Response and Remediation domain, which makes up ~6% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~3–5 in this domain), expect 3–5 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
Questions 41–45
- 41
During the post-incident review of a phishing campaign that led to credential compromise, the team notes that the email gateway had been configured to allow messages from a specific external domain because of a business partner. The review identifies that the gateway rule was overly broad. What is the most effective improvement to recommend?
Select an answer first - 42
A company is experiencing a DDoS attack that is overwhelming its internet-facing services. The attack is causing significant downtime, and the team is considering whether to implement rate limiting or to fail over to a cloud-based DDoS protection service. What is the most important factor in deciding the remediation strategy?
Select an answer first - 43
A company has been responding to a phishing incident that resulted in the compromise of several executive email accounts. The incident response team has reset the compromised accounts, removed the phishing emails, and implemented additional email filtering. The team is now considering whether to close the incident. Which factor is most important to consider before closing?
Select an answer first - 44
A multinational company is responding to a worm that spreads through a vulnerable network service. The worm is actively infecting Windows servers in multiple regions. The security team has a reliable patch, but deploying it to all servers will take several hours. Meanwhile, the worm continues to spread. What is the most effective immediate containment strategy?
Select an answer first - 45
After a ransomware attack, the team has restored all systems from backups. However, the backups were taken before the company implemented multi-factor authentication (MFA). The attacker had compromised a user account. What is the most important action to prevent a similar attack in the future?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.