
GIAC Cyber Incident Leader
Domain 3Objective 2
Incident Tracking GCIL Practice Questions (Page 3)
Part of the Incident Assessment and Tracking domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
8concepts
Questions 11–15
- 11
An incident response team is evaluating tools for incident tracking. They need a solution that automatically captures timestamps for every change and allows multiple team members to update the same incident simultaneously. Which type of tool best meets these requirements?
Select an answer first - 12
What is the primary purpose of generating reports from incident tracking data?
Select an answer first - 13
Why is it important to log the actor (person or system) who performed each action during an incident?
Select an answer first - 14
A team is evaluating whether to use a dedicated incident tracking tool or continue using a general-purpose project management tool. The team needs to track incident-specific fields such as severity, containment status, and attacker indicators. Which consideration is most important?
Select an answer first - 15
An organization is required to produce a detailed incident timeline for a client. The tracking system contains entries, but some entries lack timestamps and actor names. What should be done to ensure future incidents produce complete timelines?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.