Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Incident Leader

Domain 1Objective 4

Ransomware Attacks GCIL Practice Questions (Page 1)

Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
8concepts

Questions 1–5

  1. 1application · medium

    A company's incident response team is analyzing a ransomware attack and discovers that the attackers exfiltrated sensitive data before encrypting systems, and then threatened to publish the data if the ransom was not paid. This tactic is characteristic of which ransomware family or model?

    Select an answer first
  2. 2foundation · easy

    Which of the following is a potential operational impact of a ransomware attack on an organization?

    Select an answer first
  3. 3foundation · easy

    Which delivery vector involves an attacker exploiting a vulnerability in a service exposed to the internet?

    Select an answer first
  4. 4expert · hard

    A multinational company has suffered a ransomware attack that encrypted critical systems and exfiltrated sensitive customer data. The company has cyber insurance that covers ransom payments, but the insurer's incident response team recommends paying the ransom to restore operations quickly. The company's legal counsel notes that the data includes personal information of EU residents, and the company has not yet determined whether the attackers have actually exfiltrated the data. The company's board is concerned about reputational damage and wants to minimize downtime. Which approach best balances legal, operational, and reputational considerations?

    Select an answer first
  5. 5application · medium

    During a ransomware incident, the incident response team has isolated affected systems and is preparing to recover from backups. Which step should be taken before restoring systems to ensure the ransomware does not re-infect the environment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.