
GIAC Cyber Incident Leader
Domain 1Objective 4
Ransomware Attacks GCIL Practice Questions (Page 10)
Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
Questions 46–50
- 46
A manufacturing company discovers that files on several file servers are encrypted with a .locked extension. The initial infection is traced to a user who opened a malicious attachment from a phishing email. The attacker then used compromised credentials to move laterally and disabled the backup agent on the servers before deploying the ransomware. Which action should the incident response team take FIRST to limit further spread?
Select an answer first - 47
A hospital experiences a ransomware attack that encrypts its electronic health records (EHR) system, forcing the hospital to divert ambulances to other facilities for 48 hours. The hospital also faces a regulatory fine for failing to protect patient data. Which impact category does the ambulance diversion represent?
Select an answer first - 48
During a ransomware incident, the incident response team has isolated the affected systems and is now planning eradication and recovery. The organization has a backup strategy that includes daily snapshots stored on a separate NAS device. Which step should be taken BEFORE restoring from backups?
Select an answer first - 49
A company is hit by a ransomware variant that is known to be offered as Ransomware-as-a-Service (RaaS). The affiliate who deployed the ransomware used a phishing email to gain initial access, then used a PowerShell script to disable Windows Defender and delete shadow copies. The company has a backup solution that stores copies on a separate NAS device. During the incident, the attackers also exfiltrated data before encryption. The company is considering paying the ransom. Which factor is MOST important in deciding whether to pay?
Select an answer first - 50
A company's incident response team is analyzing a ransomware attack and discovers that the attackers used a legitimate administrative tool to disable security software and then deployed ransomware. The team also finds evidence that the attackers attempted to delete shadow copies and disable recovery features. Which ransomware family or tactic is most consistent with this behavior?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.