
GIAC Cyber Incident Leader
Domain 1Objective 4
Ransomware Attacks GCIL Practice Questions (Page 2)
Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
Questions 6–10
- 6
A city government is hit by ransomware that encrypts critical systems, including the 911 dispatch center. The attackers demand a large ransom. The city's incident commander must decide whether to pay. Which consideration is most important in this decision?
Select an answer first - 7
What is a key legal consideration when deciding whether to pay a ransomware demand?
Select an answer first - 8
A company's security team notices a spike in failed RDP login attempts from external IP addresses. The team suspects that the company's RDP servers are being targeted for ransomware delivery. Which preventive measure would be most effective in reducing the risk of a successful RDP-based ransomware attack?
Select an answer first - 9
Which of the following is a common delivery vector for ransomware?
Select an answer first - 10
During which stage of a ransomware attack does the attacker typically establish persistence and escalate privileges?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.