
GIAC Cyber Incident Leader
Domain 1Objective 4
Ransomware Attacks GCIL Practice Questions (Page 5)
Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
Questions 21–25
- 21
During a ransomware incident, the response team identifies that the attacker used a compromised VPN account to gain access, then moved laterally to the domain controller and deployed ransomware via Group Policy. The team has isolated the affected systems. Which step should be taken NEXT to eradicate the threat?
Select an answer first - 22
A security analyst is reviewing logs from a ransomware incident and identifies the following sequence: (1) a user clicked a link in a phishing email, (2) the attacker used a vulnerability in a web browser to execute code, (3) the attacker escalated privileges using a known Windows vulnerability, (4) the attacker deployed ransomware that encrypted files. Which stage of the ransomware attack lifecycle does the privilege escalation represent?
Select an answer first - 23
A user reports that their computer is displaying a full-screen message demanding payment to unlock the system, and the mouse and keyboard are unresponsive. The system does not appear to have any files encrypted, but the user cannot access the desktop. Which type of ransomware is most likely involved?
Select an answer first - 24
A company's security operations center (SOC) detects that a workstation is attempting to connect to multiple internal file shares and is executing a series of PowerShell commands that enumerate domain admin groups. The SOC suspects early-stage ransomware activity. Which immediate action should the incident response team take to contain the potential outbreak?
Select an answer first - 25
Why is a robust backup strategy considered a critical preventive control against ransomware?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.