Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Critical Infrastructure Protection (GCIP)

Domain 4Objective 2

Incident Reporting and Response Planning GCIP Practice Questions (Page 1)

Part of the Change, Vulnerability, and Incident Management domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
8concepts

Questions 1–5

  1. 1expert · hard

    A financial institution experiences a data breach involving customer account numbers. The institution's incident response plan requires notification to the primary regulator within 36 hours, but the investigation is ongoing and the full scope is unknown. The legal team advises that the regulator expects a preliminary notification with known facts. What is the most appropriate action?

    Select an answer first
  2. 2application · medium

    A cloud service provider experiences a data breach involving customer personal data. The provider's legal team determines that multiple state breach notification laws apply, each with different notification deadlines. The incident response plan currently only lists a generic 'notify affected customers' step. What is the most appropriate action?

    Select an answer first
  3. 3application · medium

    After a major incident, a post-incident review identifies that the incident response plan did not include a procedure for preserving evidence for potential legal action. The organization's legal counsel advises that this is a critical gap. What should the organization do?

    Select an answer first
  4. 4application · medium

    A multinational corporation suffers a data breach that affects customers in the EU and the US. The incident response team is unsure which data protection authorities to notify. The plan does not address cross-border notification. What is the most appropriate immediate action?

    Select an answer first
  5. 5expert · hard

    A large hospital system is updating its incident response plan. The plan must comply with HIPAA breach notification rules and state laws. The hospital has a 24/7 security operations center (SOC) but the incident response team is only staffed during business hours. The compliance officer wants to ensure that breach notifications are made within the required timeframes. Which plan component is most critical to address?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIP” is a trademark of its owner, used for identification only.