Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Critical Infrastructure Protection (GCIP)

Domain 4Objective 2

Incident Reporting and Response Planning GCIP Practice Questions (Page 6)

Part of the Change, Vulnerability, and Incident Management domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
8concepts

Questions 26–30

  1. 26application · medium

    A city's IT department is updating its IR plan. The plan must clearly define who has the authority to declare an incident, who communicates with the media, and how the city council is notified. Which component of the IR plan is most directly being addressed?

    Select an answer first
  2. 27application · medium

    A small credit union is developing its first incident response plan. The board requires that the plan address regulatory reporting obligations under state data breach laws and the GLBA. The credit union has limited staff and budget. What is the most appropriate approach to plan development?

    Select an answer first
  3. 28expert · hard

    A multinational corporation suffers a data breach that affects customers in multiple jurisdictions. The IR plan requires immediate notification to regulators in some countries and allows up to 72 hours in others. The legal team is concerned about conflicting deadlines. The IR team has limited resources. What is the best approach?

    Select an answer first
  4. 29expert · hard

    A company's incident response team is documenting a data breach. The team lead wants to ensure that the documentation is admissible in court. Which practice is most important?

    Select an answer first
  5. 30application · medium

    During an active malware incident, a security analyst discovers that the incident response plan requires a written incident report to be filed within 24 hours of detection. The analyst is still containing the malware and does not have full details. What should the analyst do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIP” is a trademark of its owner, used for identification only.