
GIAC Critical Infrastructure Protection (GCIP)
Domain 4Objective 2
Incident Reporting and Response Planning GCIP Practice Questions (Page 7)
Part of the Change, Vulnerability, and Incident Management domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 31–35
- 31
A government agency has a mature incident response plan that has passed tabletop exercises. The agency now needs to test its ability to restore critical systems from backups during a simulated ransomware attack. The agency has a limited maintenance window and cannot risk production data loss. Which testing method is most appropriate?
Select an answer first - 32
During an incident response exercise, what is the role of the exercise controller or facilitator?
Select an answer first - 33
Which of the following is an example of an external reporting requirement for a significant cyber incident?
Select an answer first - 34
How should lessons learned from an actual incident be used to improve the incident response plan?
Select an answer first - 35
Which of the following is a common output of an incident response exercise evaluation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIP” is a trademark of its owner, used for identification only.