Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Critical Infrastructure Protection (GCIP)

Domain 4Objective 2

Incident Reporting and Response Planning GCIP Practice Questions (Page 8)

Part of the Change, Vulnerability, and Incident Management domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
8concepts

Questions 36–40

  1. 36application · medium

    A regional water utility's SCADA network was hit by ransomware. The incident response team contained the threat, but the plant was offline for 14 hours. The utility's IR plan requires immediate notification to the state regulator and a post-incident report within 72 hours. During the after-action review, the team discovers that the initial detection was delayed because the on-call engineer did not recognize the early warning signs. Which action best addresses the root cause while meeting the reporting requirement?

    Select an answer first
  2. 37application · medium

    During a security incident, a system administrator discovers that the incident response plan requires all communication to be logged, but the team is using personal email to share sensitive details. What is the most appropriate action?

    Select an answer first
  3. 38application · medium

    During an active ransomware incident, the IR team lead instructs the team to document all actions in a shared log, including timestamps and the person performing each action. Which primary purpose does this documentation serve?

    Select an answer first
  4. 39application · medium

    A power utility wants to test its incident response plan's ability to coordinate with external agencies (e.g., state emergency management) during a simulated grid disturbance. The utility has never conducted a full-scale drill and wants to start with a method that tests coordination without the complexity of live systems. Which testing method is most appropriate?

    Select an answer first
  5. 40application · medium

    After a real malware incident, the IR team's after-action report identifies that the malware's command-and-control traffic was not detected because the network monitoring team lacked a playbook for that specific indicator. The team has since created a new detection rule. What is the most appropriate next step to ensure continuous improvement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIP” is a trademark of its owner, used for identification only.