
GIAC Defending Advanced Threats
Domain 5Objective 1
Reconnaissance, Threat Handling, and Incident Response GDAT Practice Questions (Page 2)
Part of the Defense and Response domain, which makes up ~13% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 7–10 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 6–10
- 6
Which of the following is an example of passive reconnaissance?
Select an answer first - 7
Which technique is classified as active reconnaissance?
Select an answer first - 8
During triage of a potential incident, an analyst finds a suspicious file on a workstation. The file hash matches a known malware signature, but the file is not executing and no other systems are affected. What is the most appropriate triage decision?
Select an answer first - 9
A post-incident review reveals that the incident response team did not have clear roles and responsibilities, leading to delayed decision-making. What is the most effective way to address this in the lessons learned phase?
Select an answer first - 10
A security analyst is reviewing web server logs and notices a pattern of requests to /admin, /backup, and /test directories from a single IP address. The requests are spread over several days and use different user agents. What does this pattern most likely indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.