
GIAC Defending Advanced Threats
Domain 5Objective 1
Reconnaissance, Threat Handling, and Incident Response GDAT Practice Questions (Page 4)
Part of the Defense and Response domain, which makes up ~13% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 7–10 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 16–20
- 16
What is the main purpose of the post-incident activity phase in the incident response lifecycle?
Select an answer first - 17
A threat intelligence feed reports that a known APT group is using a specific phishing lure that drops a unique DLL loader. The feed includes the SHA256 hash of the loader and the subject line of the phishing email. How should the security team use this intelligence to improve detection?
Select an answer first - 18
Which containment strategy is most appropriate for a single infected workstation that is not critical to business operations?
Select an answer first - 19
A security analyst notices that an external IP has been performing DNS lookups for the company's internal hostnames (e.g., dc01.internal.company.com) and has also queried the company's public WHOIS records. No successful authentication has occurred. Which type of activity does this represent?
Select an answer first - 20
How does threat intelligence primarily inform the reconnaissance phase of an attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.