Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Enterprise Incident Responder

GEIRGIAC Enterprise Incident Response

The GIAC Enterprise Incident Response (GEIR) certification validates your command of enterprise-class incident response and threat hunting tools and techniques. It is designed for incident response team leads, threat hunters, and forensic analysts who must understand attacker movement across Windows, Linux, macOS, containers, and cloud environments. Earning GEIR proves you can coordinate large-scale investigations and respond effectively to modern attacks.

503 practice questions · Updated 2026-07-30

5Domains
11Objectives
97Concepts
503Questions

GEIR Curriculum

Every domain, objective, and concept the GEIR exam measures.

Enterprise Incident Response Management

7 concepts · 47 questions
  1. Incident Response Lifecycle
  2. Incident Response Team Roles
  3. Incident Classification and Triage
  4. Incident Response Procedures
  5. Communication and Coordination
  6. Legal and Regulatory Considerations
  7. Post-Incident Activities
  1. Enterprise Visibility Architecture
  2. Data Source Identification
  3. Log Collection and Aggregation
  4. Network Visibility
  5. Endpoint Visibility
  6. Cloud and Virtualized Environment Visibility
  7. Visibility Gaps and Limitations
  8. Incident Scoping Fundamentals
  9. Scoping Techniques
  10. Scope Expansion and Containment
  11. Documentation and Reporting of Scope

Rapid Response Triage at Scale

8 concepts · 47 questions
  1. Triage Fundamentals
  2. Triage Process Workflow
  3. Automated Triage Techniques
  4. Prioritization Criteria
  5. Data Sources and Enrichment
  6. Handling Alert Fatigue
  7. Human-in-the-Loop Decision Making
  8. Metrics and Continuous Improvement

Foundational Cloud Concepts

8 concepts · 49 questions
  1. Cloud Service Models
  2. Cloud Deployment Models
  3. Shared Responsibility Model
  4. Virtualization Fundamentals
  5. Cloud Storage and Data Lifecycle
  6. Cloud APIs and Management Plane
  7. Cloud Identity and Access Management
  8. Cloud Logging and Monitoring

Cloud Response and Analysis

9 concepts · 50 questions
  1. Cloud Incident Response Fundamentals
  2. Cloud Service Models and Shared Responsibility
  3. Cloud Evidence Acquisition
  4. Cloud Log Sources and Analysis
  5. Cloud Metadata and Instance Forensics
  6. Container and Orchestration Forensics
  7. Cloud Network Traffic Analysis
  8. Cloud Incident Containment and Remediation
  9. Cloud Forensic Challenges and Legal Considerations

Container DFIR Fundamentals

10 concepts · 47 questions
  1. Container Runtime Fundamentals
  2. Container Image Layers and Overlay Filesystems
  3. Container Namespaces and Isolation
  4. Container Control Groups (cgroups)
  5. Container Orchestration Basics
  6. Container Artifacts for Forensics
  7. Container Runtime Events and Logging
  8. Container Process and Network Visibility
  9. Container Image and Registry Forensics
  10. Container Isolation and Escape Indicators

Detecting Modern Attacks

10 concepts · 52 questions
  1. Modern attack detection fundamentals
  2. Attack lifecycle and kill chain mapping
  3. Detection of initial access vectors
  4. Detection of execution and persistence
  5. Detection of privilege escalation and lateral movement
  6. Detection of command and control (C2)
  7. Detection of data exfiltration
  8. Detection of defense evasion
  9. Correlation and alert triage
  10. Incident response integration

Linux Essentials

10 concepts · 29 questions
  1. Linux File System Hierarchy
  2. Essential Linux Commands
  3. File Permissions and Ownership
  4. Process Management
  5. User and Group Administration
  6. Package Management
  7. System Logging
  8. Networking Basics
  9. Shell Scripting Fundamentals
  10. Text Processing Tools

Linux DFIR Fundamentals

9 concepts · 53 questions
  1. Linux file system hierarchy
  2. File metadata and timestamps
  3. Process and memory artifacts
  4. User and authentication artifacts
  5. Persistence mechanisms
  6. Log analysis fundamentals
  7. Network configuration and connections
  8. File system integrity and hashing
  9. Acquisition and preservation basics

macOS Essentials

7 concepts · 33 questions
  1. macOS File System Layout
  2. macOS Plist Files
  3. macOS Logging Mechanisms
  4. macOS User and Account Management
  5. macOS Application and Process Management
  6. macOS Network Configuration
  7. macOS Security Features

macOS DFIR Fundamentals

8 concepts · 39 questions
  1. macOS File System Layout
  2. macOS Artifacts Overview
  3. macOS User and Account Management
  4. macOS Process and Application Execution
  5. macOS Network and Connectivity Artifacts
  6. macOS Persistence Mechanisms
  7. macOS Security and Privacy Features
  8. macOS Logging and Auditing
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GEIR, so none is invented.