Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Enterprise Incident Responder

Domain 3Objective 1

Detecting Modern Attacks GEIR Practice Questions (Page 1)

Part of the Modern Attack Detection domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
10concepts

Questions 1–5

  1. 1foundation · easy

    Mapping an attacker's technique to the 'Lateral Movement' stage of the MITRE ATT&CK framework helps analysts primarily to:

    Select an answer first
  2. 2expert · hard

    During an incident, the IR team discovers that the attacker has been using a compromised service account to authenticate to multiple servers and has created a new domain admin account. The team needs to contain the incident while minimizing downtime for business-critical applications that depend on the service account. Which containment strategy is most effective?

    Select an answer first
  3. 3expert · hard

    An organization is trying to detect C2 traffic that uses HTTPS to blend in with normal web traffic. They have a web proxy that can decrypt and inspect HTTPS traffic, but doing so requires installing a root certificate on all endpoints and may cause privacy concerns. Which approach would best balance detection capability with operational impact?

    Select an answer first
  4. 4expert · hard

    A SOC is investigating a potential breach. Alerts show: (1) a user reported a phishing email, (2) the same user's account logged in from a foreign IP, (3) the account then accessed a file share containing sensitive data, and (4) a new scheduled task was created on the user's workstation. The team has limited resources and must decide which alert to investigate first. Which alert should be prioritized?

    Select an answer first
  5. 5application · medium

    An incident responder notices that a security tool on a critical server has been stopped, and the Windows Event Log for the service has been cleared. The server is also running a scheduled task that was not present before. Which detection method would have been most likely to catch this defense evasion activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.