Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Enterprise Incident Responder

Domain 3Objective 1

Detecting Modern Attacks GEIR Practice Questions (Page 10)

Part of the Modern Attack Detection domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
10concepts

Questions 46–50

  1. 46foundation · easy

    How do detection findings integrate into incident response processes?

    Select an answer first
  2. 47application · medium

    A company's security team notices that a server containing sensitive customer data is sending large volumes of data to an external IP address during off-peak hours. The data transfers are encrypted and occur over HTTPS. The team wants to detect if this is data exfiltration. Which detection technique would be most effective in this scenario?

    Select an answer first
  3. 48foundation · easy

    Which activity is an example of anti-forensics?

    Select an answer first
  4. 49foundation · easy

    Which technique is used by attackers to hide C2 traffic within legitimate-looking communications?

    Select an answer first
  5. 50application · medium

    An incident responder is analyzing an attack where the attacker used a valid user account to access a file share, then used a tool to dump credentials from memory, and finally transferred a large file to an external server. Which kill chain stages are represented in this attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.