
GIAC Enterprise Incident Responder
Domain 3Objective 1
Detecting Modern Attacks GEIR Practice Questions (Page 2)
Part of the Modern Attack Detection domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 6–10
- 6
Which technique is associated with privilege escalation?
Select an answer first - 7
An analyst sees a series of events: a workstation makes an SMB connection to a server, then a process on the server runs mimikatz, and then the server makes an SMB connection to a domain controller. Which attack chain is this?
Select an answer first - 8
A security team is investigating a workstation that is making DNS queries for random-looking subdomains under a single domain, such as 'a1b2c3.example.com', 'd4e5f6.example.com', and so on. The queries occur at irregular intervals. The team suspects domain generation algorithm (DGA) traffic. Which detection approach is most appropriate to confirm this suspicion?
Select an answer first - 9
A security team is struggling to detect modern attacks because attackers are using legitimate administrative tools like PowerShell and WMI to perform malicious actions. The team's current detection rules are signature-based and focus on known malware. Which improvement would most enhance the team's ability to detect these attacks?
Select an answer first - 10
Which of the following is a common persistence mechanism used by attackers?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.