
GIAC Enterprise Incident Responder
Domain 3Objective 1
Detecting Modern Attacks GEIR Practice Questions (Page 3)
Part of the Modern Attack Detection domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 11–15
- 11
An analyst is mapping an incident to the kill chain. The evidence shows: a user clicked a malicious link in a phishing email, which downloaded a macro-enabled document that executed PowerShell, which then made a connection to an external IP. Which kill chain stages are represented?
Select an answer first - 12
A company's SOC receives an alert for a successful login from a new device for a user who typically works from a fixed office location. The login occurred at 3:00 AM local time. Which action best balances the need to detect a potential account compromise with minimizing disruption to the user?
Select an answer first - 13
What is the primary goal of integrating detection with incident response?
Select an answer first - 14
Which detection technique is most useful for identifying malicious code execution?
Select an answer first - 15
A security team is designing a detection strategy for a large enterprise with a mix of on-premises and cloud workloads. They want to detect modern attacks that use encrypted channels and legitimate cloud services for C2. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.