
GIAC Enterprise Incident Responder
Domain 3Objective 1
Detecting Modern Attacks GEIR Practice Questions (Page 4)
Part of the Modern Attack Detection domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 16–20
- 16
A security analyst is correlating several alerts to determine if they are part of a single attack chain. The alerts are: (1) a user clicked a link in a phishing email, (2) a new scheduled task was created on the user's workstation, (3) the workstation made a connection to a known C2 domain, and (4) a large outbound data transfer occurred from the workstation. Select all that, when correlated, would most strongly indicate a complete attack chain from initial access to exfiltration.
Select an answer first - 17
During an incident investigation, an analyst finds a scheduled task that runs PowerShell with an encoded command every hour. The task was created by an unknown user SID. Which detection control would have most reliably identified this persistence mechanism earlier?
Select an answer first - 18
Which detection method is most effective for identifying pass-the-hash attacks?
Select an answer first - 19
A user reports receiving an email that appears to be from the company's IT department, urging them to click a link to 'verify their account' within 24 hours. The email's domain is similar but not identical to the corporate domain. The security team wants to detect this type of attack early in the kill chain. Which detection approach is most effective for identifying this initial access vector before the user interacts with it?
Select an answer first - 20
A security team notices that a host is making DNS queries for domains that look like random characters followed by '.com'. The queries occur at irregular intervals and each domain resolves to a different IP. The host also communicates with those IPs on port 443. Which detection technique would be most effective at identifying this as C2?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.