
GIAC Enterprise Incident Responder
Domain 1Objective 1
Enterprise Incident Response Management GEIR Practice Questions (Page 1)
Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 1–5
- 1
Which procedure is part of the eradication phase of incident response?
Select an answer first - 2
What is the primary purpose of a lessons-learned meeting after an incident?
Select an answer first - 3
An organization's IR team has confirmed that a worm is spreading across the network. The team has isolated the affected systems. What is the NEXT step in the containment phase?
Select an answer first - 4
After a major incident has been contained and eradicated, the incident response team is preparing for the post-incident activities. The team lead wants to ensure that the organization improves its security posture based on the lessons learned. Which activity should be included in the post-incident phase?
Select an answer first - 5
A healthcare organization discovers that a ransomware attack has encrypted the file server containing patient records. The IR team has contained the spread but has not yet determined whether any data was exfiltrated. The legal department asks the IR lead what information can be shared with the organization's cyber insurance carrier at this point. What is the most appropriate response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.