
GIAC Enterprise Incident Responder
Domain 1Objective 1
Enterprise Incident Response Management GEIR Practice Questions (Page 10)
Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 46–47
- 46
An organization has just experienced a minor security incident that was quickly contained. The IR team is now in the post-incident phase. Which activity is MOST appropriate for this phase?
Select an answer first - 47
A company is responding to a malware outbreak that has infected several servers and workstations. The incident response team has identified the malware and has a containment plan that involves isolating affected systems. However, some affected systems are critical to business operations and cannot be isolated without causing significant disruption. The team must balance containment with business continuity. Which approach should the team take?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GEIR
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.