Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Enterprise Incident Responder

Domain 1Objective 1

Enterprise Incident Response Management GEIR Practice Questions (Page 3)

Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 11–15

  1. 11application · medium

    A healthcare organization in the United States experiences a data breach involving protected health information (PHI). The incident response team has confirmed the breach and is preparing to respond. Which legal or regulatory requirement should the team consider FIRST?

    Select an answer first
  2. 12application · medium

    During a major incident, the IR team lead needs to ensure that the board of directors receives timely updates. Which role is BEST suited to prepare these updates?

    Select an answer first
  3. 13expert · hard

    An IR team is responding to a suspected data breach. The team has identified the initial access vector and is confident that the attacker is still active in the environment. The team lead must decide whether to contain immediately or continue monitoring to gather more intelligence. What is the MOST important consideration?

    Select an answer first
  4. 14expert · hard

    A company is responding to a ransomware incident. The incident response team has been activated, and the incident commander is assigning roles. The team includes a technical lead, a communications lead, a legal representative, and a business unit representative. The incident commander needs to ensure that the response is coordinated and that all stakeholders are informed. Which responsibility should the incident commander delegate to the communications lead?

    Select an answer first
  5. 15foundation · easy

    During triage, an incident is classified as 'high severity' because it involves the compromise of a database containing customer payment card data. Which action should the response team take first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.