Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Enterprise Incident Responder

Domain 1Objective 1

Enterprise Incident Response Management GEIR Practice Questions (Page 7)

Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 31–35

  1. 31application · medium

    During a large-scale incident, the IR team lead needs to ensure that the legal department is informed of any evidence that may be relevant to potential litigation. Which role is BEST suited to handle this coordination?

    Select an answer first
  2. 32application · medium

    A US-based company experiences a breach that affects the personal data of EU residents. The company has no physical presence in the EU but offers services to EU customers. The IR team is unsure whether the GDPR applies. What is the MOST accurate assessment?

    Select an answer first
  3. 33application · medium

    A company is responding to a ransomware incident that has affected a significant portion of its infrastructure. The incident commander has decided to pay the ransom to restore operations quickly. The legal team has advised that paying the ransom is not illegal in the company's jurisdiction but may have regulatory implications. Which action should the incident commander take regarding communication?

    Select an answer first
  4. 34foundation · easy

    What is the primary purpose of establishing a communication plan before an incident occurs?

    Select an answer first
  5. 35application · medium

    During a suspected data breach, the incident response team has identified a compromised server that is exfiltrating data to an external IP address. The server is running a critical business application that cannot be taken offline without significant operational impact. The team has network-level visibility and can block traffic at the firewall. Which action should the team take to contain the incident while minimizing business disruption?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.