Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Enterprise Incident Responder

Domain 1Objective 1

Enterprise Incident Response Management GEIR Practice Questions (Page 9)

Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 41–45

  1. 41application · medium

    An organization's SIEM alerts on suspicious outbound traffic from a database server. The IR team confirms that an attacker has been extracting data for the past 6 hours. The team has isolated the server and stopped the exfiltration. According to the incident response lifecycle, what is the NEXT major phase the team should formally enter?

    Select an answer first
  2. 42expert · hard

    A company's incident response team is responding to a suspected insider threat. A privileged user has been observed accessing sensitive data outside of normal working hours. The team has not yet confirmed whether the activity is malicious. The user is a senior executive, and the company has a strict policy against monitoring executives without board approval. The incident commander must balance the need to investigate with legal and policy constraints. Which action should the incident commander take?

    Select an answer first
  3. 43expert · hard

    A company discovers that a former employee's credentials were used to access a system containing trade secrets. The IR team has confirmed the access but has not yet determined if data was exfiltrated. The company's legal counsel wants to know if they should notify law enforcement. What is the MOST appropriate guidance?

    Select an answer first
  4. 44application · medium

    A company's security team is triaging three simultaneous alerts: (1) a phishing email that was reported by a user and not clicked, (2) a single workstation with confirmed malware that is isolated, and (3) a server that is actively communicating with a known command-and-control server and exfiltrating data. Which alert should the team prioritize?

    Select an answer first
  5. 45application · medium

    After a significant incident, the IR team is conducting a lessons-learned meeting. The team lead wants to ensure that the meeting produces actionable improvements. Which approach is MOST effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.