
GIAC Enterprise Incident Responder
Domain 1Objective 2
Enterprise Visibility and Incident Scoping GEIR Practice Questions (Page 1)
Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
11concepts
Questions 1–5
- 1
An organization has deployed an EDR solution on all workstations but not on servers. During an incident, analysts suspect a server is compromised but have no EDR data for it. Which alternative data source would provide the most useful endpoint visibility for the server?
Select an answer first - 2
When new evidence indicates that additional hosts are compromised, what should the incident responder do?
Select an answer first - 3
Which Windows event log is the primary source for tracking process creation events?
Select an answer first - 4
An organization is investigating a suspected data exfiltration. They have NetFlow data showing a large outbound transfer from a workstation to an external IP, but they need to determine exactly what data was sent. Which data source should they consult to reconstruct the content of the transfer?
Select an answer first - 5
Which endpoint visibility capability is provided by Endpoint Detection and Response (EDR) tools?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.