
GIAC Enterprise Incident Responder
Domain 1Objective 2
Enterprise Visibility and Incident Scoping GEIR Practice Questions (Page 10)
Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
11concepts
Questions 46–50
- 46
What type of network data is generated by NetFlow or IPFIX?
Select an answer first - 47
What is a potential impact of a visibility gap on incident scoping?
Select an answer first - 48
A company runs workloads in a cloud environment. During an incident, the incident response team needs to determine which API calls were made by a compromised service account. Which data source would provide the most direct evidence of these API calls?
Select an answer first - 49
An organization has deployed EDR on all endpoints and has network flow logs from the perimeter. During an incident, they notice that a compromised endpoint is communicating with an internal server on port 445 (SMB). The EDR does not show any suspicious process on the endpoint. What is the most likely visibility gap?
Select an answer first - 50
Which of the following is an example of an application-layer data source in an enterprise visibility architecture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.