
GIAC Enterprise Incident Responder
Domain 1Objective 2
Enterprise Visibility and Incident Scoping GEIR Practice Questions (Page 11)
Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
11concepts
Questions 51–55
- 51
After containing an incident, the incident response team needs to communicate the scope to executives. What is the most important information to include in this communication?
Select an answer first - 52
Which of the following is an output of the incident scoping process?
Select an answer first - 53
A SIEM receives logs from multiple sources in different formats. The analyst wants to search for all failed logins across Windows, Linux, and firewall logs. The logs use different field names (e.g., 'EventID', 'message', 'action'). What is the most efficient way to enable a single search?
Select an answer first - 54
An organization has EDR on all endpoints but not on servers. During an incident, they suspect a server is compromised. The EDR on endpoints shows that a workstation connected to the server via RDP. What is the most important next step to scope the incident?
Select an answer first - 55
An incident responder is investigating a possible insider threat. The user is suspected of accessing sensitive files on a file server and then emailing them externally. Which combination of data sources would provide the most complete evidence of this activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.