
GIAC Enterprise Incident Responder
Domain 1Objective 2
Enterprise Visibility and Incident Scoping GEIR Practice Questions (Page 4)
Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
11concepts
Questions 16–20
- 16
During an incident, an analyst needs to determine whether a specific executable ran on a set of Windows endpoints. The endpoints have EDR agents installed, but the EDR console only shows alerts, not a full process execution history. Which additional data source would best help confirm execution?
Select an answer first - 17
When communicating incident scope to non-technical stakeholders, what is the most effective approach?
Select an answer first - 18
An incident responder is scoping a breach that may have started six months ago. The organization retains Windows Security logs for 90 days and firewall logs for one year. The attacker is believed to have used a valid account. Which limitation is most likely to prevent a complete scope determination?
Select an answer first - 19
What is the primary purpose of log normalization in a centralized log management system?
Select an answer first - 20
An incident responder has completed the initial scoping of a malware outbreak. Management asks for a summary of which systems are affected and what evidence supports that conclusion. What is the most appropriate way to document the scope?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.