
GIAC Enterprise Incident Responder
Domain 1Objective 2
Enterprise Visibility and Incident Scoping GEIR Practice Questions (Page 7)
Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
11concepts
Questions 31–35
- 31
A company is designing a visibility architecture. They want to ensure they can detect both network-based attacks and host-based attacks. Which combination of data sources would provide the most comprehensive coverage?
Select an answer first - 32
A company runs workloads in AWS and Azure. During an incident, the analyst needs to identify who created a new administrative user in the AWS account. Which data source should be queried first?
Select an answer first - 33
Which data source is most likely to reveal the initial exploit payload delivered to a victim host?
Select an answer first - 34
Which cloud service provides an audit log of API calls made in an AWS account?
Select an answer first - 35
In a virtualized environment, which component provides visibility into traffic between virtual machines on the same hypervisor?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.