
GIAC Enterprise Incident Responder
Domain 1Objective 2
Enterprise Visibility and Incident Scoping GEIR Practice Questions (Page 9)
Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
11concepts
Questions 41–45
- 41
What is the primary purpose of incident scoping?
Select an answer first - 42
Which of the following is a data source that provides authentication activity across an enterprise?
Select an answer first - 43
Which technique involves examining events in chronological order to understand the sequence of an attack?
Select an answer first - 44
Which of the following best describes the three primary layers of an enterprise visibility architecture?
Select an answer first - 45
An organization wants to detect lateral movement between internal subnets. They currently have NetFlow enabled on core routers but no full packet capture. What is the most significant limitation of using only NetFlow for this detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.