Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Enterprise Incident Responder

Domain 1Objective 2

Enterprise Visibility and Incident Scoping GEIR Practice Questions (Page 9)

Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)

57questions here
12free pages
11concepts

Questions 41–45

  1. 41foundation · easy

    What is the primary purpose of incident scoping?

    Select an answer first
  2. 42foundation · easy

    Which of the following is a data source that provides authentication activity across an enterprise?

    Select an answer first
  3. 43foundation · easy

    Which technique involves examining events in chronological order to understand the sequence of an attack?

    Select an answer first
  4. 44foundation · easy

    Which of the following best describes the three primary layers of an enterprise visibility architecture?

    Select an answer first
  5. 45application · medium

    An organization wants to detect lateral movement between internal subnets. They currently have NetFlow enabled on core routers but no full packet capture. What is the most significant limitation of using only NetFlow for this detection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.