Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC iOS and macOS Examiner

Domain 4Objective 2

Incident Response GIME Practice Questions (Page 1)

Part of the Incident Response and Advanced Techniques domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 4–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
2concepts

Questions 1–5

  1. 1application · medium

    A security analyst suspects a macOS system is compromised because an unknown process is making frequent connections to an external IP. The analyst needs to determine whether the process is malicious and how it persists. Which combination of actions provides the most useful evidence?

    Select an answer first
  2. 2application · medium

    During an incident on an iOS device, you need to determine if a malicious app is communicating with an external server. The device is jailbroken and you have root access. Which volatile data source would be most useful?

    Select an answer first
  3. 3expert · hard

    You are investigating a macOS system where malware has created a LaunchDaemon and a LaunchAgent. The LaunchDaemon runs as root, and the LaunchAgent runs as the user. You need to remove the malware while preserving evidence for legal proceedings. What is the most appropriate action?

    Select an answer first
  4. 4application · medium

    During an investigation, you find a suspicious LaunchDaemon plist in /Library/LaunchDaemons that runs a script. The script downloads a payload from a remote server and executes it. You need to determine the scope of the infection and preserve evidence. Which step should you perform FIRST?

    Select an answer first
  5. 5expert · hard

    During an incident, you find a LaunchAgent that runs a binary with a valid Apple Developer ID signature. The binary is making network connections that match known malware behavior. You need to decide whether to treat this as malicious. What is the most important factor in your decision?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GIME” is a trademark of its owner, used for identification only.