
GIAC Security Essentials
Domain 5Objective 1
Incident Handling & Response GSEC Practice Questions (Page 1)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 1–5
- 1
An incident responder is collecting evidence from a compromised Windows workstation. The workstation is still running, and the responder needs to preserve evidence for a court case. The responder has limited time before the system must be returned to production. Which evidence collection order is MOST appropriate?
Select an answer first - 2
A security analyst notices unusual outbound traffic from a server that is not supposed to communicate externally. The analyst suspects a compromise. Which incident handling phase should the analyst formally initiate?
Select an answer first - 3
A medium-sized company has just contained a data breach that exposed customer credit card numbers. The incident response team is preparing to communicate with stakeholders. Which stakeholder group should receive the MOST detailed technical information about the attack vector and compromised systems?
Select an answer first - 4
What is the primary purpose of documenting incident details during the response?
Select an answer first - 5
When collecting digital evidence from a compromised system, why is it important to create a forensic image of the storage media rather than simply copying individual files?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.