
GIAC Security Essentials
Domain 5Objective 1
Incident Handling & Response GSEC Practice Questions (Page 2)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 6–10
- 6
After a major security incident, the incident response team conducts a post-incident review. The team identifies that the incident was prolonged because the on-call analyst did not have access to the necessary log management tools. Which action should the team take to prevent this issue in the future?
Select an answer first - 7
A security analyst discovers that an employee's workstation has been compromised and may contain evidence of data exfiltration. The company plans to pursue legal action against the employee. Which action is MOST important to ensure the evidence is admissible in court?
Select an answer first - 8
A company has just finished eradicating a ransomware infection from all affected servers and restored data from backups. The incident response team is now meeting to discuss what went well and what could be improved. According to the incident handling phases, which activity should occur next?
Select an answer first - 9
An organization has just discovered a malware infection on a critical server. According to the standard incident handling phases, which phase should occur immediately after the containment phase?
Select an answer first - 10
A security analyst notices multiple failed login attempts followed by a successful login from an unusual geographic location. Which technique is being used to detect this potential incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.