Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 5Objective 1

Incident Handling & Response GSEC Practice Questions (Page 4)

Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
8concepts

Questions 16–20

  1. 16application · medium

    During a malware outbreak, a security analyst identifies a single workstation that is actively communicating with a known command-and-control (C2) server. The workstation is used by the finance team and contains sensitive spreadsheets. The analyst needs to contain the threat while preserving evidence for potential legal action. Which containment action best balances these needs?

    Select an answer first
  2. 17application · medium

    A company has just finished responding to a ransomware incident. The incident response team is writing the final report. Which element is MOST important to include in the report for future prevention?

    Select an answer first
  3. 18expert · hard

    A company has experienced a data breach involving customer personal data. The incident response team is preparing to notify affected customers. The legal counsel advises that the notification must include the nature of the breach and the steps customers should take. The PR department wants to minimize reputational damage. Which communication approach BEST balances legal requirements and PR concerns?

    Select an answer first
  4. 19foundation · easy

    After resolving a security incident, the incident response team meets to discuss what went well and what could be improved. What is this activity called?

    Select an answer first
  5. 20application · medium

    An organization suspects an insider threat and needs to collect evidence from a laptop without alerting the employee. The legal team requires that the evidence be admissible in court. Which approach best preserves the integrity of the evidence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.