Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 5Objective 1

Incident Handling & Response GSEC Practice Questions (Page 7)

Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
8concepts

Questions 31–35

  1. 31application · medium

    A company discovers that an attacker has compromised a domain controller and is using it to authenticate to other systems. The incident response team needs to contain the incident while maintaining business operations. Which containment strategy is most effective in this situation?

    Select an answer first
  2. 32expert · hard

    An organization is responding to a suspected insider threat. The incident response team has identified a laptop that may contain evidence of unauthorized data access. The laptop is currently in use by the employee, and the company wants to avoid alerting the employee. The legal team requires that evidence be preserved for potential litigation. Which action best preserves evidence while minimizing the risk of alerting the employee?

    Select an answer first
  3. 33application · medium

    A security operations center (SOC) receives an alert about a possible malware infection on a server that hosts a critical customer-facing application. The alert is based on a signature that has a high false-positive rate. The SOC analyst must decide whether to treat this as an incident. Which action is most appropriate?

    Select an answer first
  4. 34foundation · easy

    After containing a ransomware incident, the incident response team deletes the malicious files and removes the registry entries that allowed the ransomware to execute. Which phase of incident handling does this activity represent?

    Select an answer first
  5. 35application · medium

    A company discovers that an attacker has been exfiltrating data from a file server for several weeks. The attacker's access is through a compromised service account. The team needs to stop the exfiltration while preserving evidence. Which action should be taken FIRST?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.