
GIAC Security Essentials
Domain 5Objective 1
Incident Handling & Response GSEC Practice Questions (Page 8)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 36–40
- 36
An incident responder needs to collect evidence from a compromised Linux server. The server is still running, and the responder wants to preserve volatile data. Which type of data should be collected FIRST?
Select an answer first - 37
After a ransomware incident, the incident response team has contained the spread and collected forensic images of affected servers. The company wants to restore operations as quickly as possible. Which step should be performed BEFORE restoring systems from backup?
Select an answer first - 38
After removing a web shell from a compromised web server, the incident response team wants to ensure the server is clean before returning it to production. Which step is MOST critical in the eradication phase?
Select an answer first - 39
A company has detected a worm that is spreading across its internal network. The worm exploits a vulnerability in a legacy application that cannot be patched immediately. The incident response team must contain the worm while maintaining business operations. Which containment strategy is most effective?
Select an answer first - 40
A company has experienced a ransomware attack that encrypted critical files. The incident response team has restored the files from backups and is now preparing a communication plan. The CEO wants to reassure customers that their data is safe, but the investigation has not yet confirmed whether customer data was exfiltrated. Which communication approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.