
GIAC Security Leadership
Domain 3Objective 3
Incident Response and Business Continuity GSLC Practice Questions (Page 11)
Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
15concepts
Questions 51–55
- 51
A security operations center receives multiple alerts: (1) a possible data exfiltration from a database server, (2) a denial-of-service attack on the public website, and (3) a phishing email that was quarantined. The SOC has limited staff. Which incident should be prioritized for immediate response?
Select an answer first - 52
During an incident, why is it important to keep management informed of the incident status?
Select an answer first - 53
Which incident response team role is responsible for gathering and analyzing evidence to determine the cause and scope of a security incident?
Select an answer first - 54
How does business continuity planning relate to incident response?
Select an answer first - 55
Which recovery objective indicates the maximum acceptable amount of data loss measured in time?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GSLC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.