
GIAC Security Leadership
Domain 3Objective 3
Incident Response and Business Continuity GSLC Practice Questions (Page 4)
Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
15concepts
Questions 16–20
- 16
A company's security operations center (SOC) has detected a potential security incident. The SOC analyst has confirmed that the incident is real and has escalated it to the incident response team. Which action should the SOC analyst take NEXT?
Select an answer first - 17
Which of the following is a key output of a business impact analysis?
Select an answer first - 18
Why is it important for incident response and business continuity plans to be aligned?
Select an answer first - 19
In the incident response lifecycle, which phase involves restoring affected systems to normal operation while ensuring the threat is fully removed?
Select an answer first - 20
A security analyst detects a ransomware infection on a file server used by the finance department. The malware is actively encrypting files, and the analyst has confirmed the infection is spreading to other servers on the same network segment. The incident commander has been notified. Which action should be taken FIRST to limit the spread of the infection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.