
GIAC Security Leadership
Domain 3Objective 3
Incident Response and Business Continuity GSLC Practice Questions (Page 9)
Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
15concepts
Questions 41–45
- 41
What is the first step in activating a business continuity plan?
Select an answer first - 42
In the eradication phase of incident response, what is the primary objective?
Select an answer first - 43
Who is typically responsible for communicating incident status to external parties such as law enforcement?
Select an answer first - 44
A company has activated its incident response team to handle a suspected data breach. The incident commander has been designated, and the team is assembled. The incident commander needs to assign a lead investigator to manage the technical investigation. Which responsibility is MOST appropriate for the lead investigator?
Select an answer first - 45
Which of the following is a common method for detecting a security incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.