Free GIAC Security Essentials practice — 6 questions on Incident Handling and Response, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Incident Handling and Response
A security analyst discovers a workstation actively encrypting files consistent with ransomware behavior. The IT manager wants to immediately power off the machine to stop the encryption. Which containment action is MOST appropriate to both stop the damage and preserve forensic value?
Isolating network connectivity halts lateral spread and encryption of network shares while leaving the system powered on preserves volatile memory (RAM) that may contain encryption keys, malicious process data, and active connections — critical for forensic analysis.
Question 2 of 6 · Incident Handling and Response
An organization's file server is backed up nightly at 02:00. A ransomware attack encrypts the server at 17:00 the same day, and the team restores from the most recent backup. What is the resulting Recovery Point Objective (RPO) actually realized for this incident?
The backup captured data as of 02:00; the disruption occurred at 17:00, meaning 15 hours had elapsed since the last backup, so up to 15 hours of changes were lost — that is the realized RPO for this incident.
Question 3 of 6 · Incident Handling and Response
A hospital's continuity planning team is drafting a document describing how patient admissions, billing, and clinical operations will continue — including relocating staff to a temporary facility, using paper-based charting, and reassigning duties — if the primary building becomes unusable after a flood. Which type of plan does this document represent?
A BCP addresses how an organization's critical business functions — not just IT systems — continue operating during and after a disruption, covering people, processes, alternate facilities, and manual workarounds, exactly as described.
Question 4 of 6 · Incident Handling and Response
During eradication following confirmation that a compromised Linux server had a kernel-mode rootkit installed, which action provides the highest assurance that the threat has been fully removed?
Kernel-mode rootkits can hide files, processes, and even subvert the antivirus scanner itself, making in-place cleaning unreliable. Rebuilding from known-good media is the only reliable eradication method for rootkit-level compromise.
Question 5 of 6 · Incident Handling and Response
Per RFC 3227 guidance on order of volatility (used as the basis for evidence collection priority during incident response), which of the following correctly orders forensic data sources from MOST volatile to LEAST volatile?
RFC 3227 orders volatility from registers/cache (most volatile, lost in nanoseconds) through RAM, then temp storage/swap, network state, disk, and finally archival/backup media (least volatile) — matching this sequence exactly.
Question 6 of 6 · Incident Handling and Response
An incident response team closes out a major data breach investigation after eradication and recovery are complete. According to standard incident handling practice, when should the 'lessons learned' meeting ideally be conducted, and why?
Standard incident handling guidance recommends holding the lessons-learned/post-incident review within roughly two weeks of closure — soon enough that details remain fresh, but with enough time for the team to compile logs, timelines, and complete impact assessments.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.