20+ practice questions focused on Incident Response and Cyber Investigation — one of the most tested topics on the GIAC Certified Incident Handler exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Incident Response and Cyber Investigation PracticeAn organization experiences a ransomware attack. During the containment phase, the Incident Response team must decide between isolating the affected subnet or shutting down the critical database server. Which factor should be the primary driver for this decision?
Explanation: Effective incident response requires balancing business continuity with risk mitigation. In this scenario, the team must prioritize evidence preservation and containment effectiveness. Isolating the subnet prevents lateral movement while allowing for forensic imaging without immediate data loss associated with a hard shutdown. Understanding the business impact of each containment action is vital for minimizing downtime while preventing further adversary exploitation during the critical moments of an active intrusion.
Which THREE factors should an investigator consider when evaluating the integrity of digital evidence collected during an incident?
Explanation: Evidence integrity is paramount for any forensic investigation. By using hashing, maintaining a strict chain of custody, and documenting the environment, an investigator ensures that the data presented in a report or court is authentic and untampered. Failure to account for these factors can lead to evidence being declared inadmissible or unreliable, undermining the entire investigative process and potentially allowing perpetrators to avoid accountability for their actions.
A GCIH incident handler is responding to a suspected data exfiltration incident on a Linux server. The handler needs to identify which processes are listening on network ports and which files they have open, to determine if a malicious backdoor is present. Which command should the handler use to list all open files and the processes that have them open?
Explanation: The `lsof` command provides a comprehensive list of all open files and the processes that have them open, including network sockets. This allows the handler to see which processes are listening on ports and what files they are accessing, which is crucial for identifying a backdoor. Other commands like `ps` or `netstat` offer partial views but do not combine file and network information in one output.
A GCIH incident handler is investigating a compromised Windows 10 workstation. The attacker gained access using stolen credentials and then attempted to dump credentials from memory. The handler runs Sysinternals ProcDump with the -ma flag against lsass.exe to capture a full memory dump for analysis. The attempt fails with an 'Access Denied' error. Which of the following is the MOST likely reason for this failure?
Explanation: To dump LSASS memory, the tool must run with administrative privileges that include SeDebugPrivilege. Without this privilege, the process cannot open LSASS with the necessary access rights, resulting in an access denied error. Credential Guard or PPL protections are not enabled by default and would require prior configuration, making them less likely causes in a typical incident.
Which TWO steps are critical during the 'Preparation' phase of the incident response lifecycle to ensure effective forensic investigation during a future security breach?
Explanation: Preparation is the foundation of incident response. By establishing logging infrastructure and legal protocols in advance, an organization ensures that forensic evidence is available and admissible when an incident occurs. Failing to prepare these elements often results in fragmented logs or delayed response actions, which hinders the team's ability to reconstruct the attack timeline accurately and perform root cause analysis after the threat is contained.
+15 more Incident Response and Cyber Investigation questions available
Practice all Incident Response and Cyber Investigation questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Incident Response and Cyber Investigation. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Incident Response and Cyber Investigation questions on the GCIH frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Incident Response and Cyber Investigation is tested as part of the GIAC Certified Incident Handler blueprint. Practicing with targeted Incident Response and Cyber Investigation questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GCIH practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Incident Response and Cyber Investigation is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Incident Response and Cyber Investigation practice session with instant scoring and detailed explanations.
Start Incident Response and Cyber Investigation Practice →