Be able to sequence response actions correctly: identify and scope, contain, eradicate all persistence, recover, then document lessons learned. The single most important thing is preserving volatile evidence first — capture memory and network state before powering off or wiping anything.
Start practicing
Incident Handling and Response — choose a session length
Free · No account required
Domain overview
This domain covers the six-phase incident response lifecycle — preparation, identification, containment, eradication, recovery, and lessons learned — plus evidence handling and order of volatility. GSEC questions are scenario-based: you are given a live compromise, a legal obligation, or a forensic artifact and must choose the action that best preserves evidence, limits damage, or satisfies policy.
Exam objectives
Ordering response actions by volatility: memory and network state before disk, per RFC 3227 guidance.
Using SIEM log correlation and Windows Event IDs or Sysmon telemetry to shorten detection and scoping time.
Applying containment choices (network isolation, disabling accounts, blocking IOCs) without destroying forensic evidence.
Referencing pre-existing policy documents such as the incident response plan, data classification policy, and breach notification requirements.
Shutting down or rebooting a compromised host first, which wipes volatile memory, running processes, and network connections needed for scoping.
Jumping straight to eradication and recovery before containment and full scoping, leaving additional backdoors or persistence mechanisms undiscovered.
Treating lessons-learned as blame assignment or skipping it entirely, so the root detection gap that delayed the SIEM alert is never fixed.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Refer to the exhibit. An analyst observes this command execution on a workstation. Which immediate action represents the most effective containment strategy?
2An organization is deploying an automated incident response tool. Which requirement is most important to ensure the tool's effectiveness during a high-severity security incident?
3During an investigation, you discover a persistent backdoor. Which THREE actions should be included in the Eradication phase?
4Refer to the exhibit. Which type of attack is being mitigated by the application framework, and what incident phase should this alert trigger?
5Which document is essential to have in place before an incident occurs to ensure legal and regulatory compliance regarding data privacy and breach notification?
6An analyst receives an alert that a server's CPU usage has spiked to 100% and is generating outbound traffic to a known command-and-control IP address. The server is critical for a production application. After confirming the compromise, the analyst decides to isolate the server from the network. Which incident response phase does this action fall under?
7After a major security breach, the incident response team conducts a lessons-learned meeting. The team identifies that the initial detection was delayed because log sources were not properly integrated into the SIEM. Which phase of the incident response lifecycle does this finding primarily aim to improve?
8A security analyst receives an alert that a workstation's antivirus detected and quarantined a known trojan. The endpoint is still running and the user reports no unusual behavior. According to the SANS six-step incident handling process, which phase is the analyst currently in?
9A responder is preparing to image a compromised Windows server's memory before shutting it down. The server hosts a critical database and management insists on minimal downtime. Which action best preserves the most volatile evidence while respecting the operational constraint?
10During an investigation, an analyst finds that a compromised host has an outbound connection to a known command-and-control IP every 60 seconds. The host is on a production VLAN with other servers. Which containment strategy best limits the adversary's access while preserving evidence for later analysis?
11A company's incident response plan requires a formal lessons-learned review after a major ransomware incident. Which TWO activities are appropriate during the Post-Incident Activity phase? (Choose two.)
12An analyst is examining a Linux server suspected of compromise. The analyst runs a script that lists open network connections, running processes, and loaded kernel modules, but does not copy the binaries to external media. Which principle is the analyst applying?
13A security team is conducting a post-incident review after a successful ransomware attack. The team identifies that the initial infection vector was a phishing email that delivered a malicious macro. The team wants to improve future response. Which of the following actions is MOST effective for preventing a similar incident from succeeding in the future?
14A security analyst is responding to a confirmed malware infection on a critical server. The analyst has already contained the infection by isolating the server from the network. According to the incident handling process, which TWO actions should the analyst perform during the eradication phase? (Choose two.)
15A junior analyst at a healthcare provider receives a call from the help desk: a radiology workstation is behaving erratically and displaying a ransom note. The analyst immediately opens a remote session, logs in with domain administrator credentials, and begins deleting suspicious files in the user's startup folder. The workstation is still powered on and connected to the network. Which incident handling principle did the analyst MOST directly violate?
Be able to sequence response actions correctly: identify and scope, contain, eradicate all persistence, recover, then document lessons learned. The single most important thing is preserving volatile evidence first — capture memory and network state before powering off or wiping anything.
The Courseiva GSEC question bank contains 15 questions in the Incident Handling and Response domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Incident Handling and Response domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included