GSEC › Incident Handling and Response
This domain covers the six-phase incident response lifecycle — preparation, identification, containment, eradication, recovery, and lessons learned — plus evidence handling and order of volatility. GSEC questions are scenario-based: you are given a live compromise, a legal obligation, or a forensic artifact and must choose the action that best preserves evidence, limits damage, or satisfies policy.
GSEC Incident Handling and Response — All 20 Questions
Every question in this domain with answers and detailed explanations.
Network Security Devices
Windows Security Infrastructure
macOS Security
Cryptography Application
Defense in Depth
Defensible Network Architecture
Access Control and Password Management
Cryptography
Endpoint Security
Windows Automation and Auditing
Networking and Protocols
Linux Fundamentals
Log Management and SIEM
Security Frameworks and CIS Controls
Container Security
Linux Security and Hardening
Windows Access Controls
Virtualization, Cloud, and AI Essentials
Vulnerability Scanning and Penetration Testing
Windows as a Service
Malicious Code and Exploit Mitigation
Windows Forensics
Web Communication Security
Wireless Network Security
Windows Services and MS Cloud