GSEC Incident Handling and Response Practice Question
A company's incident response plan requires a formal lessons-learned review after a major ransomware incident. Which TWO activities are appropriate during the Post-Incident Activity phase? (Choose two.)
⚠ Common exam trap
The trap here is conflating recovery actions, such as reimaging and restoring backups, with post-incident review activities, which focus on analysis and process improvement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a meeting with stakeholders to review what worked, what failed, and how to improve the plan.
The Post-Incident Activity phase is about learning from the incident and improving future response. Holding a stakeholder review meeting and updating the IR plan and detection rules based on findings both directly serve that purpose. Recovery and eradication actions belong to earlier phases, and containment is likewise an earlier-phase activity, so they are not appropriate here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reimage all affected endpoints and restore data from the most recent backups.
Why it's wrong here
Reimaging and restoring from backups are Recovery-phase activities, not Post-Incident Activity. While they are essential to restoring operations, they occur before the formal lessons-learned review. Performing them does not fulfill the phase's goal of analyzing and improving the response process, so this is not an appropriate Post-Incident Activity task.
- ✓
Conduct a meeting with stakeholders to review what worked, what failed, and how to improve the plan.
Why this is correct
The Post-Incident Activity phase centers on reviewing the incident to improve future response. A structured meeting with stakeholders captures lessons, identifies gaps in the plan, and assigns improvements. This directly fulfills the phase's purpose of turning experience into actionable changes, making it a correct activity for this scenario.
- ✓
Update the incident response plan and detection rules based on findings from the review.
Why this is correct
Updating the IR plan and detection rules translates lessons learned into tangible improvements, closing gaps discovered during the ransomware response. This is a core output of the Post-Incident Activity phase, ensuring the organization is better prepared next time. It is therefore a correct activity for this scenario.
- ✗
Isolate the compromised network segment to prevent the ransomware from spreading further.
Why it's wrong here
Isolating a network segment is a Containment-phase action taken during the active incident to limit spread. By the time the organization conducts a formal lessons-learned review, containment has already occurred. Treating isolation as a Post-Incident Activity misplaces it in the lifecycle and does not contribute to the analytical and improvement goals of the phase.
- ✗
Eradicate the ransomware binaries and remove persistence mechanisms from infected hosts.
Why it's wrong here
Eradicating malware and removing persistence are Eradication-phase tasks that happen before recovery and post-incident review. The scenario is set after a major incident where eradication has presumably concluded. Including this as a Post-Incident Activity confuses the phase sequence and does not address the review-and-improve objective of the phase.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.