GSEC · domain
Incident Handling and Response
This domain covers the six-phase incident response lifecycle — preparation, identification, containment, eradication, recovery, and lessons learned — plus evidence handling and order of volatility. GSEC questions are scenario-based: you are given a live compromise, a legal obligation, or a forensic artifact and must choose the action that best preserves evidence, limits damage, or satisfies policy.
Focused practice
Practice Incident Handling and Response questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Incident Handling and Response
Be able to sequence response actions correctly: identify and scope, contain, eradicate all persistence, recover, then document lessons learned. The single most important thing is preserving volatile evidence first — capture memory and network state before powering off or wiping anything.
Ordering response actions by volatility: memory and network state before disk, per RFC 3227 guidance.
Using SIEM log correlation and Windows Event IDs or Sysmon telemetry to shorten detection and scoping time.
Applying containment choices (network isolation, disabling accounts, blocking IOCs) without destroying forensic evidence.
Referencing pre-existing policy documents such as the incident response plan, data classification policy, and breach notification requirements.
Watch out for
Common Incident Handling and Response exam traps
- ▸Shutting down or rebooting a compromised host first, which wipes volatile memory, running processes, and network connections needed for scoping.
- ▸Jumping straight to eradication and recovery before containment and full scoping, leaving additional backdoors or persistence mechanisms undiscovered.
- ▸Treating lessons-learned as blame assignment or skipping it entirely, so the root detection gap that delayed the SIEM alert is never fixed.
Question index
All Incident Handling and Response questions (15)
Click any question to see the full explanation, or start a practice session above.
A security analyst receives an alert that a workstation's antivirus detected and quarantined a known trojan. The endpoint is still running and the user reports no unusual behavior. According to the SANS six-step incident handling process, which phase is the analyst currently in?
Easy2A company's incident response plan requires a formal lessons-learned review after a major ransomware incident. Which TWO activities are appropriate during the Post-Incident Activity phase? (Choose two.)
Hard3During an investigation, an analyst finds that a compromised host has an outbound connection to a known command-and-control IP every 60 seconds. The host is on a production VLAN with other servers. Which containment strategy best limits the adversary's access while preserving evidence for later analysis?
Medium4Which document is essential to have in place before an incident occurs to ensure legal and regulatory compliance regarding data privacy and breach notification?
Easy5An analyst receives an alert that a server's CPU usage has spiked to 100% and is generating outbound traffic to a known command-and-control IP address. The server is critical for a production application. After confirming the compromise, the analyst decides to isolate the server from the network. Which incident response phase does this action fall under?
Medium6A security team is conducting a post-incident review after a successful ransomware attack. The team identifies that the initial infection vector was a phishing email that delivered a malicious macro. The team wants to improve future response. Which of the following actions is MOST effective for preventing a similar incident from succeeding in the future?
Hard7Refer to the exhibit. Which type of attack is being mitigated by the application framework, and what incident phase should this alert trigger?
Medium8An analyst is examining a Linux server suspected of compromise. The analyst runs a script that lists open network connections, running processes, and loaded kernel modules, but does not copy the binaries to external media. Which principle is the analyst applying?
Hard9During an investigation, you discover a persistent backdoor. Which THREE actions should be included in the Eradication phase?
Hard10A junior analyst at a healthcare provider receives a call from the help desk: a radiology workstation is behaving erratically and displaying a ransom note. The analyst immediately opens a remote session, logs in with domain administrator credentials, and begins deleting suspicious files in the user's startup folder. The workstation is still powered on and connected to the network. Which incident handling principle did the analyst MOST directly violate?
Hard11A responder is preparing to image a compromised Windows server's memory before shutting it down. The server hosts a critical database and management insists on minimal downtime. Which action best preserves the most volatile evidence while respecting the operational constraint?
Medium12After a major security breach, the incident response team conducts a lessons-learned meeting. The team identifies that the initial detection was delayed because log sources were not properly integrated into the SIEM. Which phase of the incident response lifecycle does this finding primarily aim to improve?
Hard13Refer to the exhibit. An analyst observes this command execution on a workstation. Which immediate action represents the most effective containment strategy?
Hard14A security analyst is responding to a confirmed malware infection on a critical server. The analyst has already contained the infection by isolating the server from the network. According to the incident handling process, which TWO actions should the analyst perform during the eradication phase? (Choose two.)
Medium15An organization is deploying an automated incident response tool. Which requirement is most important to ensure the tool's effectiveness during a high-severity security incident?
MediumOther domains
All GSEC exam domains
Frequently asked questions
- What does the Incident Handling and Response domain cover on the GSEC exam?
- Be able to sequence response actions correctly: identify and scope, contain, eradicate all persistence, recover, then document lessons learned. The single most important thing is preserving volatile evidence first — capture memory and network state before powering off or wiping anything.
- How many questions are in this domain?
- This page lists all 15 Incident Handling and Response questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Incident Handling and Response questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.