Courseiva

GSEC · topic practice

Incident Handling and Response practice questions

This domain covers the six-phase incident response lifecycle — preparation, identification, containment, eradication, recovery, and lessons learned — plus evidence handling and order of volatility. GSEC questions are scenario-based: you are given a live compromise, a legal obligation, or a forensic artifact and must choose the action that best preserves evidence, limits damage, or satisfies policy.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Incident Handling and Response

What the exam tests

What to know about Incident Handling and Response

Be able to sequence response actions correctly: identify and scope, contain, eradicate all persistence, recover, then document lessons learned. The single most important thing is preserving volatile evidence first — capture memory and network state before powering off or wiping anything.

Ordering response actions by volatility: memory and network state before disk, per RFC 3227 guidance.

Using SIEM log correlation and Windows Event IDs or Sysmon telemetry to shorten detection and scoping time.

Applying containment choices (network isolation, disabling accounts, blocking IOCs) without destroying forensic evidence.

Referencing pre-existing policy documents such as the incident response plan, data classification policy, and breach notification requirements.

Watch out for

Common Incident Handling and Response exam traps

  • ▸Shutting down or rebooting a compromised host first, which wipes volatile memory, running processes, and network connections needed for scoping.
  • ▸Jumping straight to eradication and recovery before containment and full scoping, leaving additional backdoors or persistence mechanisms undiscovered.
  • ▸Treating lessons-learned as blame assignment or skipping it entirely, so the root detection gap that delayed the SIEM alert is never fixed.

Practice set

Incident Handling and Response questions

20 questions · select your answer, then reveal the explanation

An organization detects unauthorized lateral movement across a segmented network. Which incident handling phase is primarily responsible for identifying the scope of the compromise and determining if data exfiltration occurred?

Which TWO of the following are primary goals of the Post-Incident Activity phase of the incident response lifecycle?

An incident responder is investigating a potential data breach involving sensitive PII. Which order of volatility should the responder follow when collecting evidence?

A security analyst at a financial services firm receives an alert from the SIEM indicating that a workstation has initiated a large outbound data transfer to an unfamiliar IP address in a foreign country. The analyst confirms the workstation belongs to an employee in the accounting department who is currently on vacation. According to the GIAC incident handling process, which action should the analyst take FIRST?

A security incident responder is investigating a compromised Linux server. The responder needs to collect volatile data before shutting down the system. Which of the following commands should the responder use to capture the current network connections and listening ports?

Refer to the exhibit. An analyst observes this command execution on a workstation. Which immediate action represents the most effective containment strategy?

Exhibit

Log Entry: 2023-10-12 14:22:01, SRC: 192.168.1.50, DST: 10.0.0.5, CMD: 'powershell.exe -Enc JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsA...'

An organization is deploying an automated incident response tool. Which requirement is most important to ensure the tool's effectiveness during a high-severity security incident?

During an investigation, you discover a persistent backdoor. Which THREE actions should be included in the Eradication phase?

Refer to the exhibit. Which type of attack is being mitigated by the application framework, and what incident phase should this alert trigger?

Exhibit

ERROR: [System.Web.HttpException]: A potentially dangerous Request.Form value was detected from the client (ctl00$MainContent$txtComment='<script>alert(1)</script>').

Which document is essential to have in place before an incident occurs to ensure legal and regulatory compliance regarding data privacy and breach notification?

An analyst receives an alert that a server's CPU usage has spiked to 100% and is generating outbound traffic to a known command-and-control IP address. The server is critical for a production application. After confirming the compromise, the analyst decides to isolate the server from the network. Which incident response phase does this action fall under?

After a major security breach, the incident response team conducts a lessons-learned meeting. The team identifies that the initial detection was delayed because log sources were not properly integrated into the SIEM. Which phase of the incident response lifecycle does this finding primarily aim to improve?

A security analyst receives an alert that a workstation's antivirus detected and quarantined a known trojan. The endpoint is still running and the user reports no unusual behavior. According to the SANS six-step incident handling process, which phase is the analyst currently in?

A responder is preparing to image a compromised Windows server's memory before shutting it down. The server hosts a critical database and management insists on minimal downtime. Which action best preserves the most volatile evidence while respecting the operational constraint?

Question 15mediummultiple choice
Open the full VLAN trunking answer →

During an investigation, an analyst finds that a compromised host has an outbound connection to a known command-and-control IP every 60 seconds. The host is on a production VLAN with other servers. Which containment strategy best limits the adversary's access while preserving evidence for later analysis?

A company's incident response plan requires a formal lessons-learned review after a major ransomware incident. Which TWO activities are appropriate during the Post-Incident Activity phase? (Choose two.)

An analyst is examining a Linux server suspected of compromise. The analyst runs a script that lists open network connections, running processes, and loaded kernel modules, but does not copy the binaries to external media. Which principle is the analyst applying?

A security team is conducting a post-incident review after a successful ransomware attack. The team identifies that the initial infection vector was a phishing email that delivered a malicious macro. The team wants to improve future response. Which of the following actions is MOST effective for preventing a similar incident from succeeding in the future?

A security analyst is responding to a confirmed malware infection on a critical server. The analyst has already contained the infection by isolating the server from the network. According to the incident handling process, which TWO actions should the analyst perform during the eradication phase? (Choose two.)

A junior analyst at a healthcare provider receives a call from the help desk: a radiology workstation is behaving erratically and displaying a ransom note. The analyst immediately opens a remote session, logs in with domain administrator credentials, and begins deleting suspicious files in the user's startup folder. The workstation is still powered on and connected to the network. Which incident handling principle did the analyst MOST directly violate?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Incident Handling and Response sessions

Start a Incident Handling and Response only practice session

Every question in these sessions is drawn from the Incident Handling and Response domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Incident Handling and Response?
Be able to sequence response actions correctly: identify and scope, contain, eradicate all persistence, recover, then document lessons learned. The single most important thing is preserving volatile evidence first — capture memory and network state before powering off or wiping anything.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Incident Handling and Response questions in a focused session?
Yes — the session launcher on this page draws every question from the Incident Handling and Response domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.