Domain 3: Incident Handling & Response
GIAC Certified Enterprise Defender · 18 questions
- During the identification phase of the PICERL incident response cycle, a security analyst receives an alert for unusual login activity. What is the PRIMARY objective of this phase?
- A ransomware attack has encrypted files on 15 servers. The IR team needs to contain the incident. Which containment action should be performed FIRST?
- During a forensic investigation, an analyst must collect evidence from a running compromised Windows server. In what order should volatile data be collected following the order of volatility?
- An incident responder discovers an attacker established persistence via a scheduled task that downloads and executes a payload from an external server at startup. What is the CORRECT sequence of eradication steps?
- After containing an incident involving compromised administrative credentials, the IR team is in the recovery phase. Which action is MOST critical before returning affected systems to production?
- A forensic analyst investigating a compromised Linux system finds the command history file has been cleared. Which alternative source BEST helps reconstruct attacker command activity?
- An IR team is responding to a business email compromise where an attacker used a compromised executive's email account. During post-incident activity, which lesson-learned item is MOST valuable?
- During incident response, the team discovers the attacker used only built-in Windows tools including certutil, bitsadmin, and mshta. Why does this complicate traditional IR approaches?
- An organization has confirmed a data breach involving customer PII. The IR team lead is determining notification requirements. Which factor MOST directly affects breach notification timelines?
- During an incident response engagement, the IR team is called at 11 PM after a ransomware alert fires on a file server. The server is actively encrypting shares. What is the correct sequence of initial containment actions?
- An IR analyst is performing triage on a potentially compromised Linux web server. Which command sequence collects volatile artifacts in the correct order of volatility?
- During the eradication phase of an incident involving a compromised Active Directory environment, the team identifies that the attacker created a Golden Ticket using a stolen KRBTGT hash. Which eradication action is specifically required to invalidate all existing Golden Tickets?
- A company's IR policy states that all incidents must be categorized before escalation. An analyst receives a ticket: 'User reports laptop running slowly.' During triage, the analyst finds outbound connections to a known C2 IP and a persistent registry run key for an unknown binary. How should this incident be categorized?
- During post-incident recovery, the IR team is determining when to bring a compromised e-commerce system back online. Which condition must be satisfied before production restoration?
- An IR team is performing forensic disk acquisition of a Windows workstation suspected of data exfiltration. Which tool and method represent best practice for forensic imaging?
- An incident involves a phishing campaign that delivered a malicious macro-enabled document. After containment, the IR team must identify all affected users. Which data source most efficiently identifies who opened the document?
- An incident response team discovers that an attacker has been present in the network for 6 months. The attacker used a valid domain administrator account. Which forensic artifact is most useful for establishing a timeline of the attacker's activities within Active Directory?
- A company's written IR policy requires notifying the legal team before taking containment actions on any system. During an active ransomware outbreak, the IR team is containment-ready but the legal team is unreachable for 2 hours. What should the IR team do?