Incident Response and Cyber Investigation for GIAC Certified Incident Handler (GCIH)

This page covers the Incident Response and Cyber Investigation domain of the GIAC Certified Incident Handler (GCIH) certification. Master Cybersecurity offers 57 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    Adam works as an Incident Handler for Umbrella Inc. He has been sent to the California unit to train the members of the incident response team. As a demo project he asked members of the incident response team to perform the following actions: - Remove the network cable wires. - Isolate the system on a separate VLAN - Use a firewall or access lists to prevent communication into or out of the system. - Change DNS entries to direct traffic away from compromised system Which of the following steps of the incident handling process includes the above actions?
    1. A. Identification
    2. B. Containment
    3. C. Eradication
    4. D. Recovery
    Explanation

    The correct answer is: B. Containment.

    Every action in the list limits the reach of the compromise without yet attempting to remove its cause, which makes this the containment phase. Disconnecting the network cable severs the attacker's access immediately. Moving the system to a separate segment isolates it while keeping it available for examination. Firewall rules and access lists block traffic into and out of the host, a more controlled equivalent that also permits monitoring. Redirecting name resolution away from the compromised system keeps users from reaching it while the investigation proceeds. Identification precedes all of this and is where the event is recognised and classified. Eradication follows, and is where malicious code, accounts or vulnerabilities are actually removed. Recovery comes later still, restoring the system to service and monitoring it. The distinguishing feature of containment is that it stops the bleeding while deliberately preserving the state of the system for analysis.

  2. Question 2

    Which of the following are the primary goals of the incident handling team? Each correct answer represents a complete solution. (Choose all that apply.)
    1. A. Freeze the scene.
    2. B. Repair any damage caused by an incident.
    3. C. Prevent any further damage.
    4. D. Inform higher authorities.
    Explanation

    The correct answers are: A. Freeze the scene., B. Repair any damage caused by an incident., C. Prevent any further damage..

    Three goals are primary. Freezing the scene preserves the evidence, which constrains everything the team can later establish and must therefore happen before the situation is disturbed. Preventing further damage stops the harm spreading while the response proceeds. Repairing the damage already caused restores the organisation to working order, which is the point of responding at all. Together they cover evidence, limitation and restoration. Informing higher authorities is the option excluded, and the reason is that it is a communication obligation rather than a goal of the handling itself. Notification certainly happens, and for many incidents it is mandatory, but it serves governance and legal duties rather than the objectives the team is pursuing on the ground. The distinction between what the response is trying to achieve and what the organisation is obliged to report is worth keeping clear, because conflating them tends to delay the technical work.

  3. Question 3

    You work as a Network Administrator for Infonet Inc. The company has a Windows Server 2008 Active Directory-based single domain single forest network. The company has three Windows 2008 file servers, 150 Windows XP Professional, thirty UNIX-based client computers. The network users have identical user accounts for both Active Directory and the UNIX realm. You want to ensure that the UNIX clients on the network can access the file servers. You also want to ensure that the users are able to access all resources by logging on only once, and that no additional software is installed on the UNIX clients. What will you do to accomplish this task? Each correct answer represents a part of the solution. (Choose two.)
    1. A. Configure a distributed file system (Dfs) on the file server in the network.
    2. B. Enable the Network File System (NFS) component on the file servers in the network.
    3. C. Configure ADRMS on the file servers in the network.
    4. D. Enable User Name Mapping on the file servers in the network.
    Explanation

    The correct answers are: B. Enable the Network File System (NFS) component on the file servers in the network., D. Enable User Name Mapping on the file servers in the network..

    Two components are required. Enabling Network File System on the file servers lets the Unix clients mount and access the shares using the protocol they already speak, which satisfies the constraint that no additional software may be installed on those clients. Enabling User Name Mapping supplies the missing half by associating each Unix identity with its corresponding directory account, so a user authenticated on the Unix side is recognised as the same principal on the Windows side and does not have to authenticate again. Together they deliver access and single sign-on without touching the clients. A distributed file system provides a unified namespace and referrals across servers, which is useful for organising shares but does nothing to make them reachable by Unix clients or to reconcile identities. A rights management service protects documents by controlling what recipients may do with them, which is a content protection technology unrelated to cross-platform file access.

  4. Question 4

    Which of the following Incident handling process phases is responsible for defining rules, collaborating human workforce, creating a back-up plan, and testing the plans for an enterprise?
    1. A. Preparation phase
    2. B. Eradication phase
    3. C. Identification phase
    4. D. Recovery phase
    5. E. Containment phase
    Explanation

    The correct answer is: A. Preparation phase.

    Defining rules, assembling and organising the people who will respond, creating a backup plan and testing those plans all happen before any incident occurs, which makes this the preparation phase. Preparation is the phase that determines whether a response will be competent: it establishes the authority to act, produces the policies and checklists the team will follow, provisions the tools and training, and validates through exercises that the arrangements actually work. Testing in particular belongs here, because a plan that has never been rehearsed is unproven. The other phases all operate on an incident that already exists. Identification detects and classifies an event. Containment limits its spread. Eradication removes the cause. Recovery returns systems to service. None of them can encompass the building of the capability itself, which is why preparation is treated as continuous work rather than as a stage triggered by an event.

  5. Question 5

    You work as a System Engineer for Cyber World Inc. Your company has a single Active Directory domain. All servers in the domain run Windows Server 2008. The Microsoft Hyper-V server role has been installed on one of the servers, namely uC1. uC1 hosts twelve virtual machines. You have been given the task to configure the Shutdown option for uC1, so that each virtual machine shuts down before the main Hyper-V server shuts down. Which of the following actions will you perform to accomplish the task?
    1. A. Enable the Shut Down the Guest Operating System option in the Automatic Stop Action Properties on each virtual machine.
    2. B. Manually shut down each of the guest operating systems before the server shuts down.
    3. C. Create a batch file to shut down the guest operating system before the server shuts down.
    4. D. Create a logon script to shut down the guest operating system before the server shuts down.
    Explanation

    The correct answer is: A. Enable the Shut Down the Guest Operating System option in the Automatic Stop Action Properties on each virtual machine..

    Enabling the option to shut down the guest operating system in the automatic stop action properties of each virtual machine is what achieves the requirement. That setting tells the virtualisation host what to do with each guest when the host itself is shutting down, and choosing an orderly shutdown of the guest operating system means each machine closes cleanly and in sequence before the host completes its own shutdown, avoiding the data loss that abrupt suspension or power-off can cause. Configuring it per machine is the mechanism the platform provides for exactly this purpose. Manually shutting down twelve guests before every host restart is error-prone and does not scale, and it fails entirely for an unattended or unexpected shutdown. A batch file would have to be invoked reliably at the right moment in the shutdown sequence, which is precisely what the built-in setting already guarantees. A logon script runs when a user signs in, which is the wrong event altogether.

Other GIAC Certified Incident Handler (GCIH) domains

Practice all 57 Incident Response and Cyber Investigation questions · Browse GIAC Certified Incident Handler (GCIH)