GIAC Enterprise Incident Response - GEIR Exam Practice Test
Which tool is primarily used for detailed investigation of the filesystem in Linux DFIR tasks?
Response:
Response:
Correct Answer: A
What are effective practices for maintaining enterprise visibility to support incident scoping?
Response:
Response:
Correct Answer: B,D
Which strategy is MOST effective in managing the complexity of a large-scale digital forensic investigation in a multinational corporation?
Response:
Response:
Correct Answer: A
Which of the following best describes 'Infrastructure as a Service' (IaaS)?
Response:
Response:
Correct Answer: B
Which of the following is a foundational strategy for responding to a container-based incident?
Response:
Response:
Correct Answer: C
Select the types of logs that would be most helpful in scoping a data exfiltration incident.
Response:
Response:
Correct Answer: B,C,E