GIAC Certified Incident Handler (GCIH)
Exam (AGACNP-C) 2026–2027 |
Comprehensive Question Practice Test
with Answers & Rationales| Free Pdf
Access
1. The primary objective of incident handling is to:
A. Increase network bandwidth
B. Detect, contain, eradicate, and recover from security incidents while minimizing business
impact
C. Replace vulnerability management
D. Eliminate all cyber risks
Correct Answer: B
Rationale: Incident handling focuses on managing and recovering from security incidents
effectively.
2. Which phase of the incident handling lifecycle comes first?
A. Containment
B. Preparation
C. Eradication
D. Recovery
,Correct Answer: B
Rationale: Preparation establishes the people, processes, and tools needed before incidents
occur.
3. Which document defines roles, responsibilities, and procedures for
responding to incidents?
A. Employee Handbook
B. Incident Response Plan
C. Software License Agreement
D. Asset Inventory
Correct Answer: B
Rationale: The Incident Response Plan provides guidance for coordinated response
activities.
4. Which activity is MOST appropriate during the preparation phase?
A. Restoring backups
B. Developing and testing incident response procedures
C. Rebuilding compromised systems
D. Removing malware
Correct Answer: B
Rationale: Preparation includes planning, training, and testing response capabilities.
5. The primary purpose of incident classification is to:
A. Increase storage capacity
,B. Prioritize response based on severity and impact
C. Configure firewalls
D. Eliminate false positives
Correct Answer: B
Rationale: Classification helps allocate resources efficiently.
6. Which source commonly provides the earliest indication of malicious
activity?
A. Intrusion Detection System (IDS)
B. Printer logs
C. Office attendance records
D. Hardware inventory
Correct Answer: A
Rationale: IDS alerts often provide early warning of suspicious activity.
7. An Indicator of Compromise (IOC) is:
A. Evidence suggesting a system may have been compromised
B. A backup policy
C. A firewall rule
D. A password policy
Correct Answer: A
Rationale: IOCs help identify malicious activity.
, 8. Which log source is MOST valuable for investigating authentication
failures?
A. Security Event Logs
B. DHCP Logs
C. Print Logs
D. BIOS Logs
Correct Answer: A
Rationale: Security logs record successful and failed authentication attempts.
9. Which SIEM capability is especially useful during incident analysis?
A. Event correlation
B. Disk defragmentation
C. File compression
D. RAID management
Correct Answer: A
Rationale: Event correlation combines related security events into meaningful incidents.
10. False positives should be:
A. Validated before escalation
B. Reported immediately without review
C. Ignored permanently
D. Deleted automatically
Exam (AGACNP-C) 2026–2027 |
Comprehensive Question Practice Test
with Answers & Rationales| Free Pdf
Access
1. The primary objective of incident handling is to:
A. Increase network bandwidth
B. Detect, contain, eradicate, and recover from security incidents while minimizing business
impact
C. Replace vulnerability management
D. Eliminate all cyber risks
Correct Answer: B
Rationale: Incident handling focuses on managing and recovering from security incidents
effectively.
2. Which phase of the incident handling lifecycle comes first?
A. Containment
B. Preparation
C. Eradication
D. Recovery
,Correct Answer: B
Rationale: Preparation establishes the people, processes, and tools needed before incidents
occur.
3. Which document defines roles, responsibilities, and procedures for
responding to incidents?
A. Employee Handbook
B. Incident Response Plan
C. Software License Agreement
D. Asset Inventory
Correct Answer: B
Rationale: The Incident Response Plan provides guidance for coordinated response
activities.
4. Which activity is MOST appropriate during the preparation phase?
A. Restoring backups
B. Developing and testing incident response procedures
C. Rebuilding compromised systems
D. Removing malware
Correct Answer: B
Rationale: Preparation includes planning, training, and testing response capabilities.
5. The primary purpose of incident classification is to:
A. Increase storage capacity
,B. Prioritize response based on severity and impact
C. Configure firewalls
D. Eliminate false positives
Correct Answer: B
Rationale: Classification helps allocate resources efficiently.
6. Which source commonly provides the earliest indication of malicious
activity?
A. Intrusion Detection System (IDS)
B. Printer logs
C. Office attendance records
D. Hardware inventory
Correct Answer: A
Rationale: IDS alerts often provide early warning of suspicious activity.
7. An Indicator of Compromise (IOC) is:
A. Evidence suggesting a system may have been compromised
B. A backup policy
C. A firewall rule
D. A password policy
Correct Answer: A
Rationale: IOCs help identify malicious activity.
, 8. Which log source is MOST valuable for investigating authentication
failures?
A. Security Event Logs
B. DHCP Logs
C. Print Logs
D. BIOS Logs
Correct Answer: A
Rationale: Security logs record successful and failed authentication attempts.
9. Which SIEM capability is especially useful during incident analysis?
A. Event correlation
B. Disk defragmentation
C. File compression
D. RAID management
Correct Answer: A
Rationale: Event correlation combines related security events into meaningful incidents.
10. False positives should be:
A. Validated before escalation
B. Reported immediately without review
C. Ignored permanently
D. Deleted automatically