GIAC GSEC (Security Essentials)

Incident Handling, Logging & Frameworks

22 practice questions with explanations — 15 free to try

1 of these 22 questions are in the free 15-question taster · the full topic is part of Premium

PassNova has 22 GIAC GSEC (Security Essentials) practice questions on Incident Handling, Logging & Frameworks, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.

Sample questions

Incident Handling, Logging & Frameworks: example questions & answers

1 worked example with answers and explanations below. Try 15 GIAC GSEC (Security Essentials) questions free in the browser; the full 22-question Incident Handling, Logging & Frameworks bank is part of PassNova Premium.

  1. In the six-step incident handling process of Preparation, Identification, Containment, Eradication, Recovery and Lessons Learned, what comes immediately after Containment?

    • ARecovery
    • BLessons Learned
    • CEradication✓
    • DIdentification

    Answer: Once the incident is contained, eradication removes its cause, such as malware, attacker accounts and persistence mechanisms, and fixes the exploited weakness, before recovery returns cleaned systems to production under close monitoring. Restoring systems before eradication risks reinfection. Identification comes before containment, and lessons learned closes the cycle.

Start practising Incident Handling, Logging & Frameworks →