Which of the following is typically performed during the Recovery phase of incident response?
An attacker crafts an email that will send a user to the following site if they click a link in the message. What else is necessary for this type of attack to work?

Which of the following is a facilitated tabletop exercise that is run in odd years and provides an overall public Lessons Learned report each year it is run?
What is an output of a Business Impact Analysis?
In the context of ICS the process of fuzzing a device is described as which of the following?
A brewer uses a local HMI to communicate with a controller that opens a pump to move the workfrom the boil kettle to the fermentor. What level of the Purdue model would the controller be considered?
At which offset of ~/GIAC/memdump/raw/key_13does binwalkindicate is the beginning of the binary file?
An organization has their ICS operations and networking equipment installed in the Purdue model level 3. Where should the SIEM for this equipment be placed in relation to the existing Level 3 devices?
According to the DHS suggested patch decision tree, what should the next step be if there is a vulnerability with an available patch, but without an available workaround?
Which of the following would use round-robin process scheduling?