Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC AI Security Automation Engineer

Domain 4Objective 2

Defensive Security Automation GASAE Practice Questions (Page 2)

Part of the Offensive and Defensive Automation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
9concepts

Questions 6–10

  1. 6application · medium

    A vulnerability scanner identifies a critical remote code execution vulnerability on a set of internet-facing web servers. The security team has an automated remediation workflow that patches servers by applying the vendor's update. However, the workflow currently patches all servers simultaneously, and the team is concerned about service availability. Which modification to the workflow would best balance the need for rapid remediation with the risk of service disruption?

    Select an answer first
  2. 7foundation · easy

    What is a key consideration when designing an automation workflow for defensive security?

    Select an answer first
  3. 8expert · hard

    A security engineer is designing an automated workflow that handles data exfiltration incidents. The workflow must: (1) identify the affected endpoint, (2) block the endpoint's network access, (3) notify the incident response team, and (4) create a forensic snapshot of the endpoint. The team has a requirement that the forensic snapshot must be taken before the endpoint is powered off, but the endpoint may be powered off by the user at any time. The engineer wants to ensure the snapshot is taken as soon as possible. Which workflow design is most appropriate?

    Select an answer first
  4. 9expert · hard

    A security team wants to implement continuous monitoring for insider threats. They have access to employee authentication logs, file access logs, and email metadata. The team wants to detect when an employee accesses sensitive files outside of their normal working hours and then sends an email with an attachment. The team is concerned about privacy regulations. What is the best approach?

    Select an answer first
  5. 10application · medium

    A security analyst wants to automate the detection of data exfiltration from their cloud storage. They have access to cloud audit logs and a SIEM. The detection should trigger when a user downloads a large volume of data from a sensitive bucket outside business hours. What is the most effective automated detection mechanism?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.