Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC AI Security Automation Engineer

Domain 4Objective 2

Defensive Security Automation GASAE Practice Questions (Page 6)

Part of the Offensive and Defensive Automation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
9concepts

Questions 26–30

  1. 26foundation · easy

    Which of the following is an example of an automated threat detection mechanism?

    Select an answer first
  2. 27application · medium

    A security engineer is designing an automated threat detection workflow for a fleet of Windows servers. The workflow must collect security event logs every 5 minutes, correlate them with known indicators of compromise (IOCs), and trigger an incident ticket only when a correlation confidence score exceeds 0.8. The engineer wants to avoid alert fatigue while ensuring that a newly discovered IOC is applied within 15 minutes of publication. Which approach best meets these requirements?

    Select an answer first
  3. 28expert · hard

    A company's automated threat detection system uses a machine learning model to identify phishing emails. The model was trained on email data from the past year. Recently, the company has seen an increase in phishing emails that use new techniques, and the model's detection rate has dropped. The security team wants to improve the model's performance. Which action is most appropriate?

    Select an answer first
  4. 29expert · hard

    A security team is building an automated incident response playbook for a malware infection. The playbook should: (1) quarantine the infected host, (2) kill the malicious process, (3) collect a memory dump, and (4) notify the incident response team. The team is concerned about the order of actions because killing the process may prevent memory dump collection. What is the best order?

    Select an answer first
  5. 30application · medium

    A SOAR playbook automatically blocks an IP address in the firewall when a threat intelligence feed reports it as malicious. The team is concerned about blocking a legitimate IP due to a false positive. What is the best way to test the playbook before production?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.