
GIAC AI Security Automation Engineer
Domain 4Objective 2
Defensive Security Automation GASAE Practice Questions (Page 9)
Part of the Offensive and Defensive Automation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
9concepts
Questions 41–45
- 41
Why is it necessary to maintain and update defensive automation?
Select an answer first - 42
A company has an automated incident response playbook that isolates a compromised host by applying a network access control list (ACL) via the firewall API. During a recent ransomware simulation, the playbook successfully isolated the host, but the security team was not notified until 20 minutes later because the notification step ran after the isolation step and the notification service was temporarily unavailable. The team wants to ensure that notifications are sent reliably and promptly. Which improvement should be made to the playbook?
Select an answer first - 43
A company uses a SOAR platform to automate incident response. The SOAR platform integrates with the ticketing system, the SIEM, and the firewall. The team wants to create a playbook that, when a SIEM alert is received, creates a ticket, enriches the alert with threat intelligence, and if the alert is confirmed, blocks the source IP on the firewall. The team is concerned about the reliability of the integration with the threat intelligence service, which occasionally times out. Which design should be used to ensure the playbook completes even if the threat intelligence service is unavailable?
Select an answer first - 44
Which of the following is a best practice for designing defensive automation workflows?
Select an answer first - 45
A security team is setting up continuous monitoring for a new application. The monitoring system must detect anomalies in user behavior, such as unusual login times or excessive data downloads. The team has historical data from the application's first month of operation, but the application is new and user behavior is expected to evolve. The team wants to minimize false positives while still detecting genuine anomalies. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.