Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC AI Security Automation Engineer

Domain 1Objective 3

Security Orchestration Automation and Response GASAE Practice Questions (Page 2)

Part of the Security Automation Foundations domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
6concepts

Questions 6–10

  1. 6foundation · easy

    In a SOAR platform, what is the primary function of the 'automation' component?

    Select an answer first
  2. 7application · medium

    A SOC manager is evaluating a SOAR platform to improve incident response times. The team currently spends a significant amount of time on manual data gathering and repetitive tasks. The manager is concerned about the initial setup effort and the need for ongoing maintenance. Which evaluation factor is most important to consider when deciding whether to implement SOAR?

    Select an answer first
  3. 8application · medium

    A small SOC is considering implementing SOAR. They have a limited budget and a small team. They want to automate a few repetitive tasks but are concerned about the complexity of maintaining playbooks. What is the most important factor to consider before implementation?

    Select an answer first
  4. 9expert · hard

    A security team is designing a SOAR workflow for phishing response. The workflow must check the email's sender domain against a threat intelligence feed, and if the domain is malicious, quarantine the email. If the domain is not malicious, the workflow should still notify an analyst for review. The team is concerned about the reliability of the threat intelligence feed and wants to avoid quarantining legitimate emails due to a feed outage. Which workflow design best addresses this concern?

    Select an answer first
  5. 10application · medium

    A SOAR platform needs to pull alerts from a SIEM and also push indicators of compromise (IOCs) to a threat intelligence platform. What is the recommended way to achieve this bidirectional integration?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.