Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC AI Security Automation Engineer

Domain 1Objective 3

Security Orchestration Automation and Response GASAE Practice Questions (Page 5)

Part of the Security Automation Foundations domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
6concepts

Questions 21–25

  1. 21application · medium

    A company uses a SIEM for log aggregation, a ticketing system for incident tracking, and a threat intelligence platform (TIP) for indicator feeds. The SOC wants to automatically enrich every phishing alert with reputation data from the TIP and create a ticket only if the reputation score exceeds a threshold. Which SOAR integration approach should be used?

    Select an answer first
  2. 22application · medium

    A SOC manager wants to integrate a threat intelligence platform (TIP) with the SOAR platform to enrich alerts. The TIP provides a REST API that requires an API key. What is the best practice for storing and using this API key in the SOAR platform?

    Select an answer first
  3. 23expert · hard

    A SOC is evaluating whether to build a SOAR playbook for a complex incident response process that involves multiple teams and tools. The playbook would automate many steps, but the process is not well-documented and changes frequently. What is the primary risk of automating this process?

    Select an answer first
  4. 24expert · hard

    A security team is designing a SOAR playbook for a critical alert that requires approval from a senior analyst before blocking a user account. The playbook should pause and wait for approval, but if the approval is not received within 10 minutes, it should escalate to the SOC manager. What is the best way to implement this in the SOAR workflow?

    Select an answer first
  5. 25application · medium

    A SOAR playbook is designed to handle a malware outbreak. The first step quarantines the affected endpoint, the second step collects forensic artifacts, and the third step notifies the incident response team. The playbook is currently set to run all steps in parallel. What is the main problem with this configuration?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.