Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC AI Security Automation Engineer

Domain 5Objective 1

Using Automation and AI for Detection Engineering and Incident Response GASAE Practice Questions (Page 2)

Part of the Advanced Automation for Incident Response domain, which makes up ~9% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~6–11 in this domain), expect 6–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
6concepts

Questions 6–10

  1. 6expert · hard

    A security team has deployed an automated detection rule that uses an AI model to identify malicious PowerShell commands. The rule has a high false positive rate, causing alert fatigue. The team wants to improve the rule's precision without significantly reducing recall. What is the best approach?

    Select an answer first
  2. 7application · medium

    An organization uses a SIEM and a ticketing system. They want to integrate an AI-based alert triage tool into their existing incident response workflow. The tool should enrich alerts with threat intelligence and suggest response actions, but analysts must approve any automated action. What is the best way to integrate this tool?

    Select an answer first
  3. 8application · medium

    A detection engineering team has developed a new AI model that generates potential detection rules from network traffic data. Before deploying any of these rules to production, the team wants to validate their effectiveness. Which validation approach provides the most reliable evidence that a generated rule will work correctly in the live environment?

    Select an answer first
  4. 9foundation · easy

    What is the primary purpose of an automated incident response playbook?

    Select an answer first
  5. 10expert · hard

    A SOC has deployed an AI model that generates a risk score for each alert. The model was trained on historical data where the true positive rate was 1% (i.e., 1 in 100 alerts was a real incident). After deployment, the SOC notices that the model is flagging 10% of all alerts as high-risk. The SOC's analysts are overwhelmed and are ignoring the high-risk alerts. What is the most likely cause of this problem, and what is the best adjustment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.