
GIAC AI Security Automation Engineer
Domain 5Objective 1
Using Automation and AI for Detection Engineering and Incident Response GASAE Practice Questions (Page 3)
Part of the Advanced Automation for Incident Response domain, which makes up ~9% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~6–11 in this domain), expect 6–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
6concepts
Questions 11–15
- 11
A SOC is evaluating an AI model that will be used to prioritize alerts. The model was trained on a dataset where 95% of the alerts were from a single, noisy detection rule. The team is concerned that the model will be biased toward this rule. What is the most effective way to address this bias during the model's evaluation?
Select an answer first - 12
A security team is automating its detection engineering process. They have an AI model that generates candidate rules, a CI/CD pipeline that tests them, and a manual approval step before deployment. The team is seeing a bottleneck: the AI model generates hundreds of candidate rules per week, but the analysts only have time to review and approve a small fraction of them. What is the most effective way to address this bottleneck without sacrificing the quality of the rules that are deployed?
Select an answer first - 13
A detection engineer wants to use a machine learning model to generate new detection rules from historical attack telemetry. The team is concerned about the model producing rules that are too broad and would generate excessive false positives. What is the most effective way to constrain the model's output while still leveraging AI?
Select an answer first - 14
An organization has an automated playbook that responds to a specific type of phishing alert. The playbook's first step is to automatically delete the reported email from all user mailboxes. The security team is concerned that this action is too aggressive and could delete legitimate emails if the alert is a false positive. Which modification to the playbook best addresses this concern?
Select an answer first - 15
A company's incident response (IR) team uses a legacy ticketing system and manual processes. They are introducing an AI-powered tool that can analyze an alert and suggest a response playbook. The team wants to integrate this tool into their existing workflow with minimal disruption. What is the most effective first step for this integration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.