
GIAC AI Security Automation Engineer
Domain 5Objective 1
Using Automation and AI for Detection Engineering and Incident Response GASAE Practice Questions (Page 6)
Part of the Advanced Automation for Incident Response domain, which makes up ~9% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~6–11 in this domain), expect 6–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
6concepts
Questions 26–30
- 26
A company is integrating an AI-based detection tool with its existing SOAR platform. The AI tool identifies potential threats and the SOAR platform is used to execute response playbooks. The team wants to ensure that the AI tool's output is effectively used by the SOAR platform. What is the most important integration point to configure?
Select an answer first - 27
An organization is integrating an AI-based alert enrichment tool into their incident response workflow. The tool adds threat intelligence context to alerts, but it sometimes enriches alerts with irrelevant or outdated information. The team wants to ensure that the enrichment is useful and does not mislead analysts. What is the best way to handle this?
Select an answer first - 28
A company has an automated playbook that responds to a specific type of alert. The playbook's first step is to automatically isolate the affected host from the network. The second step is to automatically run a set of forensic commands. The security team is concerned that the forensic commands are too intrusive and could disrupt the host's operations if the alert is a false positive. They also want to ensure that the response is fast enough to contain a real threat. What is the best way to modify the playbook to address these concerns?
Select an answer first - 29
An organization is integrating an AI-based incident response assistant into their SOAR platform. The assistant can suggest response actions, but the team is concerned about the assistant making mistakes. They want to ensure that the assistant's suggestions are safe and effective. What is the best way to implement this integration?
Select an answer first - 30
A security team maintains a large repository of Sigma rules. They want to automate the detection engineering lifecycle so that new rules are validated against a set of known-good and known-bad events before being deployed to production SIEMs. Which approach best uses automation and AI to achieve this while minimizing manual review effort?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.