
GIAC Enterprise Incident Responder
Domain 1Objective 3
Rapid Response Triage at Scale GEIR Practice Questions (Page 2)
Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 6–10
- 6
A security operations center (SOC) receives 15,000 alerts per day, but analysts only investigate about 200. The team lead wants to reduce the noise so analysts can focus on genuine threats. The SIEM already ingests endpoint, network, and identity logs. Which approach should the team implement first to reduce alert volume while preserving detection coverage?
Select an answer first - 7
A SOC is experiencing alert fatigue due to a high volume of low-priority alerts. The SOC manager wants to reduce the number of alerts that analysts need to review without increasing the risk of missing true positives. What is the best strategy?
Select an answer first - 8
A company has a small SOC and receives a burst of alerts during a widespread phishing campaign. The SOC manager wants to ensure that the most critical business functions are protected first. What is the primary goal of rapid response triage in this situation?
Select an answer first - 9
How can scripting be used to accelerate triage?
Select an answer first - 10
How can feedback from triage outcomes be used to improve the triage process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.