
GIAC Enterprise Incident Responder
Domain 1Objective 3
Rapid Response Triage at Scale GEIR Practice Questions (Page 6)
Part of the Incident Response Foundations domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 26–30
- 26
A SOC has a triage workflow that includes a first-level review, a second-level review, and escalation to incident response. The first-level analyst is supposed to enrich alerts with asset information and threat intelligence. However, the analyst often skips enrichment because it requires opening multiple tools. What is the best improvement to ensure enrichment is consistently performed?
Select an answer first - 27
A large organization has a mature SOC with a well-defined triage process. During a major incident, the SOC manager wants to ensure that the triage team focuses on the most critical alerts while maintaining situational awareness. The team is receiving a high volume of alerts, many of which are low severity. What is the best approach to balance speed and accuracy?
Select an answer first - 28
A SOC has an automated triage system that uses a machine learning model to classify alerts as true or false positives. The model has a high precision but a low recall. The SOC manager is concerned about missing true positives. What is the best way to improve the system's recall without significantly reducing precision?
Select an answer first - 29
A SOC has implemented an automated triage system that uses machine learning to classify alerts as 'malicious' or 'benign' with 95% accuracy. The system is configured to automatically close any alert classified as 'benign' without human review. After a week, the team notices that a few genuine intrusions were missed because the system classified them as 'benign'. What is the most significant risk of this configuration, and what should the team do?
Select an answer first - 30
A SOC analyst is triaging a large number of alerts after a phishing campaign. The analyst must decide which alerts to investigate first. The organization has a mix of servers, workstations, and executive laptops. Which approach best aligns with the goals of rapid response triage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.