
GIAC Information Security Professional
Domain 2Objective 2
Security Operations GISP Practice Questions (Page 1)
Part of the Security Architecture and Operations domain, which makes up ~43% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~41–69 in this domain), expect 14–23 from this objective — we provide 62 practice questions to prepare you well beyond it. (estimate)
62questions here
13free pages
12concepts
Questions 1–5
- 1
Which SOC function involves proactively searching for threats that have evaded existing detection mechanisms?
Select an answer first - 2
A SOC analyst sees a SIEM alert for a single failed login to a non-privileged account, followed by a successful login from the same source IP. The source IP is a known VPN egress for a partner company. The user has not reported any issue. According to the incident triage process, what should the analyst do first?
Select an answer first - 3
A company's SIEM is not receiving logs from a critical database server. The server team says the agent is running, but the SIEM shows no recent events. Which troubleshooting step should the analyst take first?
Select an answer first - 4
Why is log collection and analysis essential for security operations?
Select an answer first - 5
During an incident investigation, a forensic analyst needs to collect evidence from a compromised server. The server is still running and the analyst wants to preserve volatile data. Which action should the analyst take first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.