
GIAC Information Security Professional
Domain 2Objective 2
Security Operations GISP Practice Questions (Page 10)
Part of the Security Architecture and Operations domain, which makes up ~43% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~41–69 in this domain), expect 14–23 from this objective — we provide 62 practice questions to prepare you well beyond it. (estimate)
62questions here
13free pages
12concepts
Questions 46–50
- 46
A security analyst receives an alert about a possible malware infection on a finance department workstation. The analyst confirms the alert is a true positive and isolates the host from the network. Which next step best aligns with the incident response lifecycle?
Select an answer first - 47
Why is patch management an important part of vulnerability management?
Select an answer first - 48
What is the primary purpose of Security Orchestration, Automation, and Response (SOAR) platforms?
Select an answer first - 49
A security team is investigating a potential data exfiltration incident. The SIEM shows a large amount of data being transferred from an internal server to an external IP address over a period of several hours. The server is a file share used by multiple departments. The analyst needs to determine if this is legitimate activity. Which action is most effective?
Select an answer first - 50
What is the purpose of maintaining a chain of custody for digital evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.