
GIAC Information Security Professional
Domain 2Objective 2
Security Operations GISP Practice Questions (Page 6)
Part of the Security Architecture and Operations domain, which makes up ~43% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~41–69 in this domain), expect 14–23 from this objective — we provide 62 practice questions to prepare you well beyond it. (estimate)
62questions here
13free pages
12concepts
Questions 26–30
- 26
During an incident investigation, a forensic analyst needs to collect the contents of a compromised server's memory. The server is still running and is critical to the business. What is the most appropriate action?
Select an answer first - 27
In a Security Operations Center (SOC), which role is primarily responsible for monitoring alerts and determining whether an alert represents a genuine security incident?
Select an answer first - 28
A SOC analyst is triaging multiple alerts. One alert indicates a potential ransomware infection on a single workstation, another indicates a phishing email that was blocked by the gateway, and a third indicates a failed login attempt on a non-critical system. Which alert should be escalated first?
Select an answer first - 29
What is the key difference between an intrusion detection system (IDS) and an intrusion prevention system (IPS)?
Select an answer first - 30
A vulnerability scanner identifies a critical vulnerability on an internet-facing web server. The patch is available but requires a reboot, which will cause downtime. The server is business-critical and cannot be taken offline during business hours. What is the best course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.