
GIAC Information Security Professional
Domain 2Objective 2
Security Operations GISP Practice Questions (Page 7)
Part of the Security Architecture and Operations domain, which makes up ~43% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~41–69 in this domain), expect 14–23 from this objective — we provide 62 practice questions to prepare you well beyond it. (estimate)
62questions here
13free pages
12concepts
Questions 31–35
- 31
A company's security operations team is updating its incident response plan. They want to ensure that critical business functions can continue during a prolonged security incident. Which component should be integrated into the plan?
Select an answer first - 32
What is the primary capability of Endpoint Detection and Response (EDR) tools?
Select an answer first - 33
A threat intelligence feed provides a list of malicious IP addresses and domain names associated with a new campaign. The SOC wants to use this information to detect potential infections. What is the most effective way to operationalize this intelligence?
Select an answer first - 34
A vulnerability management team discovers a critical vulnerability in a widely used application. The vendor has released a patch, but the patch is known to cause compatibility issues with a custom in-house application. The team must decide how to proceed. Which approach best balances risk and operational stability?
Select an answer first - 35
What is the primary objective of the preparation phase in the incident response lifecycle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.