
GIAC Information Security Professional
Domain 2Objective 2
Security Operations GISP Practice Questions (Page 8)
Part of the Security Architecture and Operations domain, which makes up ~43% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~41–69 in this domain), expect 14–23 from this objective — we provide 62 practice questions to prepare you well beyond it. (estimate)
62questions here
13free pages
12concepts
Questions 36–40
- 36
A SOC is implementing a new incident response process. The team wants to ensure that alerts are consistently triaged and that critical incidents are escalated to the appropriate personnel. Which role is primarily responsible for the initial assessment and prioritization of alerts?
Select an answer first - 37
What is an Indicator of Compromise (IoC)?
Select an answer first - 38
During an incident response, a forensic analyst needs to collect evidence from a compromised server. The server is running a critical application that cannot be stopped. The analyst must preserve evidence while minimizing disruption. Which approach balances both requirements?
Select an answer first - 39
Why is disaster recovery planning important for security operations?
Select an answer first - 40
What is the first step in digital forensics evidence collection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.