
GIAC Security Leadership
Domain 3Objective 1
Managing a Security Operations Center GSLC Practice Questions (Page 2)
Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
6concepts
Questions 6–10
- 6
In a typical SOC, which role is primarily responsible for triaging alerts and determining whether they are legitimate threats?
Select an answer first - 7
A SOC manager must choose between two SIEM solutions: Solution A has a lower upfront cost but requires significant manual tuning and has limited automation; Solution B has a higher upfront cost but includes automated alert triage and machine learning. The SOC has a small team and a high alert volume. Which solution is more appropriate?
Select an answer first - 8
A SOC is at a maturity level where it has defined processes but they are not consistently followed. The manager wants to improve maturity by ensuring processes are followed and measured. Which initiative would be most effective?
Select an answer first - 9
What is the purpose of a SOC's escalation procedure?
Select an answer first - 10
A SOC is implementing a new SIEM solution. The team needs to ensure that the SIEM can collect logs from various sources and correlate events to detect attacks. Which additional technology is most important to integrate with the SIEM to enhance its detection capability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.